<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>Yarmo - keyoxide</title>
    <subtitle>Blog of an Open Source developer</subtitle>
    <link rel="self" type="application/atom+xml" href="https://yarmo.eu/tags/keyoxide/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://yarmo.eu"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2021-06-29T14:52:10+00:00</updated>
    <id>https://yarmo.eu/tags/keyoxide/atom.xml</id>
    <entry xml:lang="en">
        <title>Keyoxide Project Update #5</title>
        <published>2021-06-29T14:52:10+00:00</published>
        <updated>2021-06-29T14:52:10+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yarmo.eu/blog/keyoxide-project-update-5/"/>
        <id>https://yarmo.eu/blog/keyoxide-project-update-5/</id>
        
        <content type="html" xml:base="https://yarmo.eu/blog/keyoxide-project-update-5/">&lt;p&gt;An update for all.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Accessibility&quot;&gt;Accessibility&lt;&#x2F;h2&gt;
&lt;p&gt;The latest 3.1.0 release of &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;keyoxide&#x2F;keyoxide-web&quot;&gt;keyoxide-web&lt;&#x2F;a&gt; greatly improves accessibility 
and ensures that it works nicely together with screen readers.&lt;&#x2F;p&gt;
&lt;p&gt;To make sure the implementation of accessibility features was as thorough as possible, it was first ran through a series
of automated tests, namely &lt;a href=&quot;https:&#x2F;&#x2F;web.dev&#x2F;measure&#x2F;&quot;&gt;Lighthouse&lt;&#x2F;a&gt; and &lt;a href=&quot;https:&#x2F;&#x2F;wave.webaim.org&#x2F;&quot;&gt;WAVE&lt;&#x2F;a&gt;, both giving
Keyoxide respectively a &lt;strong&gt;100% accessibility score&lt;&#x2F;strong&gt; and &lt;strong&gt;0 accessibility errors&lt;&#x2F;strong&gt; on every page.&lt;&#x2F;p&gt;
&lt;p&gt;While automated tests are a decent start, nothing beats feedback from the actual target audience: good ol&#x27; human beings.&lt;&#x2F;p&gt;
&lt;p&gt;After &lt;a href=&quot;https:&#x2F;&#x2F;fosstodon.org&#x2F;@keyoxide&#x2F;106380848176122986&quot;&gt;posting a message&lt;&#x2F;a&gt; on the Keyoxide fediverse account 
(&lt;a href=&quot;https:&#x2F;&#x2F;fosstodon.org&#x2F;@keyoxide&quot;&gt;keyoxide@fosstodon.org&lt;&#x2F;a&gt;) to call for help from people who use accessibility tools
like screen readers, I received plenty of feedback about little quirks that went undetected by the automated tests.
These were all addressed and fixed.&lt;&#x2F;p&gt;
&lt;p&gt;So I can now gladly confirm that the Keyoxide website should be &lt;strong&gt;WAI-AA&lt;&#x2F;strong&gt; compliant, meaning all text has a contrast
ratio higher than 4.5:1, all links and images are appropriately labeled for screen readers and even the profile pages 
can be navigated by keyboard alone.&lt;&#x2F;p&gt;
&lt;p&gt;I once again thank the people that have provided the invaluable feedback without whom the result of my efforts would
have proven unsufficient.&lt;&#x2F;p&gt;
&lt;p&gt;If you find more quirks and&#x2F;or annoyances, please do file an issue on the
&lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;keyoxide&#x2F;keyoxide-web&#x2F;issues&quot;&gt;code repository&lt;&#x2F;a&gt; so it can be fixed as quickly as possible.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;#keyoxide_on_IRC&quot;&gt;#keyoxide on IRC&lt;&#x2F;h2&gt;
&lt;p&gt;Keyoxide was just about to request a channel on freenode when sadly, well, &lt;em&gt;that&lt;&#x2F;em&gt; happened.&lt;&#x2F;p&gt;
&lt;p&gt;So now, it is with delight that I can now invite you all to our &lt;strong&gt;#keyoxide&lt;&#x2F;strong&gt; channel on the great
&lt;a href=&quot;https:&#x2F;&#x2F;libera.chat&#x2F;&quot;&gt;libera.chat&lt;&#x2F;a&gt; network. In addition to our Matrix room, this is one more place where we can hang
out and discuss the future of identity on the internet. And many other things.&lt;&#x2F;p&gt;
&lt;p&gt;And yes, of course I have already proven my identity on IRC using the
&lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;irc&quot;&gt;IRC guide on Keyoxide&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Signing_off&quot;&gt;Signing off&lt;&#x2F;h2&gt;
&lt;p&gt;For all your questions and suggestions, be sure to join the conversation in the
&lt;a href=&quot;https:&#x2F;&#x2F;matrix.to&#x2F;#&#x2F;#keyoxide:matrix.org&quot;&gt;Keyoxide matrix room&lt;&#x2F;a&gt; or the #keyoxide channel on 
&lt;a href=&quot;https:&#x2F;&#x2F;libera.chat&#x2F;&quot;&gt;libera.chat&lt;&#x2F;a&gt;. Or raise an issue on &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;keyoxide&#x2F;&quot;&gt;Codeberg.org&lt;&#x2F;a&gt;.
