#FediHood and #HolosSocial, two separate #Fediverse projects (that I maintain), can now send each other #E2EE DMs, fully over #ActivityPub.
-
#FediHood and #HolosSocial, two separate #Fediverse projects (that I maintain), can now send each other #E2EE DMs, fully over #ActivityPub.


-
#FediHood and #HolosSocial, two separate #Fediverse projects (that I maintain), can now send each other #E2EE DMs, fully over #ActivityPub.


Small clarification: FediHood is fully a web app, like other Fediverse software (Mastodon, Pleroma, etc.). I reused the work I did on HolosSocial, which already used the Signal Protocol.
I'll write a FEP about it, since it works well. -
Small clarification: FediHood is fully a web app, like other Fediverse software (Mastodon, Pleroma, etc.). I reused the work I did on HolosSocial, which already used the Signal Protocol.
I'll write a FEP about it, since it works well.@apps
Does Signal offer a stable API for third-party developers? Is it documented? -
@amd
I'm following what they're doing, though it works differently: they're going for MLS over ActivityPub, while I use the Signal Protocol. With HolosSocial I already had something working and published, so I just extended it to my other project. Once their approach is available, I even suggested switching to it. -
@apps
Does Signal offer a stable API for third-party developers? Is it documented?@nunesgh
The Signal Protocol (i.e. the encryption itself) is an open, documented spec with open libraries (libsignal). I use the protocol, not Signal's API or servers. -
Small clarification: FediHood is fully a web app, like other Fediverse software (Mastodon, Pleroma, etc.). I reused the work I did on HolosSocial, which already used the Signal Protocol.
I'll write a FEP about it, since it works well.@apps
Could you tell me, what the fedihood project is? Is there any website?
I tried to find more info, but I couldn't. -
@apps
Could you tell me, what the fedihood project is? Is there any website?
I tried to find more info, but I couldn't.@wloczykij
I've written several posts recently with the #FediHood tag, you should find all the details there. -
@nunesgh
The Signal Protocol (i.e. the encryption itself) is an open, documented spec with open libraries (libsignal). I use the protocol, not Signal's API or servers.@apps
Thank you for your reply!
Did you reimplement the protocol or did you vendor libsignal? -
@apps
Thank you for your reply!
Did you reimplement the protocol or did you vendor libsignal?@nunesgh
I vendored, not reimplemented. I use https://www.npmjs.com/package/@privacyresearch/libsignal-protocol-typescript, a pure TS port of libsignal running on Web Crypto. I only wired the sessions and the ActivityPub transport. -
Small clarification: FediHood is fully a web app, like other Fediverse software (Mastodon, Pleroma, etc.). I reused the work I did on HolosSocial, which already used the Signal Protocol.
I'll write a FEP about it, since it works well.@apps Very cool, is this MLS? Would be awesome to make Loops compatible with this!
-
@apps Very cool, is this MLS? Would be awesome to make Loops compatible with this!
@dansup
Unfortunately not, but I am following what is being done
-
#FediHood and #HolosSocial, two separate #Fediverse projects (that I maintain), can now send each other #E2EE DMs, fully over #ActivityPub.


@apps@toot.fedilab.app just pinging @benpate@mastodon.social to bring this to his attention. <img class="not-responsive emoji" src="https://activitypub.space/assets/plugins/nodebb-plugin-emoji/emoji/android/1f604.png?v=8161d5c9b56" title="
" />Very cool!
-
#FediHood and #HolosSocial, two separate #Fediverse projects (that I maintain), can now send each other #E2EE DMs, fully over #ActivityPub.


@apps Hey, cool news, and congrats on this development!
I saw below that you’re planning an FEP. I’d love to read what you’ve got, once it’s published

And yeah @all - we’ve talked about interior with Bonfire and Emissary. One thing at a time.. but that’ll be important once Mastodon joins the party next year.
-
@SpaceLifeForm
In the browser, in IndexedDB (one store per account), kept encrypted with a non-extractable AES-GCM key, and wiped on logout. The server only ever sees public keys and encrypted messages, never private keys. -
@SpaceLifeForm
It's the Signal Protocol via libsignal, not handmade. Your message reaches the server the moment you send it, so logout never loses it and delivery doesn't depend on your session. The server only holds public keys and ciphertext, held 30 days for pickup. Each message is bound to the sender's identity key, so the recipient can confirm who sent it, verified by a safety number. Logout only wipes local keys, affecting old history on a new device. Key backup is planned.
Ciao! Sembra che tu sia interessato a questa conversazione, ma non hai ancora un account.
Stanco di dover scorrere gli stessi post a ogni visita? Quando registri un account, tornerai sempre esattamente dove eri rimasto e potrai scegliere di essere avvisato delle nuove risposte (tramite email o notifica push). Potrai anche salvare segnalibri e votare i post per mostrare il tuo apprezzamento agli altri membri della comunità.
Con il tuo contributo, questo post potrebbe essere ancora migliore 💗
Registrati Accedi
Citiverse è un progetto che si basa su NodeBB ed è federato! | Categorie federate | Chat | 📱 Installa web app o APK | 🧡 Donazioni | Privacy Policy