silverpill
Developer of ActivityPub-based micro-blogging and content subscription platform Mitra. I help maintain the FEP repository and write my own FEPs too. Currently working on ActivityPub Next.
@greyarea@mitra.vpclmulqdq.moe
I can think of two scenarios where HPKE-level sender authentication or aad binding might be important:
- The sender creates an activity that is attributed to somebody else, encrypts it, and sends to the recipient. This shouldn't be a problem, because the inner activity MUST be portable, and therefore required to have an integrity proof. A compliant recipient can't be fooled into thinking that misattributed activity is real.
- Somebody (e.g. server operator) takes the fep0806:cipherText out of EncryptedActivity, and creates a new activity with the same fep0806:cipherText but different id, actor and/or to. This shouldn't be a problem either. In the worst case, the activity will be delivered to somebody else who will not be able to decrypt it. Replacing id and actor may be even a good thing (obfuscation).
it was a giant mess of w3c specs.
It's an ever-expanding mess of W3C specs, RFCs and FEPs.
Integrity proofs are relatively new, they are described in Data Integrity W3C spec: https://www.w3.org/TR/vc-data-integrity/
Private groups Lately, I've been seeing various people claiming that fediverse doesn't have private groups. They often point to some task force at w3c that is supposedly working to fill the gap.
However, fediverse has had private groups for a very long time:
- Hubzilla channels. This project probably had private groups before ActivityPub. The implementation was later adapted for ActivityPub and refined in subsequent forks, Streams and Forte. It is now partially documented in FEP-171b: Conversation Containers.
- Smithereen groups. This implementation is documented in FEP-400e: Publicly-appendable ActivityPub collections (published in 2021) and FEP-db0e: Authentication mechanism for non-public groups.
- Lemmy communities. Private groups were proposed in Lemmy RFC 0005 and have been implemented in the development version. There is a test instance running this version (Lemmy v1.0b) at https://voyager.lemmy.ml/
There are probably other implementations that I am not aware of.
I added a list of recommended libraries to the ActivityPub developer guide:
https://codeberg.org/ap-next/ap-next/src/branch/main/guide.md#libraries
- activity (Go, used in GoToSocial)
- Fedify (JavaScript, used in Hollo and Ghost)
- Fedipub (Ruby, used in Manyfold)
- activitypub_federation (Rust, used in Lemmy)
- APx (Rust, used in Mitra)
This list only includes libraries that are actually used somewhere. Libraries that are not used, or used in projects with too few users are not included.