All contributions (including PRs!) are welcome.&lt;&#x2F;p&gt;
&lt;p&gt;As always, the source code is available at the &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;keyoxide&#x2F;keyoxide-web&quot;&gt;Codeberg.org repo&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;All work on Keyoxide is possible thanks to donations, the project stands against VC funding. If you feel like Keyoxide
is a step in the right direction for netizens worldwide, please &lt;a href=&quot;https:&#x2F;&#x2F;liberapay.com&#x2F;Keyoxide&#x2F;&quot;&gt;become a patron&lt;&#x2F;a&gt; and
help the project do its part in the global fight against the internet corporations.&lt;&#x2F;p&gt;
&lt;p&gt;Until next time,&lt;br &#x2F;&gt;
Yarmo&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Keyoxide Project Update #4</title>
        <published>2021-05-04T17:52:10+00:00</published>
        <updated>2021-05-04T17:52:10+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yarmo.eu/blog/keyoxide-project-update-4/"/>
        <id>https://yarmo.eu/blog/keyoxide-project-update-4/</id>
        
        <content type="html" xml:base="https://yarmo.eu/blog/keyoxide-project-update-4/">&lt;p&gt;The update I have been looking forward to for months.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Keyoxide_3.0.0&quot;&gt;Keyoxide 3.0.0&lt;&#x2F;h2&gt;
&lt;p&gt;Every day I work on Keyoxide, I learn more and gain a deeper understanding of how powerful this Decentralized
OpenPGP-based Identity verification actually can be. And as we are nearing the first anniversary of the Keyoxide project,
I realized all the new ideas and major improvements—most suggested by the community—were being held back by
the previous implementation of the code, restricted by my earlier understanding and imagination.&lt;&#x2F;p&gt;
&lt;p&gt;It was time not for a number of superficial additions and fixes, but for a big overhaul of the core code which would
then cause a chain reaction of bugs to be fixed and features to be added or improved.&lt;&#x2F;p&gt;
&lt;p&gt;To illustrate what is new in this version, here&#x27;s my
&lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;9f0048ac0b23301e1f77e994909f6bd6f80f485d&quot;&gt;Keyoxide profile&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;Visuals&quot;&gt;Visuals&lt;&#x2F;h3&gt;
&lt;p&gt;Ok, let&#x27;s do start superficial, though. Keyoxide 3.0.0 has a shiny new look. I hope you will agree with me that that
was much needed. The previous design of the website was made before I even implemented the concept of decentralized
proofs.&lt;&#x2F;p&gt;
&lt;p&gt;The new and cleaner design has eliminated most of the clutter and puts all the emphasis on what is important: the
identity claims.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;Server_side_rendering&quot;&gt;Server side rendering&lt;&#x2F;h3&gt;
&lt;p&gt;Thanks to the class-based approach of the &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;keyoxide&#x2F;doipjs&#x2F;&quot;&gt;doip.js library (version 0.12.*)&lt;&#x2F;a&gt;,
Keyoxide will now do most of the mundane work on the server and let the browser finish the process of identity
verification. So who does exactly what now?&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;The server will try and find the public key associated with the profile to be generated&lt;&#x2F;li&gt;
&lt;li&gt;The server will parse the identity claims stored inside the public key&lt;&#x2F;li&gt;
&lt;li&gt;The server will match the identity claims to the known library of service providers&lt;&#x2F;li&gt;
&lt;li&gt;The server will render the profile page, including the yet-to-be-verified identity claims, and send it to the browser&lt;&#x2F;li&gt;
&lt;li&gt;The browser will parse the yet-to-be-verified identity claims and verify them&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Not only is the website now much faster to load, the browser will verify the identity claims in parallel! No more
waiting for that one slow identity to verify before showing the result of all the other identity verifications.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;rel=&amp;quot;me&amp;quot;&quot;&gt;rel=&amp;quot;me&amp;quot;&lt;&#x2F;h3&gt;
&lt;p&gt;The wait is finally over! Server-side rendering means that Mastodon instances can now detect the &lt;strong&gt;rel=&amp;quot;me&amp;quot;&lt;&#x2F;strong&gt; links
on Keyoxide profile pages and will reward you with a green tick for every Keyoxide profile you link to in your
Mastodon bio!&lt;&#x2F;p&gt;
&lt;p&gt;Here&#x27;s an example: &lt;a href=&quot;https:&#x2F;&#x2F;fosstodon.org&#x2F;@keyoxide&quot;&gt;@keyoxide@fosstodon.org&lt;&#x2F;a&gt;. So satisfying!&lt;&#x2F;p&gt;
&lt;p&gt;Yes, this means Keyoxide can now do and be as much as &amp;quot;any other&amp;quot; identity provider on Mastodon. By just using basic
web technology. Without requiring special server protocols. And no VC-funded companies needed.&lt;&#x2F;p&gt;
&lt;p&gt;Small web truly is beautiful, isn&#x27;t it? (quote from &lt;a href=&quot;https:&#x2F;&#x2F;small-tech.org&#x2F;&quot;&gt;Small Tech Foundation&lt;&#x2F;a&gt;)&lt;&#x2F;p&gt;
&lt;h3 id=&quot;A_claim_failed,_what_does_that_mean?&quot;&gt;A claim failed, what does that mean?&lt;&#x2F;h3&gt;
&lt;p&gt;The issue of a claim failing to verify is actually more complex than it seems, and something that the previous versions
of Keyoxide did not handle very elegantly.&lt;&#x2F;p&gt;
&lt;p&gt;As an example, let us claim to be Alice on Github. If it fails, it could either mean that we made a mistake somewhere,
or we are attempting to impersonate Alice—the very thing Keyoxide is designed to detect and prevent.&lt;&#x2F;p&gt;
&lt;p&gt;In this case, it&#x27;s simple: the claim &lt;code&gt;https:&#x2F;&#x2F;gist.github.com&#x2F;Alice&#x2F;...&lt;&#x2F;code&gt; could only reference Github so the story ends
here.&lt;&#x2F;p&gt;
&lt;p&gt;But what if we wanted to verify &lt;code&gt;https:&#x2F;&#x2F;alice.tld&#x2F;apps&#x2F;live&lt;&#x2F;code&gt;? From the looks of it, it could be an
&lt;a href=&quot;https:&#x2F;&#x2F;owncast.online&#x2F;&quot;&gt;Owncast&lt;&#x2F;a&gt; server, but that is just a guess.&lt;&#x2F;p&gt;
&lt;p&gt;When this claims fails to verify, does it fail because that Owncast server is not mine (impersonation) or because it
wasn&#x27;t actually an Owncast server? This URL could also very well lead to a repo on a &lt;a href=&quot;https:&#x2F;&#x2F;gitea.io&#x2F;&quot;&gt;Gitea&lt;&#x2F;a&gt; server.&lt;&#x2F;p&gt;
&lt;p&gt;And what if it also fails to verify as a Gitea account? Was it one of them that genuinely failed, or neither of them?&lt;&#x2F;p&gt;
&lt;p&gt;Keyoxide 3.0.0 now recognizes &amp;quot;ambiguity&amp;quot; in URLs and acts accordingly. Does a claim with an unambiguous URL (like
Github) fail? Keyoxide will let the visitor know the claim genuinely failed. Did a claim with an ambiguous URL fail?
