this post was submitted on 07 May 2025
505 points (97.9% liked)
Fediverse
37492 readers
111 users here now
A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).
If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!
Rules
- Posts must be on topic.
- Be respectful of others.
- Cite the sources used for graphs and other statistics.
- Follow the general Lemmy.world rules.
Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration)
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
There’s a link in the second paragraph to the technical details, including source code for the implementation and documentation for the required infrastructure.
But the tl;dr is that the tokens aren’t associated to your account. Unless you were able to snoop on the original request that generated the tokens (in which case, you’ve got bigger issues!), there’s no way to prove that a token is related to a specific account. A token only proves that an authorization server once granted access to some account.
Edit: Wikipedia has a good intro:
Edit 2: You should not be catching downvotes. You had a reasonable question.
I'm reminded of this mindset from the crypto scam surge.
Points at technical documents
"Well, it says it's secure so quit arguing that it's not secure"
Typically followed by
"If someone traced you/robbed you, then you were just doing it wrong"
Like, we've got high level white house officials feeding national security secrets to the Israelis because they just blindly implemented a "secure" Signal extension. So I guess I shouldn't be surprised people don't look past the cover.
But come on. "You can just buy some tokens and then you're secure" is painfully naive.
I’m out here trying to answer reasonable questions techie folks might have about the most promising possibility I’ve seen so far for getting our normie families off of Google.
What are you here for? Calling people naive pseudo-scammers? Get out of here.