Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Phillip Hallam-Baker

@hallam@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Working on end-to-end secure everything: https://mathmesh.com/

772 Followers
153 Following
24 Posts
Joined November 06, 2022
Web:
https://www.hallambaker.com/
Mesh Test2:
https://example.com/MAAC-2JTO-TQDK-HYT3-2DYP-4ZT2-7WUE
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 24mo ago

So trudging through Ivan Jablonka's History of Masculinity, some thoughts.

First off, the alleged history of masculinity has very little mention of men or masculinity. Which, OK so playing the game of excluding men from their narrative like women are, yada yada. Problem is, I was already familiar with most of his material. What I was after was more insight into the mostly male crap heads who cause most of the problems in the world and Jablonka didn't really deliver.

We are given a received frame through which we are told to view the world. While it is true that the frame is biased towards the male gender and masculinity, patriarchy is a consequence of the frame, not the frame itself.

To understand the essence of the frame, it is necessary to look at the rubes following the cults of MAGA and Boris Johnson, mostly but not exclusively men who have invested their entire self-actualization in the service of what they see as a cause greater than themselves. And so, they praise men who are so obviously frauds as their personal messiah.

The first frame we are given is a hierarchy and we are told that our objective must be to climb to its apex. After a while this simplistic frame is replaced with a new one which admits that the hierarchy we are born into is in competition with other hierarchies: nation, religion, culture. And it is our duty to ensure that our hierarchy wins against its competitors.

And as George Orwell explains in 1984, this struggle between hierarchies is in fact a sham, a deliberate fiction maintained for the sole purpose of maintaining the hierarchy. And so in 1989 as the Brelin wall was starting to crumble, Margaret Thatcher was dispatched by Bush the elder to tell Gorbachev to ignore protests on behalf of the protestors, he should crush dissent with an iron fist.

It is that betrayal, a betrayal which I knew about long before it was revealed by the Gorbachev archives, which has informed my politics and led to my work on the Web. The real goal of the Web was to give people direct access to information without the frame inserted by the press, the academy, the church.

Once we can find a place outside the frame, we can see how the system works. Men like Boris Johnson found people who could further his career with the promise that if they helped him climb the greasy pole, he would pull them up as well once he got to the top.

And so social media is filled with angry old men shouting loudly that Trump is the messiah, that only a fool, an idiot, a communist would oppose him. Angry old men franticly demanding that the hierarchy be preserved so that they can take their rightful place within it.

Yesterday, J.D. Vance gave an angry speech about the 'fact' that a dozen eggs now cost $4 under Vice-President Harris while in a supermarket standing in front of signs selling a dozen eggs for $2.

It isn't an accident that Vance is the very best the patriarchy could find to defend it, Vance and Trump represent a type of masculinity most men now reject because just like Trump's tax cuts only benefited the 0.1%, the 'benefits' of the patriarchy are distinctly skewed as well.

I don't see the image of strength and power Vance and Trump want to project. I see two frightened little men who are desperate to gain position and power but have absolutely no idea how to use either.

Patriarchy provides an alternative frame through which we can understand the power dynamics that drive authoritarian bigots like Trump and Putin, but it is a flawed frame because it reduces all relations to gender and is counterproductive in that it encourages men to imagine they have a stake in maintaining it.

Some on the far left employ a similarly flawed frame of colonialism which holds the US, NATO and the democratic nations generally as being responsible for all the misery in the world and that therefore Putin's aggression against Ukraine is legitimate.

If we instead look at history as the result of the actions of individuals rather than states, we can see that every country has a war party and that the invasion of Iraq was the result of neo-colonialists who had the ear of George W. Bush and that we have to look at individual circumstances to decide what causes to support and not the frame we are given and told we must not question.

And the last is the really important part because if we blindly follow those in authority without question, we are going to end up following incompetent clowns like Boris Johnson and incompetent rapist clowns like Trump.

18
1
12
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 11mo ago

The OpenAI / Oracle / nVidia deals are a clear cut example of circular finance. Also known as 'Enron accounting'.

nVidia 'invests' $100 billion in Open AI. OpenAI stock price soars.

Open AI 'pays' Oracle $100 billion for cloud services to support their AI. Oracle stock price soars.

Oracle 'pays' $100 million to nVidia to 'buy' GPUs, nVidia stock soars.

And all the time, the CEOs and top execs at all three companies are exercising and selling their stock options at ever inflated prices.