Then Keyoxide will show a message letting the visitor know that it wasn&#x27;t sure what the claim was meant to be but
regardless, it failed to verify.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Future_improvements&quot;&gt;Future improvements&lt;&#x2F;h2&gt;
&lt;p&gt;Keyoxide 3.0.0 brings a few tweaks, but again, the biggest change is the overhaul of the core code. This will allow
a bunch more improvements to be made soon with relative ease. Here&#x27;s an overview of what is in the pipeline.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;Requirement_of_JavaScript&quot;&gt;Requirement of JavaScript&lt;&#x2F;h3&gt;
&lt;p&gt;Previous versions of Keyoxide said &amp;quot;the browser must do everything&amp;quot;. This meant that JavaScript had to enabled in order
for Keyoxide to be able to do anything at all.&lt;&#x2F;p&gt;
&lt;p&gt;As stated above, Keyoxide 3.0.0 now only lets the browser do the very last step of the whole process but this still
means JavaScript is required. However, it is not difficult to imagine now that the server could do everything and just
send the finished profile page to the browser.&lt;&#x2F;p&gt;
&lt;p&gt;In a future version of Keyoxide, visitors who have JavaScript disabled and do not mind waiting for up to fifteen seconds
(due to some claims taking more time to verify) will be able to request a fully server-side rendered profile page.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;a11y_and_i18n&quot;&gt;a11y and i18n&lt;&#x2F;h3&gt;
&lt;p&gt;With more work being done server-side, it becomes simpler to implement internationalisation and render the website in
different languages.&lt;&#x2F;p&gt;
&lt;p&gt;Also, with the pages themselves become less dynamic, decent accessibility is also simpler to achieve and currently has
the highest priority.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Signing_off&quot;&gt;Signing off&lt;&#x2F;h2&gt;
&lt;p&gt;That&#x27;s about it for today. This update marks a big change that will greatly benefit future versions of Keyoxide. I can&#x27;t
wait to start working on the next developments and share them with you as they come along.&lt;&#x2F;p&gt;
&lt;p&gt;As always, the source code is available at the &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;keyoxide&#x2F;keyoxide-web&quot;&gt;Codeberg.org repo&lt;&#x2F;a&gt;
(now renamed to &lt;strong&gt;keyoxide-web&lt;&#x2F;strong&gt;).&lt;&#x2F;p&gt;
&lt;p&gt;For all your questions and suggestions, be sure to join the conversation in the
&lt;a href=&quot;https:&#x2F;&#x2F;matrix.to&#x2F;#&#x2F;#keyoxide:matrix.org&quot;&gt;Keyoxide matrix room&lt;&#x2F;a&gt; or raise an issue on
&lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;keyoxide&#x2F;&quot;&gt;Codeberg.org&lt;&#x2F;a&gt;. All contributions are welcome!&lt;&#x2F;p&gt;
&lt;p&gt;Until next time.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Keyoxide Project Update #3</title>
        <published>2021-03-09T16:00:00+00:00</published>
        <updated>2021-03-09T16:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yarmo.eu/blog/keyoxide-project-update-3/"/>
        <id>https://yarmo.eu/blog/keyoxide-project-update-3/</id>
        
        <content type="html" xml:base="https://yarmo.eu/blog/keyoxide-project-update-3/">&lt;p&gt;Two months since the last update. Two great new additions for this one.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Keyoxide_2.5.0&quot;&gt;Keyoxide 2.5.0&lt;&#x2F;h2&gt;
&lt;p&gt;The latest version of Keyoxide&#x27;s web client has two very neat additions, all
thanks to the latest &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;keyoxide&#x2F;doipjs&quot;&gt;0.11.*&lt;&#x2F;a&gt; release of
&lt;a href=&quot;https:&#x2F;&#x2F;yarmo.eu&#x2F;blog&#x2F;keyoxide-project-update-3&#x2F;js.doip.rocks&quot;&gt;doip.js&lt;&#x2F;a&gt;: the verification of accounts on the IRC and Matrix
platforms.&lt;&#x2F;p&gt;
&lt;p&gt;This really is what Keyoxide was designed to do: making sure your online
correspondances are exchanged with the intended person or entity, even as both
parties use anonymous accounts with varying usernames on different platforms.&lt;&#x2F;p&gt;
&lt;p&gt;To this end, it was important to integrate additional communication platforms,
to join the already supported &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;xmpp&quot;&gt;XMPP&lt;&#x2F;a&gt; protocol.&lt;&#x2F;p&gt;
&lt;p&gt;Given the popularity and decentralized nature of either platform, IRC and Matrix
were both prime candidates. So, let&#x27;s see what goes into proving identities on
IRC and Matrix.&lt;&#x2F;p&gt;
&lt;p&gt;(All examples below use a certain OpenPGP fingerprint and a fictional user, make
sure to use your own data when replicating the steps!)&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Proving_IRC_identity_with_taxonomy&quot;&gt;Proving IRC identity with taxonomy&lt;&#x2F;h2&gt;
&lt;p&gt;What is taxonomy within the context of IRC?&lt;&#x2F;p&gt;
&lt;pre style=&quot;background-color:#212733;color:#ccc9c2;&quot;&gt;&lt;code&gt;&lt;span&gt;&amp;gt;&amp;gt; &#x2F;msg NickServ help TAXONOMY
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;***** NickServ Help *****  
&lt;&#x2F;span&gt;&lt;span&gt;Help for TAXONOMY:
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;The taxonomy command lists metadata information associated
&lt;&#x2F;span&gt;&lt;span&gt;with registered users.
&lt;&#x2F;span&gt;&lt;span&gt; 
&lt;&#x2F;span&gt;&lt;span&gt;Examples:  
&lt;&#x2F;span&gt;&lt;span&gt;    &#x2F;msg NickServ TAXONOMY foo  
&lt;&#x2F;span&gt;&lt;span&gt;***** End of Help *****
&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Taxonomy is metadata information, much like the vCard data for XMPP. Let us use
this to our advantage:&lt;&#x2F;p&gt;
&lt;pre style=&quot;background-color:#212733;color:#ccc9c2;&quot;&gt;&lt;code&gt;&lt;span&gt;&amp;gt;&amp;gt; &#x2F;msg NickServ SET PROPERTY KEY openpgp4fpr:3637202523e7c1309ab79e99ef2dc5827b445f4b
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;Metadata entry KEY added.
