erlend, (edited )
@erlend@writing.exchange avatar

There’s a major convergence of OAuth/OIDC support across applications, is going all-in on it as its root default, and other social web protocols are tagging along as well.

Like the separation of church and state, it seems prudent to keep the management of our digital identities separate from our social network servers.

Domain-based OIDC accounts with web sign-in, especially when self-hosted, serve the function of a minimum-viable

https://socialhub.activitypub.rocks/t/autonomous-identity-for-the-pluriverse-based-on-oauth-oidc/3675?u=erlend_sh

dameoutlaw,

@erlend what’s with people’s negative responses? The current system isn’t cutting it but let’s not try something anyways?
I think using DIDs makes sense

jaxter184,

@erlend ive only recently started exploring the current state of decentralized identity, but do you have any resources that could explain why fediverse and matrix stuff needs oidc rather than just indieauth?

and you mentioned that theyre not really compatible with each other. does that mean that we need to pick one and discard the other?

erlend,
@erlend@writing.exchange avatar

@jaxter184 We need something like IndieAuth, I.e. ‘web sign-in’. But IndieAuth is an extension of OAuth that predates OIDC and is not compatible with it. Mastodon already supports its own form of ‘web sign-in’, and this too is a custom thing rather than IndieAuth exactly.

hueso,
@hueso@kosmos.social avatar

@erlend that's pretty much what Nostr does.

erlend,
@erlend@writing.exchange avatar

@hueso it’s what a lot of other things do, but none of those are already widely implemented across most fediverse apps, which OIDC is. It’s an already adopted standard, not a new thing that would take years of advocacy and coordination.

silverpill,
@silverpill@mitra.social avatar

@erlend The end result of wide OIDC adoption is "Sign In With Google" buttons everywhere in Fediverse. This will also stifle adoption of decentralized identity systems (that's why this broken and outdated standard is being pushed so hard by megacorps).

erlend,
@erlend@writing.exchange avatar

@silverpill I don’t think you read my proposal if that’s what you’re taking away from this.

Web sign-in (like IndieAuth) by OIDC is the antidote to the auth-monopoly of the megacorps.

jenniferplusplus,
@jenniferplusplus@hachyderm.io avatar

@erlend I am very sympathetic to this desire to have some kind of self-controlled portable identity. But I also have to consider that it's already incredibly hard to get a new project onto the fediverse, and this would likely add to that.

erlend,
@erlend@writing.exchange avatar

@jenniferplusplus sure. On the plus side, this isn’t so much an addition to the fediverse as it is a minor reconfiguration of the status quo.

A proof of concept can be put together by a single developer.

darius,
@darius@friend.camp avatar

@erlend appreciate your disclaimer re "inability to follow the exact technicalities of authentication specifications" haha

  • All
  • Subscribed
  • Moderated
  • Favorites
  • fediverse
  • DreamBathrooms
  • magazineikmin
  • InstantRegret
  • GTA5RPClips
  • ngwrru68w68
  • Youngstown
  • cisconetworking
  • slotface
  • everett
  • rosin
  • Durango
  • kavyap
  • tacticalgear
  • mdbf
  • provamag3
  • thenastyranch
  • normalnudes
  • tester
  • modclub
  • khanakhh
  • ethstaker
  • cubers
  • osvaldo12
  • megavids
  • Leos
  • anitta
  • JUstTest
  • lostlight
  • All magazines