The scheme does require the parties to pay a tithe to the grifter in chief or the SEC would quickly put a stop to the scam. Legal or not, Trump demands his cut.

When the music stops, all three companies will collapse as the bubble bursts.

2
0
0
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 12mo ago

Spent some time thinking about what it would take to bind Mastodon and the ATmopsphere and the remains of the blogosphere into a single information space.

Yes, I do realize some folk would rather erect a little moat around their social space rather than to unite against the people yelling 'free speech' as pretext for censoring all opposition to the orange rapist. Well tough.

First dimension of welding together the social media is to enable people to use a single account anywhere. OAUTH provides a framework for doing just that but it is only a framework, to achieve account portability, we need a single standard that is widely supported. The BlueSky profile of OAUTH looks like it does just that. There is one dependency I would like to shear off but that is pretty much it.

Second dimension is to provide a standard means of presenting an index of a social media stream. This is the role RSS was originally developed for but being based on XML which only allows for one root element, the entire RSS document has to be rewritten every time a new entry is added.

I proposed a format that allows JSON and XML objects to be packaged up in a simple binary format for precisely that purpose some years back. I am now proposing it to IETF as part of my @nyone proposal. The idea is simple, wrap each JSON or XML object in a binary frame using the same varint length-data chunking scheme used in QUIC.

The third and final dimension is an efficient update notification mechanism so that any one of millions of users can be notified when any one of billions of information assets is updated.

RSS allows Alice to pull a document giving the last ten posts of Bob's blog. Expanding that to all the posts is an improvement but what Alice really wants is a scheme in which she is informed the minute any update occurs.

This is a problem that is solved to a degree in pretty much every modern social media system. What I want to do is to strip that mechanism down to the absolute bare minimum so that it can be used as a generic protocol building block across systems built for entirely different purposes.

For example, when Alice updates her JSContact card, she wants Bob and everyone she knows to start using the new contact immediately.

This part of the problem is the part that is still 'research'. Which is to say that it is a problem Blue Sky and Mastadon have only partial solutions for at the moment.

The part that makes it a really hard problem is that the advertisement mechanism is potentially under constant attack from parties attempting a denial of service attack. The goal of most Russian disinformation operations isn't so much convincing people of anything in particular, it is denying them the ability to think for themselves or discuss anything amongst themselves.

And to make my specific problem with the Mesh social media system harder still, all the content is encrypted end to end, none of the services know what it is saying.

So before I start, yes I am aware that much of this is supported by existing schemes. The different is not the features I am adding, IT IS THE FEATURES I TAKE OUT. The reason the Web worked when Xanadu did not is not because the Web has cleverer technology, the real breakthrough was junking features driven by Ted Nelson's peculiar ideological commitments that were very expensive adding complexity and computation overhead into the specification core. The Web doesn't guarantee referential transparency and doesn't support search directly and that is why it works.

The design I am looking at right now begins with the concept of an aggregation provider which accepts notifications from a set of producers and forwards them to a set of consumers.

Each notification is a fixed length data object specifying a unique notification identifier, the producer identifier, the object that was updated by means of a UUID, the time the update occurred an indicator of the update type and a logarithmic indication of the number of updates.

[Collections of notifications MAY be authenticated by means of an efficient digital signature scheme, e.g. ML-DSA over a Merkle Tree. Since this is only needed for an accountability control, it does not need to arrive with the notifications.]

This allows a blog to inform the aggregator that there have been ~200 like/dislike responses to a post. It also allows the aggregator to create summary notifications aggregating across producers responding to the same object.

It is not necessary for the update count to be very precise; a producer is likely to react differently 1,000,000 notifications that a hash tag is being used than ten but isn't going to be reacting any differently to 1,000,001.

On the consumer side, consumers respond to sets of notifications indicating relevance so that the aggregator can pick the items to forward in the future. This is the primary defense against flooding attacks. Producers generating notifications that are consistently flagged as irrelevant will be deprioritized and eventually dropped entirely.

Limiting the notification engine to just reporting the fact that an update has occurred allows the defenses against resource exhaustion attacks to be made more effective as they are not attempting to provide protection across a wider field.

Now obviously, generating plaintext notifications on the basis of the content of encrypted posts is going to compromise confidentiality.
That is going to require some degree of encryption of the notifications and we are probably going to have to accept that there will be some residual leakage even then but certainly less than what leaks from S/MIME because the subject line isn't encrypted.

