"Find friends by phone" is a common tool in social networks. We're proposing a secure scheme and requesting comments from the dev community.

Goals: ・Double opt-in: you're not findable by your phone unless YOU use the tool ・Secure to enumeration attacks ・Resistant to decryption if compromised

This article outlines plans for a future Bluesky feature \- it doesn’t exist yet\! By sharing our ideas early, we hope to solicit feedback from the community.

Request For Comments: A secure contact import scheme for social networks | Bluesky

This article outlines plans for a future Bluesky feature \- it doesn’t exist yet\! By sharing our ideas early, we hope to solicit feedback from the community.

81

I wouldn't use it for phone numbers. Not for email addresses either. Potentially I might want to link up with those I've shared a PGP key with, or an approach linked to Yubikeys (or similar). Are they envisaged? If so are there any details you can share?

Replies

No replies yet