Comment on How decentralized Bluesky is compared to the Fediverse.
General_Effort@lemmy.world 5 days agoIt’s doable with E2E encryption,
How?
Comment on How decentralized Bluesky is compared to the Fediverse.
General_Effort@lemmy.world 5 days agoIt’s doable with E2E encryption,
How?
Natanael@infosec.pub 5 days ago
peergos.org
General_Effort@lemmy.world 4 days ago
Wait. What is the relation to vote federation?
Natanael@infosec.pub 4 days ago
They’re implementing E2E encrypted social stuff. Voting privacy and encryption is linked.
Especially when you have users across multiple servers and both want voting privacy AND being able to deal with vote manipulation. You need stuff like pseudonymous commitments per account attested to by the hosting instance, etc. The only thing that’s simpler but still private is having instances just digitally sign a total vote tally, which also means you can’t detect vote manipulation on other servers at all.
General_Effort@lemmy.world 4 days ago
But accounts are already pseudonymous?
Here’s where I am at:
I can check if my votes are federated correctly by checking if any of my votes are suppressed or votes in my name are made up. If my instance sends a different random token with each vote, I can still do that, as long as I know which tokens are assigned to my votes.
But vote tallies can also be manipulated by making up new votes through fake/bot accounts. If a vote can be connected to posts, this can be checked to some degree. Say, if an instance has a lot of voters that never post, that indicates a problem.
I don’t see how the second thing with E2EE.