2
0
0
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 21mo ago

I am spending most of my time on BlueSky right now. They seem to have got decentralization more right than Mastodon has to date.

There is really no reason why the two systems need to be separate.

@hallam@infosec.exchange is an identifier that is controlled by infosec.exchange rather than me.

If Mastodon supported use of the BlueSky handle system, I could be @phill.hallambaker.com in both places, post to both under the same handle, interact with both.

Maybe merging with BlueSky doesn't seem very appealing right now. But one big advantage of their handle system over the Mastodon approach is I can completely control my identity in that forum where here I can't. And I can use my BlueSky identity outside BlueSky.

So I now have a private forums scheme that people can post at using the same account they use with BlueSky.

There are some rough edges but we could knock them off if we got a group of people together to discuss how to get from where we are today to where we really want to be.

Right now, I can only authenticate to my BlueSky account using the BlueSky OAUTH server. Where I want to get to is I can pick my own authentication server and use that to log in anywhere.

3
0
1
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 46mo ago

Having spent nearly 30 years building PKIs, I have some thoughts on the matter that I think may be relevant to adding end-to-end communication capabilities to Mastodon.

1) Don't add crypto capabilities to Mastodon, add them to the Fediverse. If Fred is using some Fediverse version of a Medium/Substack like service, I want to be able to use the same contact info to contact him there as I use here.

2) Don't add crypto capabilities to the Fediverse, add them to the Internet. Take the big picture. All it takes to add an existing service to the Fediverse is to start publishing an Activity Pub (or RSS feed). I remember when people laughed at the idea that the Web would eat AOL and Compuserve less than 12 months before it did exactly that.

Facebook will be the last to join the Fediverse but it will.

3) Don't get hung up over debates about PKI structures. Every functioning open PKI in existence has elements of Web of Trust and brokered trust. A hybrid model is provably superior to either.

4) Don't get hung up on Blockchain either. And by that, I mean recognize that notary hash chains are just another tool, but they are still a very useful one. Just ignore the hyper authoritarian Blockchain bullshit and understand that proof of work is fragile security besides being horrifically inefficient.

I have been using structured cryptography in my designs for over a decade and proposed using a notary chain at IETF before Hal Finney wrote his original BitCoin paper. And that is because of the little bit of magic that happens when you enroll an assertion in a notary chain: The work factor for forging the timestamp goes to close to infinity if you get the construct right. The Mesh uses cross notarization which gives provably superior security (as measured by work factor) to crockchain and consumes (almost) no electricity.

5) End to end is between the public key and the private key. If you don't control either one, your communication is end-to-end but the ends are not what you think.

I don't want to whale on Signal, it is a fine E2E channel. But the Signal app is not end to end as far as I am concerned.

I don't have direct control of my private key, I don't have visibility into the curation of other people's public keys.

Now I used to trust Moxie but then he started pushing weird crypto-Ponzi coins and so that puts him on my 'do not trust' list.

BTW, having helped build the first commercial CA and being a part of that industry for 25 years, I have never taken objection to people asking why they should trust me or my product. But I do find it rather off that while it is very trendy to slag off CAs, usually using false or misleading claims, the same people will then turn round and declare some trendy system beyond all reproach like it has been blessed by the pope himself.

6) Pay close attention to the management of the private keys.

Modern users have multiple devices. They are not going to use your E2E system unless they can read their mail on their phone, laptop and iPad.

I discovered threshold cryptography solves this problem about ten years ago and I am still trying to get people to listen.

The Mesh has the architecture, the specification, even the code you need to do this right.

7) Support key recovery as an option if you want people to encrypt valuable data at rest.

Since I have been attacked by the IRG and have been warned that I am a target of other hostile foreign powers, my approach to securing my most sensitive data is simple: I don't keep any.

If I did keep that type of data, I would keep it separate and use keys that I don't keep recovery capability for.

My photographs and documents are encrypted by default. But I make damn sure I keep the recovery keys.

8) The proper role of Trusted parties is to act as introducers rather than being a continuous active role in the communication thereafter.

Any system that allows me to send mail to an employee at Microsoft in their role at Microsoft is going to end up looking like an X.509/PKIX architecture. You can change the syntax of the certificates, you can call the CA and LRA different things. But the task of credentialing an employee of a corporation or government is going to have a hierarchical structure because that is how enterprises work.