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;&amp;gt;&amp;gt; &#x2F;msg NickServ TAXONOMY foo
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;Taxonomy for foo:
&lt;&#x2F;span&gt;&lt;span&gt;KEY              : openpgp4fpr:3637202523e7c1309ab79e99ef2dc5827b445f4b
&lt;&#x2F;span&gt;&lt;span&gt;End of foo taxonomy.
&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;And there you have it: one-directional linking from IRC to an OpenPGP key. Now,
to make that bidirectional, add the following notation to your key:&lt;&#x2F;p&gt;
&lt;pre style=&quot;background-color:#212733;color:#ccc9c2;&quot;&gt;&lt;code&gt;&lt;span&gt;proof@metacode.biz=irc:&#x2F;&#x2F;chat.freenode.net&#x2F;foo
&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Et voilà, foo has now cryptographically proven that that IRC nickname is theirs.&lt;&#x2F;p&gt;
&lt;p&gt;All steps above are explained with more detail in the
&lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;irc&quot;&gt;IRC guide&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;It is important to note that IRC is the slowest identity to verify to date. As
IRC servers lack API endpoints to query the taxonomy metadata (maybe one
day? ^_^), Keyoxide has to log in into the IRC server like any other client,
send a message to NickServ, parse the response and log out again.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Proving_Matrix_identity_with...&quot;&gt;Proving Matrix identity with...&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;https:&#x2F;&#x2F;matrix.org&#x2F;&quot;&gt;Matrix&lt;&#x2F;a&gt; is an excellent decentralized communication
platform, but sadly, for identity verification purposes, it completely lacks
any form of customisable metadata. A shortcoming we can work with, but one which
might also understandibly deter some from proving Matrix identities.&lt;&#x2F;p&gt;
&lt;p&gt;One simply sends a message to a public room with the following content:&lt;&#x2F;p&gt;
&lt;pre style=&quot;background-color:#212733;color:#ccc9c2;&quot;&gt;&lt;code&gt;&lt;span&gt;[Verifying my OpenPGP key: openpgp4fpr:3637202523e7c1309ab79e99ef2dc5827b445f4b]
&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Easy enough. The issue is: Keyoxide can only read messages in a public room via
a Matrix account that already has access to said public room.&lt;&#x2F;p&gt;
&lt;p&gt;Ergo, we can&#x27;t just use any room, we&#x27;ll all have to use the same room.&lt;&#x2F;p&gt;
&lt;p&gt;A dedicated room named
&lt;a href=&quot;https:&#x2F;&#x2F;matrix.to&#x2F;#&#x2F;#doipver:matrix.org&quot;&gt;#doipver:matrix.org&lt;&#x2F;a&gt; has been created
for the very purpose of receiving Matrix identity proofs. Simply join the room
and send the message with your own OpenPGP fingerprint.&lt;&#x2F;p&gt;
&lt;p&gt;By viewing the source of message, you get the data needed to generate the
identity claim to be stored inside your OpenPGP key: the &lt;code&gt;room_id&lt;&#x2F;code&gt; (shared by
everyone) and the &lt;code&gt;event_id&lt;&#x2F;code&gt; (unique to your proof). The notation will look
like this:&lt;&#x2F;p&gt;
&lt;pre style=&quot;background-color:#212733;color:#ccc9c2;&quot;&gt;&lt;code&gt;&lt;span&gt;proof@metacode.biz=matrix:u&#x2F;@foo:matrix.org?org.keyoxide.r=!dBfQZxCoGVmSTujfiv:matrix.org&amp;amp;org.keyoxide.e=$3dVX1nv3lmwnKxc0mgto_Sf-REVr45Z6G7LWLWal10w
&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;That is quite an unwieldy notation, but one designed to follow the
&lt;a href=&quot;https:&#x2F;&#x2F;github.com&#x2F;matrix-org&#x2F;matrix-doc&#x2F;pull&#x2F;2312&quot;&gt;MSC2312 Matrix URI scheme proposal&lt;&#x2F;a&gt;
.&lt;&#x2F;p&gt;
&lt;p&gt;Please refer to the &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;matrix&quot;&gt;Matrix guide&lt;&#x2F;a&gt; for
detailed instructions on how to verify your own Matrix identity.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Signing_off&quot;&gt;Signing off&lt;&#x2F;h2&gt;
&lt;p&gt;As the project now supports multiple communications platforms and its
versatility increases with each update, I am confident that Keyoxide is now
ready for the next phase: focus on the user experience. Nothing to show just
yet, but I am sure the next project update will have interesting announcements
related to this.&lt;&#x2F;p&gt;
&lt;p&gt;For all your questions and suggestions, be sure to join the conversation in the
&lt;a href=&quot;https:&#x2F;&#x2F;matrix.to&#x2F;#&#x2F;#keyoxide:matrix.org&quot;&gt;Keyoxide matrix room&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;Until next time.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Keyoxide Project Update #2</title>
        <published>2021-01-11T16:30:00+00:00</published>
        <updated>2021-01-11T16:30:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yarmo.eu/blog/keyoxide-project-update-2/"/>
        <id>https://yarmo.eu/blog/keyoxide-project-update-2/</id>
        
        <content type="html" xml:base="https://yarmo.eu/blog/keyoxide-project-update-2/">&lt;p&gt;A prosperous 2021 to all. Let&#x27;s dive into some Keyoxide news.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Signature_profiles&quot;&gt;Signature profiles&lt;&#x2F;h2&gt;
&lt;p&gt;The Keyoxide web client just got updated to &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;keyoxide&#x2F;web&#x2F;releases&#x2F;tag&#x2F;2.4.0&quot;&gt;2.4.0&lt;&#x2F;a&gt; which
introduced a few minor bug fixes as well as a robots.txt and noindex meta tags.&lt;&#x2F;p&gt;
&lt;p&gt;The most exciting new feature in this release is the support for &amp;quot;signature profiles&amp;quot;, a new way of creating
decentralized profiles that is both simpler to generate and solves a few drawbacks that come with the traditional
method of storing identity claims as notations in cryptographic keys.&lt;&#x2F;p&gt;
&lt;p&gt;From the newly added &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;signature-profiles&quot;&gt;signature profiles guide&lt;&#x2F;a&gt;:&lt;&#x2F;p&gt;
&lt;blockquote&gt;
&lt;p&gt;Storing claims inside the key as notations is a powerful method. Wherever the public key goes, so go the identity claims. This allows one to use the existing vast network of key sharing tools to also share these identity claims.&lt;&#x2F;p&gt;
&lt;p&gt;There are drawbacks to this: you lose granularity. You cannot pick and choose the claims you want to send to certain people or use for certain purposes. There is also the possibility that notations in keys could be scraped as the keys are publicly available.&lt;&#x2F;p&gt;
&lt;p&gt;Putting (certain) claims in a signature profile solves both drawbacks. You can choose which claims to be associated with each other and you can choose which persons can see this by only sending it to them. You can even encrypt the signature profile! Since the signature profile is not publicly available (unless you make it so), there is no possibility to scrape the contents of it.&lt;&#x2F;p&gt;
&lt;p&gt;Note that there is one catch: the person you send it to could publish it. Only send claims you wish to keep secret to people you trust!&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
&lt;h3 id=&quot;What_does_a_signature_profile_look_like?&quot;&gt;What does a signature profile look like?&lt;&#x2F;h3&gt;
&lt;p&gt;Here&#x27;s an example:&lt;&#x2F;p&gt;
&lt;pre style=&quot;background-color:#212733;color:#ccc9c2;&quot;&gt;&lt;code&gt;&lt;span&gt;-----BEGIN PGP SIGNED MESSAGE-----
&lt;&#x2F;span&gt;&lt;span&gt;Hash: SHA512
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;Hey there! Here&amp;#39;s a signature profile with proofs related to the DOIP project (https:&#x2F;&#x2F;doip.rocks).
