this post was submitted on 26 Jun 2023
0 points (NaN% liked)

Fediverse

36098 readers
77 users here now

A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).

If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!

Rules

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration)

founded 2 years ago
MODERATORS
 

I'm trying to better understand Activitypub and I understand that there's a signature to avoid forgeries of known accounts.

However I'm having trouble understanding what prevents a malicious actor from sending a private spam message supposedly from a never before seen account name with valid generated key pair but for a domain they've never bought since there is no DNS lookup or test.

Thank you!

you are viewing a single comment's thread
view the rest of the comments
[–] syboxez@lemmy.world 1 points 2 years ago

On the point of 2, it could be made optional, so that the user could choose.