Natanael

joined 1 year ago
[–] Natanael@slrpnk.net 4 points 9 months ago

We need pictures when it's done

[–] Natanael@slrpnk.net 1 points 9 months ago

No it does not because you can cut out the timestamp and put it into anything if the timestamp doesn't encode anything about the frame contents.

It is always possible to backdate file edits.

Sure, public digital timestamping services exists, but most people will not check. Also once again, an older timestamp can simply be cut out of one file and posted into another file.

You absolutely must embedd something which identifies what the media file is, which can be used to verify ALL of the contents with cryptographic signatures. This may additionally refer to a verifiable timestamp at some timestamping service.

[–] Natanael@slrpnk.net 1 points 9 months ago (2 children)

That doesn't prove that the data outside the timestamp is unmodified

[–] Natanael@slrpnk.net 1 points 9 months ago

I think the best bet is really video formats with multiple embedded streams carrying complementary frame data (already exists) so you decide video quality based on how many streams you want to merge in playback.

If you then hashed the streams independently and signed the list of hashes, then you have a video file which can be "compressed" without breaking the signature by stripping out some streams.

[–] Natanael@slrpnk.net 4 points 9 months ago

This would work very well with a text adventure game, though. A lot of them are already set in fantasy worlds with cosmic horrors everywhere, so this would fit well to animate what's happening in the game

[–] Natanael@slrpnk.net 4 points 9 months ago

Aerogel is also fragile

[–] Natanael@slrpnk.net 1 points 9 months ago (2 children)

No, it took a week to refine the attack algorithm, the collision generation itself is fast

The point of perceptual hashes is to let you check if two things are similar enough after transformations like scaling and reencoding, so you can't rely on that here

[–] Natanael@slrpnk.net 2 points 9 months ago (1 children)

If you look at the nodes which are most likely to trigger from given inputs then you can draw paths

[–] Natanael@slrpnk.net 1 points 9 months ago

You can't use a MAC for public key signatures. That's ECC, RSA, and similar.

[–] Natanael@slrpnk.net 2 points 9 months ago* (last edited 9 months ago)

Not in ActivityPub no.

The main privacy/security issue is mostly mitigated by the fact that there's a sync behavior for accounts and follows and distribution of content where the host can push revocation messages, triggering other servers to delete follows and wipe cached account data originating from that hosting server, which means that somebody who takes over a domain after a wipe can't imitate the exact same accounts. But old links can still be redirected because there's no way to verify what they were supposed to point to, so some degree of impersonation remains possible unless other servers agree to preemptively defederate...

[–] Natanael@slrpnk.net 1 points 9 months ago

It's really only long range travel away from grids (like maybe autonomous trucks traveling through very large unpopulated areas, but not on rail or boat) where hydrogen has meaningful advantages due to energy density. Anywhere else there's something else which is comparable or better.

view more: ‹ prev next ›