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;Verify this profile at https:&#x2F;&#x2F;keyoxide.org&#x2F;sig
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;proof=dns:doip.rocks
&lt;&#x2F;span&gt;&lt;span&gt;proof=https:&#x2F;&#x2F;fosstodon.org&#x2F;@keyoxide
&lt;&#x2F;span&gt;&lt;span&gt;-----BEGIN PGP SIGNATURE-----
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;iQHEBAEBCgAuFiEENjcgJSPnwTCat56Z7y3FgntEX0sFAl&#x2F;7L0MQHHRlc3RAZG9p
&lt;&#x2F;span&gt;&lt;span&gt;cC5yb2NrcwAKCRDvLcWCe0RfS3iYC&#x2F;0QQqz2lzSNrkApdIN9OJFfd&#x2F;sP2qeGr&#x2F;uH
&lt;&#x2F;span&gt;&lt;span&gt;98YHa+ucwBxer6yrAaTYYuBJg1uyzdxQhqF2jWno7FwN4crnj15AN5XGemjpmqat
&lt;&#x2F;span&gt;&lt;span&gt;py9wG6vCVjC81q&#x2F;BWMIMZ7RJ&#x2F;m8F8Kz556xHiU8KbqLNDqFVcT35&#x2F;PhJsw71XVCI
&lt;&#x2F;span&gt;&lt;span&gt;N3HgrgD7CY&#x2F;vIsZ3WIH7mne3q9O7X4TJQtFoZZ&#x2F;l9lKj7qk3LrSFnL6q+JxUr2Im
&lt;&#x2F;span&gt;&lt;span&gt;xfYZKaSz6lmLf+vfPc59JuQtV1z0HSNDQkpKEjmLeIlc+ZNAdSQRjkfi+UDK7eKV
&lt;&#x2F;span&gt;&lt;span&gt;KGOlkcslroJO6rT3ruqx9L3hHtrM8dKQFgtRSaofB51HCyhNzmipbBHnLnKQrcf6
&lt;&#x2F;span&gt;&lt;span&gt;o8nn9OkP7F9NfbBE6xYIUCkgnv1lQbzeXsLLVuEKMW8bvZOmI7jTcthqnwzEIHj&#x2F;
&lt;&#x2F;span&gt;&lt;span&gt;G4p+zPGgO+6Pzuhn47fxH+QZ0KPA8o2vx0DvOkZT6HEqG+EqpIoC&#x2F;a7wD68n789c
&lt;&#x2F;span&gt;&lt;span&gt;K2NLCVb9oIGarPfhIdPV3QbrA5eXRRQ=
&lt;&#x2F;span&gt;&lt;span&gt;=QyNy
&lt;&#x2F;span&gt;&lt;span&gt;-----END PGP SIGNATURE-----
&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;I only wrote the four lines after &lt;code&gt;Hash: SHA512&lt;&#x2F;code&gt;! The rest is generated by an OpenPGP-compatible library.&lt;&#x2F;p&gt;
&lt;p&gt;The first two lines are meant for humans. They state my intent with this signature profile as well as give an
instruction to whomever receives it.&lt;&#x2F;p&gt;
&lt;p&gt;The remaining two lines are my identity claims. They follow a specific syntax that Keyoxide and any other service using
&lt;a href=&quot;https:&#x2F;&#x2F;doip.rocks&quot;&gt;doip.js&lt;&#x2F;a&gt; can interpret.&lt;&#x2F;p&gt;
&lt;p&gt;The text around it is the signature. They make the message both provably beyond doubt written by yours truly, and
untemparable. Try it in the next step, change any character in the text, it will fail. This ensures that no bad actor
could intercept my signature on its way to you and modify its content.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;What_to_do_with_it?&quot;&gt;What to do with it?&lt;&#x2F;h3&gt;
&lt;p&gt;When put into &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;sig&quot;&gt;keyoxide.org&#x2F;sig&lt;&#x2F;a&gt;, the website will perform two verifications.&lt;&#x2F;p&gt;
&lt;p&gt;First, is the signature valid? Has the text been tampered with? If the signature is valid, a so-called &#x27;fingerprint&#x27;
is extracted from it and displayed. Preferably, I have already mentioned my fingerprint to you. This ensures that you
didn&#x27;t simply get a signature from someone else pretending to be me.&lt;&#x2F;p&gt;
&lt;p&gt;The fingerprint of the key that I used for the signature above is &lt;code&gt;3637202523e7c1309ab79e99ef2dc5827b445f4b&lt;&#x2F;code&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;Second step is the verification of the identity claims. I could write a perfectly valid signature profile filled with
absurd and incorrect identity claims! We don&#x27;t want that.&lt;&#x2F;p&gt;
&lt;p&gt;The fingerprint we just extracted from the signature is now used to verify these identity claims. For example, the first
claim (doip.rocks) will have a DNS record with that value. And the second claim (fosstodon.org&#x2F;@keyoxide) has the
fingerprint in the bio section of the account.&lt;&#x2F;p&gt;
&lt;p&gt;Both should verify. This allows you to say:&lt;&#x2F;p&gt;
&lt;blockquote&gt;
&lt;p&gt;Whoever signed this profile, holds the doip.rocks domain name and the fosstodon.org&#x2F;@keyoxide account.&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
&lt;h3 id=&quot;Granular_and_non-scrapable_identity_claims&quot;&gt;Granular and non-scrapable identity claims&lt;&#x2F;h3&gt;
&lt;p&gt;There you have it. Identity claims that can be sent granularly (you pick and choose which to include) and are
non-scrapable (signature profiles are not publicly available).&lt;&#x2F;p&gt;
&lt;p&gt;And if you wish to go a step further, you can even encrypt the signature profile to make sure it can&#x27;t be read while in
transit to the intended recipient.&lt;&#x2F;p&gt;
&lt;p&gt;Happy signing!&lt;&#x2F;p&gt;
&lt;h2 id=&quot;doip.js_0.9.0&quot;&gt;doip.js 0.9.0&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;keyoxide&#x2F;doipjs&#x2F;releases&#x2F;tag&#x2F;0.9.0&quot;&gt;Release 0.9.0&lt;&#x2F;a&gt; of &lt;a href=&quot;https:&#x2F;&#x2F;js.doip.rocks&quot;&gt;doip.js&lt;&#x2F;a&gt; introduced
support for the verification of signature profiles. In fact, Keyoxide simply relies on doip.js for all identity
verifications. This makes it possible for new projects to get started quickly with fully decentralized identity
verification and always have the same feature set that Keyoxide has.&lt;&#x2F;p&gt;
&lt;p&gt;This is the way.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Signing_off&quot;&gt;Signing off&lt;&#x2F;h2&gt;