9) You cannot expect to successfully bind any credential to a name that the user does not actually control. Not your name, not your credential.

What this means is that if you are trying to set up some sort of validation process for alice@example.com, the best you will ever manage is to bind the credential to 'example.com'. You are not going to end up with a binding that the holder of example.com cannot corrupt.

10) If you want human readable names bound to a public key, build out the naming infrastructure and the PKI at the same time.

I explore that approach in the callsign registry. To register a callsign entry, Alice first has to generate herself a Mesh account. She then applies to the callsign registry to bind however many callsigns she wants to use to the root signature key of that account.

So, @alice@infosec.exchange, @alice_lastname, @alice1, @alice2 are all aliases for the same Mesh account issued on a first come first served basis.

I have been involved in running registries and while it can be done a lot cheaper than DNS, it cannot be done well without adequate resources. But one very simple way to reduce the cost of running the registry is to issue names that never expire.

It is not clear to me that we need to go that route. But if we did, registration can be done for $0.10 one-time fee.

If we did that, I have a scheme that would also map the callsigns to a fake DNS TLD, mm--. Which has some interesting properties in itself.

Instead of paying ICANN $10/yr for a name that will expire. Alice can pay 1% of that as a one-time fee and get alice.mm--

[Yes, name registries are hard, I was Principal Scientist at VeriSign, I know the issues. That is why I am saying cheap, not free]

12
1
6
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 12mo ago
Replying to
@evan@cosocial.ca Your email address was what I was after as it happens, I seem to have used an obsolete one. Kind of ironic given the topic, eh. Will email you the files tomorrow.
1
1
0
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 25mo ago

If you were wondering how bad it is in the rest of social media, Facebook is now a worse fascist s-hole than Twitter.

Or at least that is the case if you use Twitter Control Panel to purge the HTML of all Musk features, the For Fascism Feed, restore the bird, etc. etc.

My Facebook feed is now 80% Russian bot clickbait memes trying to praise the US Confederacy, claim various celebrities are being cancelled for being 'woke' and praising the mighty Russian military and its stupendous T72 tanks.

The only reason to look at Twitter or Facebook these days is if you study the Russian propaganda efforts which account for a vast amount of traffic on both sites. And so of course it is TikTok which does not have a Russian bot problem which is in court today trying to protect its first amendment rights.

On that front, after years of having these creeps attack me as 'deluded', it gives me great satisfaction to see Tim Pool outed as a $400,000/mo Kremlin prostitute. His claim to not know where the money came from should not be believed. Any organization employing him as a 'journalist' has to be considered to be another Kremlin front.

3
1
1
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 43mo ago

Huge progress on the Mesh last week, I have completed the plumbing for the (optional) naming infrastructure.

Forget all the talk about 'end to end' and 'decentralization'. The single biggest issue for giving ordinary Internet users control over their digital lives is giving them lifelong control over the names they use to identify themselves.

You cannot be a first citizen on Twitter or Facebook because they own your account name and can yank it away at any time they choose. Same for gmail.com.

The Mesh offers three naming alternatives.

The first is a name formed from the base32 fingerprint of your account public key. e.g. MB2GK-6DUF5-YGYYL-JNY5E-RWSHZ.

That name is permanent and unique but it isn't routable. To make it routable, we have to add a location for the current service provider:

MB2GK-6DUF5-YGYYL-JNY5E-RWSHZ@example.com

Now that works but is a pain in the patootie to use. So people are going to demand to use an alias. So Alice can call herself alice@example.com if her service provider is example.com and it agrees.

Now what happens if Alice changes service provider to example.net. Her impractical is easy:

MB2GK-6DUF5-YGYYL-JNY5E-RWSHZ@example.net

But what if alice@example.net was taken? How do people find out Alice's address changed.

The answer to both problems is the callsign registry. And this is the one part of the Mesh that I cannot decentralize fully and cannot run for free at global scale. I can however make it very very cheap.

So first round was the 'change of address service'. Alice uploads a binding declaring that her new service is example.net and people can now find out where she went even if example.com refuses to help.

But for the same cost, the change of address service can issue aliases on a first come first served basis. So Alice can register @alice@infosec.exchange and that is hers for life and it is hers globally. Or at least globally among mesh service providers using the common registry.

So then we get into the political issues to do with how to make a registry and not have it turn out like ICANN's yacht fund with ridiculous fees. $10 is a weeks wages for many people. If we are going to go global, it has to be possible to get a usable name for $0.10.

