Nomadic Identity Is Coming to ActivityPub
wedistribute.org
wedistribute.org
Auth can be subtle and I'm likely missing some things, but the UX appears to be essentially equivalent to OIDC, especially given the caveat at the bottom which states users might want to consent before exposing their identity to any random server.
So I'm assuming the benefit here is that the logins themselves and any actions you take are tied to your public key and not the domain you use to host your key at any given point in time? Do they talk at all about the typical issues with PKI identity, ie lost/compromised private keys?
[0]: https://codeberg.org/fediverse/fep/src/branch/main/fep/61cf/...
[1]: https://socialhub.activitypub.rocks/t/fep-61cf-the-openwebau...
My current server has been very slow and I’ve wanted to move. I’ll wait till this is fully deployed and then give it a shot!
Mastodon are not known for adding support for other ActivityPub implementations extra features. I doubt they'll look into this any time soon.
Maybe a dedicated archive would be better. It would be a matter of generating a static website from the export. Nobody else would need to moderate it, because it’s not their website.
Unless you have key-based naming (userId@keyFingerprint), you have to rely on a server running at the domain to be the ultimate authority on legitimacy of identities anyway, right? Exchanging a single shared secret between servers seems like a much more lightweight way to do that.
For portability, couldn't userId@example.com publish a message saying that it is now (only-or-also) known as userId@othersite.com? If example.com had the private key at some point and you were moving permanently, you'd need to generate a new one anyway and need to publish a similar message, so why have the keys at all vs. the server just saying "yeah that's my user"?