&lt;p&gt;Hope you enjoy the signature profiles. Do not hesitate to get in touch for questions, comments or suggestions. There&#x27;s
a &lt;a href=&quot;https:&#x2F;&#x2F;matrix.to&#x2F;#&#x2F;#keyoxide:matrix.org&quot;&gt;Keyoxide matrix room&lt;&#x2F;a&gt; as well as a
&lt;a href=&quot;https:&#x2F;&#x2F;lists.sr.ht&#x2F;~yarmo&#x2F;keyoxide-devel&quot;&gt;mailing list&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;Until next time.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Keyoxide CLI released</title>
        <published>2020-12-08T16:30:00+00:00</published>
        <updated>2020-12-08T16:30:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yarmo.eu/blog/keyoxide-cli-released/"/>
        <id>https://yarmo.eu/blog/keyoxide-cli-released/</id>
        
        <content type="html" xml:base="https://yarmo.eu/blog/keyoxide-cli-released/">&lt;p&gt;Five months ago when I made &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;keyoxide.org&lt;&#x2F;a&gt; public, one
specific request made by quite a few people stood out: we need the ability to
perform the identity verification locally. And given that it was a quite
technical crowd, this meant: we need a command-line interface (CLI).&lt;&#x2F;p&gt;
&lt;h2 id=&quot;The_command-line_interface&quot;&gt;The command-line interface&lt;&#x2F;h2&gt;
&lt;p&gt;Today, I&#x27;m pleased to announce the release of the CLI. Written in Node.js and
published on &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;keyoxide&#x2F;cli&quot;&gt;Codeberg&lt;&#x2F;a&gt; under the
&lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;keyoxide&#x2F;cli&#x2F;src&#x2F;branch&#x2F;main&#x2F;LICENSE&quot;&gt;AGPL-v3.0-or-later&lt;&#x2F;a&gt;
license, the Keyoxide CLI uses the recently released
&lt;a href=&quot;https:&#x2F;&#x2F;js.doip.rocks&quot;&gt;doip.js&lt;&#x2F;a&gt; library and does all the things the Keyoxide
website does, but locally. This means you no longer need to trust the website of
the Keyoxide instance you are using, its maintainer or everything inbetween.&lt;&#x2F;p&gt;
&lt;p&gt;Your machine fetches the keys, parses them locally and then directly requests
the identity proofs from the service providers to verify the identity
claims. Here&#x27;s a quick tour.&lt;&#x2F;p&gt;
&lt;p&gt;Assuming you already have Node.js installed, first install the CLI:&lt;&#x2F;p&gt;
&lt;pre data-lang=&quot;bash&quot; style=&quot;background-color:#212733;color:#ccc9c2;&quot; class=&quot;language-bash &quot;&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;&lt;span style=&quot;color:#ffd580;&quot;&gt;npm&lt;&#x2F;span&gt;&lt;span&gt; install&lt;&#x2F;span&gt;&lt;span style=&quot;color:#ffcc66;&quot;&gt; -g&lt;&#x2F;span&gt;&lt;span&gt; keyoxide
&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Then go and verify the identity proofs inside a cryptographic key! To get
started, try out the key I use for testing:&lt;&#x2F;p&gt;
&lt;pre data-lang=&quot;bash&quot; style=&quot;background-color:#212733;color:#ccc9c2;&quot; class=&quot;language-bash &quot;&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;&lt;span style=&quot;color:#ffd580;&quot;&gt;keyoxide&lt;&#x2F;span&gt;&lt;span&gt; verify hkp:test@doip.rocks
&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;You should now get the following result:&lt;&#x2F;p&gt;
&lt;pre style=&quot;background-color:#212733;color:#ccc9c2;&quot;&gt;&lt;code&gt;&lt;span&gt;Verification results:
&lt;&#x2F;span&gt;&lt;span&gt;Yarmo Mackenbach (material for test frameworks) &amp;lt;test@doip.rocks&amp;gt;
&lt;&#x2F;span&gt;&lt;span&gt;  ✓ doip.rocks (dns)
&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;And there you have it! Whoever generated this key verifiably owns the
&lt;a href=&quot;https:&#x2F;&#x2F;doip.rocks&quot;&gt;doip.rocks&lt;&#x2F;a&gt; domain name.&lt;&#x2F;p&gt;
&lt;p&gt;Of course, the CLI can also fetch keys using WKD or get them from Keybase. More
information about these protocols is available on the
&lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;&quot;&gt;Keyoxide&lt;&#x2F;a&gt; website and in the source code&#x27;s
&lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;keyoxide&#x2F;cli&quot;&gt;readme&lt;&#x2F;a&gt; document.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;FOSS_FTW&quot;&gt;FOSS FTW&lt;&#x2F;h2&gt;
&lt;p&gt;As always, this project is fully open source and I welcome all criticism and
contributions, both issues and PRs. We all stand to benefit from solutions that
are built for and by the people. As governments worldwide push for cryptographic
backdoors, let us all keep using and promote free and open software.&lt;&#x2F;p&gt;
&lt;p&gt;Many thanks to &lt;a href=&quot;https:&#x2F;&#x2F;nlnet.nl&quot;&gt;NLnet&lt;&#x2F;a&gt; for supporting me on this journey and
allowing me to focus on these projects while keeping them free from VC funding
and other means of monetization that could compromise the privacy of the
individual.&lt;&#x2F;p&gt;
&lt;p&gt;If you value my efforts and would like to donate, it&#x27;s possible to do so on the
project&#x27;s &lt;a href=&quot;https:&#x2F;&#x2F;liberapay.com&#x2F;Keyoxide&#x2F;&quot;&gt;Liberapay&lt;&#x2F;a&gt; page. Cheers and I&#x27;ll see
