This part can be addressed easily with avatars such as those Gravatar makes. Using a blockchain instead seems like a huge overkill, and also brings 'login' back into the equation, albeit with a different connotation than traditional login.
A gravatar is great for a profile photo, but in the end, there's no guarantee that the message viewed by a user was actually written by the poster. A site admin could simply inject posts as that user.
With signed messages, only those who possess the key could have created the signature for the signed message. Even a site admin cannot edit the message and get away with it (since the signature wouldn't validate).
If you think about it, this is also true for web3 — true enough that it's broken.
We don't live in a world where you can't take things from people, etc.
Ultimately, society works because we don't really need ironclad guarantees — and we don't have any.
You absolutely cannot fake a message being cryptographically signed without providing a broken verification function.
> We don't live in a world where you can't take things from people, etc.
The half glass empty approach is one method. The other method is to review the primitives we have in place today and explore different permutations that allow us to route around our adversities. That's the Hacker way. Of course, we do it with code.
> Ultimately, society works because we don't really need ironclad guarantees like that.
The society you live in is very different from mine. Fraud and impersonation are real. [1]
[1] https://www.theverge.com/2016/11/23/13739026/reddit-ceo-stev...
How about by obtaining the private key?
And getting access to private keys can happen by means other than the user volunteering them.
I think it might be wise to review what signing means to understand that I didn't "move the goalposts" at all [1], but thanks for the discussion, as I merit it will help a lot of people to better understand the power of cryptography as I'm guessing it's a new field here as of yet.
Happy New Year!
As always, there's a relevant XKCD https://xkcd.com/538/
If Person B published a message under Person A's name, that is, to the non-crypto world, a faked post. They're not going to be impressed by your argument that actually it isn't faked, it's real, Person B just had access to Person A's computer.
Happy new year.
I'm not making a comment out of pedantry, I'm telling you how I expect this is going to be seen by regular users. People on the whole are not interested in whether or not some particular security system is theoretically perfect, they're interested in whether or not it actually provides the security that they interpret it to promise. And they will interpret your claims as meaning that messages cannot come from anyone other than the signed user, which is going to be a problem the first time that assumption fails. And it will fail, because people aren't good at keeping secrets secret.
So if I wanted to make a post, I first generate a public-private key pair, and then sign posts using my public key?