#social 2016-10-03

2016-10-03 UTC
jungbin, timbl, shepazu_ and dan joined the channel
#
cwebber2
hello #social
#
aaronpk
good morning!
#
cwebber2
how are you aaronpk
#
cwebber2
back from the combo lisbon/london trip
#
cwebber2
back in my home office. It's nice to be back.
#
aaronpk
working on micropub.rocks tests!
#
cwebber2
whee \o/
#
cwebber2
also working on AP things. Go figure!
#
cwebber2
getting a little bit distracted by the intarwebs though
#
cwebber2
too much intarwebs
#
aaronpk
so far my own implementation only failed one test ;-) https://aaronparecki.com/uploads/Screen-Shot-2016-10-03-09-25-13.png
#
cwebber2
cool aaronpk
#
cwebber2
has 3 more responses from wide review sent to private email or via xmpp to add to the document...
#
cwebber2
the majority of responses seem to be "where's the cyrptographic integrity component / signatures" esp from people implementing existing federation systems, which is interesting to see
#
cwebber2
and not what I expected
#
cwebber2
but, since we can't specify auth, and thus can't normatively provide it
#
cwebber2
at least it indicates that we can non-normatively suggest how it might be done
#
aaronpk
interesting
#
aaronpk
tho I feel like it should be possible to specify signing without auth
#
cwebber2
how so aaronpk ?
#
aaronpk
reviews the specific text in our charter about auth being out of scope
#
aaronpk
apparently that was not explicitly excluded in our charter, must have been in a meeting
#
cwebber2
it happened in a few meetings, yeah
#
cwebber2
I think across two face to face meetings iirc
#
aaronpk
oh jeez something here makes my browser pop up the client cert prompt https://www.w3.org/wiki/Socialwg/2015-03-17-minutes
#
cwebber2
I loosely remember the first boston meeting and the SF meeting, though I could be wrong
#
aaronpk
clientcerts--
#
Loqi
clientcerts has -1 karma
#
aaronpk
huh i can't find it
#
aaronpk
anyway I do think verification is different than authentication
#
cwebber2
aaronpk: verification feels like it is authentication, in that you're authenticating that the person who posted it is who they say they are
#
cwebber2
but maybe it's a different authentication mechanism than login
#
aaronpk
i guess it is when you put it that way
tantek joined the channel
#
aaronpk
which is why i was trying to find the reasons we excluded authentication
#
aaronpk
authentication as a login mechanism is a different beast
#
aaronpk
i'm pretty sure we all agreed that coming up with a login mechanism was the thing that was out of scope
#
cwebber2
aaronpk: well, it's *potentially* a different beast :)
#
cwebber2
you might use the same mechanism
#
cwebber2
aaronpk: it's more likely a much more related beast if you're talking about authentication *between* servers and you use signatures for it
#
cwebber2
as in, a user on server A is having its client authorized to post as itself, and presents that to server B
#
cwebber2
but I suppose for client -> server on server A, the client would have either its own key or token anyway.
#
aaronpk
related, I was pretty happy about the minimal "auth" we used for private webmention. it avoids the need for user accounts and user identity entirely: https://aaronparecki.com/2016/09/30/12/private-webmentions
#
Loqi
[Aaron Parecki] First draft of Private Webmention sending
#
cwebber2
aaronpk: ah, it's based on generating tokens for specific URLs?
#
cwebber2
though, it will mean storing up a lot more tokens I guess
#
@csarven
@dret We are also referring to Accept-Post at https://www.w3.org/TR/ldn/ and wanted to double check.
(twitter.com/_/status/782984099262763012)
#
aaronpk
kind of. it actually leaves it open to the implemenation to decide whether to do it per URL or per domain or whatever
#
aaronpk
also if you use self-encoded tokens you don't even need to store them
#
aaronpk
basically it leaves open some interesting possibilities for implementation specific details like that, while still being specified enough to be interoperable
#
tantek
that's one of the most important balances to strike in writing a good spec / standard
#
tantek
(also really happy to see this discussion here between aaronpk cwebber2 )
#
tantek
aaronpk++
#
Loqi
aaronpk has 1111 karma (62 in this channel)
#
tantek
cwebber2++
#
Loqi
cwebber2 has 72 karma
#
aaronpk
anyway it's interesting that that's the feedback you're getting!
tantek and shepazu joined the channel