you in the next Keyoxide project update post!&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Keyoxide Project Update #1</title>
        <published>2020-11-09T14:00:00+00:00</published>
        <updated>2020-11-09T14:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yarmo.eu/blog/keyoxide-project-update-1/"/>
        <id>https://yarmo.eu/blog/keyoxide-project-update-1/</id>
        
        <content type="html" xml:base="https://yarmo.eu/blog/keyoxide-project-update-1/">&lt;p&gt;Time for the first big Keyoxide project update! A lot to cover, so let&#x27;s get to
it.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;The_Big_Identity&quot;&gt;The Big Identity&lt;&#x2F;h2&gt;
&lt;p&gt;Decentralized identity is coming. &lt;a href=&quot;https:&#x2F;&#x2F;www.w3.org&#x2F;TR&#x2F;did-core&#x2F;&quot;&gt;DIDs&lt;&#x2F;a&gt; are
coming. Awesome libraries like &lt;a href=&quot;https:&#x2F;&#x2F;idx.xyz&#x2F;&quot;&gt;IDX&lt;&#x2F;a&gt; are being published. Even
&lt;a href=&quot;https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;security&#x2F;business&#x2F;identity&#x2F;own-your-identity&quot;&gt;Microsoft&lt;&#x2F;a&gt;
seems on board.&lt;&#x2F;p&gt;
&lt;p&gt;My point is this: decentralized identity is an exciting field to be working on
right now and I&#x27;m committed to keep learning about this domain, its technologies
and contribute to our digital society&#x27;s cure from the parasitic tech giants.
Keyoxide and the response it generated showed me this is within the realm of the
possible.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;A_wild_foundation_appears!&quot;&gt;A wild foundation appears!&lt;&#x2F;h2&gt;
&lt;p&gt;To help me achieve this, I&#x27;ve decided to set up a foundation. Please welcome the
&lt;a href=&quot;https:&#x2F;&#x2F;keytoidentity.foundation&quot;&gt;Key to Identity Foundation&lt;&#x2F;a&gt;! The foundation
will serve as an umbrella for a couple of identity-related projects to come,
which I will be glad to share more about as they progress. In fact, one of these
new projects is included in this update :)&lt;&#x2F;p&gt;
&lt;p&gt;Having a non-profit foundation also allows me to try and fully sustain the
project on donations and grants. I truly believe this model will help the
project and give it the best chance at making a significant change out there.&lt;&#x2F;p&gt;
&lt;p&gt;And as it turns out, I am not the only one who wants to see that happen…&lt;&#x2F;p&gt;
&lt;h2 id=&quot;NLnet_grant_for_Keyoxide_development&quot;&gt;NLnet grant for Keyoxide development&lt;&#x2F;h2&gt;
&lt;p&gt;The awesome people over at &lt;a href=&quot;https:&#x2F;&#x2F;nlnet.nl&#x2F;&quot;&gt;NLnet&lt;&#x2F;a&gt; have taken a good look at
the current status of the Keyoxide project, my plans for its future and it is
now my pleasure to announce they have decided to award me an
&lt;a href=&quot;https:&#x2F;&#x2F;nlnet.nl&#x2F;NGI0&#x2F;&quot;&gt;NGI Zero grant&lt;&#x2F;a&gt; and fund the development!&lt;&#x2F;p&gt;
&lt;p&gt;I couldn&#x27;t be more excited about this news. Keyoxide generated a lot of positive
feedback and ideas on how to improve it when it launched. Getting the
possibility to work on it full-time and build on the aspects that were important
to the community is a dream come true.&lt;&#x2F;p&gt;
&lt;p&gt;More information available on the
&lt;a href=&quot;https:&#x2F;&#x2F;nlnet.nl&#x2F;project&#x2F;Keyoxide&#x2F;&quot;&gt;NLnet website&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Keyoxide_endgame&quot;&gt;Keyoxide endgame&lt;&#x2F;h2&gt;
&lt;p&gt;I would like to expand on a point that is dear to me. Today&#x27;s internet is in its
precarious state because we put faith in monopolistic forces that blossomed
under a lack of competition. The endgame of this endeavor is not just to create
a successful project. It is to build an ecosystem that will thrive on
competition and ultimately deliver the best experience for netizens.&lt;&#x2F;p&gt;
&lt;p&gt;It is what this in mind that I am releasing a new project today that should help
new projects get started in the decentralized identity world.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;doip.js&quot;&gt;doip.js&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;strong&gt;DOIP&lt;&#x2F;strong&gt; stands for Decentralized OpenPGP Identity Proofs, the technology that
enables the identity verification that Keyoxide performs.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;doip.js&lt;&#x2F;strong&gt; is a Node.js library that enables any project to perform the same
tricks. It is even able to run directly in the browser!&lt;&#x2F;p&gt;
&lt;p&gt;What excites me most is that any contribution, like supporting new service
providers, is immediately available to all those projects and websites, not just
Keyoxide.&lt;&#x2F;p&gt;
&lt;p&gt;Documentation is available at &lt;a href=&quot;https:&#x2F;&#x2F;js.doip.rocks&#x2F;#&#x2F;&quot;&gt;doip.rocks&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;Code is licensed under Apache 2.0 and hosted by
&lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;keyoxide&#x2F;doipjs&quot;&gt;Codeberg.org&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Building_a_community&quot;&gt;Building a community&lt;&#x2F;h2&gt;
