Email or username:

Password:

Forgot your password?
Top-level
Glyph

@darius FWIW email is a lot more secure, on average, than people give it credit for. It doesn't break in the nice clean way that e.g. spoofed TLS would, but in practice if you try to blast out plaintext SMTP forged from: headers these days, you get blackholed into oblivion 99% of the time. servers are also using TLS between each other and so grabbing messages off the wire is not trivial either.

3 comments
Darius Kazemi

@glyph right, and ActivityPub has similar protections built in for forged from fields and the like. The core insecurity of "Google can hand your plaintext email to the cops" is analogous to "admins can read your DMs" that people on here are always bringing up

Jason Petersen (he)

@darius @glyph how is all of this that you’ve described not jus Matrix. Yes, it’s not activity pub. But it’s mostly what you mean, and it’s federated.

Darius Kazemi

@jason @glyph it is frustrating to ask "has anyone built a bridge out of paper?" and to get a bunch of replies about how plenty of bridges are built from steel

Go Up