So the idea is that the registry is a not for profit that funds the development of end to end secure, open applications and code. Callsigns of 9 Latin characters or more are $0.10. Callsigns that are bound to a mesh fingerprint of 24 characters or more are free. Callsigns of 8 characters or less are premium and have higher fees.

(Currently just doing Latin, will add Han, Arabic, Cyrillic, etc.as expertise becomes available).

Names can be used to retrieve a contact assertion which gives access to your address info for any application you wish to share.

One use for this would be in the developer community. Use your Mesh account to manage credentials for your SSH, OpenPGP and PKIX code signing, they are all linked to one identifier allowing traceability across the whole development surface, 'This is the GIT update Bob signed, This is Carol's executable she signed, etc. etc.'

Closing the circle here, while $0.10 isn't nothing, I can also provide DNS type functionality. A callsign binding can optionally specify a DNS server authoritative for the .m3-- domain.

This is a name you can enter into a Web browser and it will work if your DNS server recognizes the .m3-- alt-domain.

So that $0.10 is for a DNS zone for life as well.

OK so how can I promise the names will resolve forever on a one time charge? Simple, understanding where the costs lie in DNS, I have pushed them all off to your Mesh Service Provider.

Registering names is cheap.

Dealing with IPR disputes is expensive but can be entirely shifted to the disputants.

Supporting online resolution of the names is very expensive and the design of the DNS makes that especially so.

So the registry does not provide the resolution service, each Mesh Service Provider does. And that immediately removes 99% of running the resolve which is dealing with abuse from script kiddies trying to 'take down the Internet'. They can't because taking out the registry doesn't stop anything working, it just delays updates to the registrations.

So to sum up, your choices for a Mesh name are:

1) MB2GK-6DUF5-YGYYL-JNY5E-RWSHZ@example.com

2) alice@example.com

3) @alice@infosec.exchange

This really demonstrates a Zokko's triangle, there are three properties, each fails one,

1) Fails usability

2) Fails individual ownership

3) Fails 'free'

Any objections?

4
19
2
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 22mo ago

Change is coming to Social Media and the X-odus and the explosive growth of Blue Sky is just the start.

Blue Sky grew from a few million users to 23 million in three weeks. And not just any users, pretty much all of the core contributors on Twitter have joined the X-odus. Blue Sky has critical mass now, Twitter is starting to deflate.

I have seen a lot of social media go from dominant to dead in the space of a few months: AOL, MySpace, GeoCities, USENET. All gone like tears in the rain.

And don't think that Facebook can't fall as well. It's the toe, not the whole jackboot on the scales at Facebook. But the whole algorithm is skewed for facists. I received the content strike for mentioning The Zuck breaking bread with the Rapist of Mar-a-Largo.

Whether the Fediverse survives or thrives is going to depend on whether it stays on the sidelines of the transformation or is a part of making it happen.

The ATmosphere protocol used by Blue Sky is at least in theory a federated protocol. Whether that is true in practice has yet to be seen. I plan to be setting up my own PDS and testing that federation claim. But more importantly, I am looking at ways to bridge from the ATmosphere to other protocols and communities.

What Facebook offers and Blue Sky does not is forums for private groups. And it is really not clear how the AT protocol lends itself to that mode. Contrawise, the Mathematical Mesh I developed is designed for end-to-end secure private groups with encrypted data at rest. So why not try to put the two together?

I think I have an approach worked out that allows me to use OAUTH2 to bind an account on a private group forum to a Blue Sky account. So this would allow me to use one credential to log into Blue Sky and my private groups. Joining a group is inevitably going to introduce a bit of friction because the whole point of having private groups is they are private, you have to be allowed to join.

I have already bound my Blue Sky account to my private domain so I am @phill.hallambaker.com there.

I would really like to be the same here in the Fediverse.

1
1
1
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 46mo ago
Replying to
@abr @robin @slightlyoff @Edent Like Netscape used to do.
3
0
0
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 12mo ago

@evan@cosocial.ca I was just trying to DM you like your post suggests, but can't find a DM capability.

0
2
0
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 12mo ago

Big progress on my @nyone scheme which allows people to exchange contact card information by means of DNS handles or QR codes in an industry standard format (JSContact) with extensions that support inclusion of cryptographic credentials linked to specific applications and automatic updates.

Why is this important? Because once Alice and Bob exchange their contact information, they each have all the contact addresses and all the cryptographic credentials they support, both today and in the future.

