It has nothing to do with the identity verification a la Keybase, unfortunately, as that would be a really good and useful feature for the fediverse, but I think it would be a lot harder to do.
It has nothing to do with the identity verification a la Keybase, unfortunately, as that would be a really good and useful feature for the fediverse, but I think it would be a lot harder to do.
... thinking it through, maybe not. I guess if a client initiates AddVerification for some twitter handle, and the directory service sends that handle a private twitter message with some guid, and then the client sends AddVerificationStepTwo with that guid, the directory service could append both of those messages to attest that that user is associated with that handle. A malicious directory service (or a real directory service that's calling a malicious twitter clone) could fail to correctly verify someone, but it wouldn't be able to add a verification for the wrong client or for a client that didn't initiate it, which is probably good enough?
edit: just realized you're the author, thanks for working on this stuff!