If Alice adds a Signal account to her card after they exchanged contacts, Bob can contact her on Signal without any need for them to meet up again. The Signal option simply appears in his contacts app.

[Now yes, this does raise the problem of how to efficiently notify a set of subscribers to one or more elements in collection of objects of an update to that object. But that is a very general problem and we could apply a solution to that problem to many things. Yes, yes, Bloom filters to you as well].

The piece of the puzzle I solved today is the problem of maintaining multiple identities which I perhaps referred to a little flippantly at HOPE 2025: If you don't want your grandmother knowing you are on FetLife, don't put it in your contact card.

While this advice is surely sound, what if Alice is exchanging her contact information for her addiction support group? We want that to still use modalities like QR codes and NFC and DNS Handles. How can we do that and avoid accidental disclosures?

My solution is that the organization runs a key service for members which will provide keys to decrypt documents encrypted under the club key but ONLY to members of the club.

I won't go into the technical details here but of course I would use threshold cryptography for this. The club service can control decryption but cannot decrypt and has no idea who they are decrypting for.

So, 'all' Alice needs to do is to use an additional layer of encryption to encrypt the club contact card under the club key and to specify that in a format that doesn't reveal which key was involved to anyone that isn't a member of the club.

Can all be built with code I already have.

0
0
0
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 25mo ago

Had to reset my DNS server because some S-head was using it to mask the source of their DDoS attack.

Anyone know of a bind9 switch that reduces the number of requests handled to no more than 200/hr?

The service is on a Digital Ocean droplet and serves 'example.com' so that the test services can perform unit testing and build example material for Internet Drafts.

0
2
1
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 27mo ago

@kate@fosstodon.org Just thought I would write a note to thank you for your site grid.iamkate.com which injects much needed sanity into the attempts to spread disinformation about climate change.

The number of folk who splutter about 'renewables not being viable' when wind is actually used to generate more electricity than fossil fuels in the UK is quite something.

I am not a fan of nuclear power on account of the expense so I get accused of being ignorant quite a bit. I do have a doctorate from Oxford University Department of Nuclear Physics so if that isn't enough not to be ignorant, I don't know what is.

The problem with nuclear is in accounting and the problem with wind/solar is in the intermittency issue.

Nuclear costs at least six times as much as offshore wind, which means we will soon be needing to look at storage to get from 38% renewables to over 60%. So the figure I am interested in right now is what the headroom is for increasing renewables without overcapacity.

0
0
0
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 43mo ago
Replying to
@markd@hachyderm.io @alice@infosec.exchange how do they work though?
0
1
1
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 42mo ago
Replying to
@markd@hachyderm.io OK, now I see where you are coming from. Yes, I have that modality as well. Slightly different implementation but close. My plan is to support BOTH of alice.m3-- RWSHZ.JNY5E.YGYYL.6DUF5.MB2GK.m3-- As DNS domains derived from a Mesh account registration. The difference being: 1) alice.m3-- is much easier to type and to remember. It is 'forever' for as long as the callsign registration binding lasts which is normally forever but can change in certain circumstances. 2) ...MB2GK.m3-- is a pain to type but can be easily generated by an automated tool. It is forever for as long as the destination specified in the binding assertion points to the actual content. Neither is fully forever but can be used as the starting point for forever. So let us think about 100 years hence. Alice wrote a great deal of stuff and put it on her personal Web server and the DNS still points to that IP but that Web server hasn't been active for 30 years now and Alice is dead so the binding can't be updated. So the direct resolution isn't going to work in that particular case but there is enough there for someone with a subscription to some sort of persistence repository to reconstruct a link to some stored data which can then be authenticated using a signature. Incidentally, the reason for reversing the UDF to make the domain is same as for reverse DNS IP lookup, the UDF is Bigendian and DNS is little.
0
1
0
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 42mo ago
Replying to
@markd@hachyderm.io Yeah, I am pretty sure that there is a place for the callsign system even though it will require a registry and thus incur costs. There is no way I can expect people to exchange fingerprints as contact addresses and the ICANN tax is ridiculous. Not acting means perpetuating the ICANN tax. But callsigns are really hailing addresses. They are a way to make contact with Alice. and they will invariably end up being mediated through a callsign binding giving the UDF of the user's root of trust. So we can just transition to the UDF based fingerprint DNS scheme at that point since we are going under the covers anyway. So yes, alice.m3-- still has some value, can type it in to an address bar to get to Alice's Web pages. But it isn't a canonical form and isn't needed as a forever name.
0
1
0
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 42mo ago
Replying to
@markd@hachyderm.io I think we need to go into a bit of semiotics at this point. A callsign is a name, it has the property of thirdness, the relationship between the signifier and the signified is purely a matter of convention. A fingerprint such as a UDF has the property of secondness, the signifier is derived from the signified by a formal construction (SHA2/SHA3) As a result, fingerprints are going to be much more robust as identifiers when used internally. The role of callsigns is really limited to hailing, that is establishing connections between parties. So while MASHZ-E3WR4-.. is the better unique identifier for the machines, there is a value to that layer of indirection. You can put @markd@infosec.exchange on your business card for instance. You can give it out over the phone. My vision here is that we use this technology to support applications like healthcare so you give your callsign to your doctor and it is used as a locator for your private information. So I call up the pharmacy on a legacy telephone, give my callsign @hallam@infosec.exchange and I get a 2FA challenge to my watch to prove I am me. That is not a 1% requirement.
0
1
0
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 46mo ago
Replying to
@securopean@infosec.exchange Take a look at the Mathematical Mesh. It is an infrastructure whose primary purpose is to manage private keys across multiple devices. It uses novel threshold cryptography to allow for a seamless user experience. The credential vault is end-to-end encrypted and only the user's endpoints ever have decryption capability. The system is designed to be resistance to certain types of supply chain manipulation of devices. It takes multiple compromised for any breach to occur. It is all open source and open specification and no proprietary service either. Open as in open. http://mathmesh.com/
mathmesh.com
0
0
0
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 46mo ago
Replying to
That sort of thing is on my list: 1) End to end secure chat/voice/video app 'Everything' for the fediverse. 2) Extend 'Everything' to add Mastodon/RSS feeds. 3) Add augmented feedback: 'give me more/less' and lightweight semantic links. 4) Proof of concept curation engine The last step will give you what you want for buying/selling. And that is the step I don't plan to do more than a proof of concept on because once the APIs are established, anyone can come along and build a better mousetrap. The goal is to have a fediverse of curation engine options. And some of those are going to be engines that are optimized for finding goods for sale. So right now, there is a broken washing machine and a perfectly good but ugly Maytag dryer in my bedroom.LG still hasn't come to collect them under the 'White Glove' service I paid for. Wouldn't it be nice if I could just get rid of them? Yes, I totally get that any sales conduit is going to be a magnet for people spamming it. And that is why any curation engine has to look for content that is liked by people like me. Merely netting out likes/dislikes doesn't work. I do have running code: https://github.com/hallambaker/Mathematical-Mesh The initial client will be based on Microsoft Edge in Kiosk mode: https://github.com/hallambaker/PhillsHypotheticalBrowser If anyone out there does C#, I am looking for collaborators. @ShayneLaughter@masthead.social @dynamicsymmetry@wandering.shop @jenniferplusplus@tech.lgbt
github.com
0
0
1
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 43mo ago
Replying to
@bobwyman@mastodon.social @alice@infosec.exchange if people are interested I will
0
0
1
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 24mo ago
Replying to
@eternaltyro@mastodon.social Absolutely and we all use a frame of some sort. Science is a frame, and not a fixed one either. The science frame we use today is very different from the one a scientist would use in the 1930s or the 1860s. And when we do apply the science frame, we do so in two different modes. As an engineer I use the latest science to build something but as an experimentalist, I employ methodical doubt etc.
0
0
1
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 22mo ago
Replying to
@idlestate@toot.cat Interesting. Having tried to build decentralized, I am thinking BlueSky is doing about as good as can be expected at this stage. People have to start building alternative sites and transferring accounts between them before we really know how open the service is. And I am engaged in some pretty aggressive adversarial interop...
0
0
0
0
Open post
Phillip Hallam-Baker @hallam@infosec.exchange
· 46mo ago
Replying to
I think we want more effective ways of selecting and discovering content. I am a maker and a member of a maker space. So I am probably in your core customer base. But other people are probably less interested. There are some things I want as a maker that are really hard to find. If I could find someone could do a small amount of metal spinning for me, I could finish my Star Trek 3D Chess. @dynamicsymmetry@wandering.shop @jenniferplusplus@tech.lgbt
0
1
1
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 08:26:05 UTC