&lt;p&gt;Keyoxide now has a Matrix room, come hang out and discuss related topics!&lt;&#x2F;p&gt;
&lt;p&gt;Invite link: &lt;a href=&quot;https:&#x2F;&#x2F;matrix.to&#x2F;#&#x2F;#keyoxide:matrix.org&quot;&gt;#keyoxide:matrix.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h2 id=&quot;The_road_ahead&quot;&gt;The road ahead&lt;&#x2F;h2&gt;
&lt;p&gt;We are just getting started here. A lot still needs to happen to make Keyoxide
and OpenPGP-based decentralized identity practical and useful for a larger
audience. With the NLnet grant and my newly-acquired ability to turn this
project into a full-time job, I foresee a bright future.&lt;&#x2F;p&gt;
&lt;p&gt;Hope to see you back for the next update!&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Keyoxide 1.0.0: switched to AGPL-v3</title>
        <published>2020-07-30T12:48:24+00:00</published>
        <updated>2020-07-30T12:48:24+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yarmo.eu/blog/keyoxide-agpl/"/>
        <id>https://yarmo.eu/blog/keyoxide-agpl/</id>
        
        <content type="html" xml:base="https://yarmo.eu/blog/keyoxide-agpl/">&lt;h2 id=&quot;The_big_1.0.0&quot;&gt;The big 1.0.0&lt;&#x2F;h2&gt;
&lt;p&gt;Well, yes but no. It&#x27;s actually a small update but with a MAJOR (get it? Because &lt;a href=&quot;https:&#x2F;&#x2F;semver.org&#x2F;&quot;&gt;semver&lt;&#x2F;a&gt;) change: the project has switched to the &lt;a href=&quot;https:&#x2F;&#x2F;www.gnu.org&#x2F;licenses&#x2F;agpl-3.0.en.html&quot;&gt;AGPL-3.0-or-later&lt;&#x2F;a&gt; license.&lt;&#x2F;p&gt;
&lt;p&gt;When I started the &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide&lt;&#x2F;a&gt; project, it didn&#x27;t have the scope and ambitions it has now. What begun as a tool to bring simple PGP operations directly to the user&#x27;s browser—a side project like many others—has turned into a full-blown solution to prove online identity in a decentralized manner.&lt;&#x2F;p&gt;
&lt;p&gt;The project has also seen quite a warm welcome among the tech-savvy and privacy-minded as a partial replacement for alternatives like Keybase. More importantly, the project has started receiving contributions from other people. From that point on, as was pointed out to me by &lt;a href=&quot;https:&#x2F;&#x2F;social.tchncs.de&#x2F;@t0k&quot;&gt;@t0k@social.tchncs.de&lt;&#x2F;a&gt;, a permissive license like I was using before will no longer do.&lt;&#x2F;p&gt;
&lt;p&gt;A copyleft license like &lt;a href=&quot;https:&#x2F;&#x2F;www.gnu.org&#x2F;licenses&#x2F;agpl-3.0.en.html&quot;&gt;AGPL-3.0-or-later&lt;&#x2F;a&gt; is much better suited to protect the project and its contributors from getting the source code—including everyone&#x27;s contributions—turned into a closed-source clone. Keyoxide is for the online citizenry and will remain so.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Why_1.0.0?&quot;&gt;Why 1.0.0?&lt;&#x2F;h2&gt;
&lt;p&gt;Usually, the &amp;quot;big 1.0&amp;quot; is associated with a project coming out of a beta period or more generally, becoming a product that users can use without excessive bugs. This is not the case here.&lt;&#x2F;p&gt;
&lt;p&gt;The versioning of this project adheres to &lt;a href=&quot;https:&#x2F;&#x2F;semver.org&#x2F;&quot;&gt;semver&lt;&#x2F;a&gt;: MAJOR-MINOR-PATCH. A license change such as this one might put certain people or organizations off from using it (it shouldn&#x27;t… but it might) and could therefore be considered a breaking change which, according to semver, triggers a MAJOR release.&lt;&#x2F;p&gt;
&lt;p&gt;Hence 1.0.0.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Keyoxide and XMPP + OMEMO</title>
        <published>2020-07-23T14:08:02+00:00</published>
        <updated>2020-07-23T14:08:02+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yarmo.eu/blog/keyoxide-xmpp-omemo/"/>
        <id>https://yarmo.eu/blog/keyoxide-xmpp-omemo/</id>
        
        <content type="html" xml:base="https://yarmo.eu/blog/keyoxide-xmpp-omemo/">&lt;h2 id=&quot;XMPP&quot;&gt;XMPP&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;https:&#x2F;&#x2F;xmpp.org&#x2F;&quot;&gt;XMPP&lt;&#x2F;a&gt; is an open messaging protocol that not only drives a &lt;strong&gt;thriving secure communication ecosystem for the privacy-minded&lt;&#x2F;strong&gt;, but also handles the messages sent by platforms like WhatsApp and Zoom. Knowingly or not, you have most likely used XMPP at some point in your life.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;em&gt;For the rest of this post, we will not take into account services like WhatsApp and Zoom as their platforms are closed off from all other platforms even though they use the same XMPP protocol.&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;p&gt;That &lt;strong&gt;ecosystem for the privacy-minded&lt;&#x2F;strong&gt; consists of libraries for developers, server applications for the tech-savvy service providers and clients like &lt;a href=&quot;https:&#x2F;&#x2F;dino.im&#x2F;&quot;&gt;Dino&lt;&#x2F;a&gt; (Linux), &lt;a href=&quot;https:&#x2F;&#x2F;gajim.org&#x2F;&quot;&gt;Gajim&lt;&#x2F;a&gt; (Windows, Mac, Linux) and &lt;a href=&quot;https:&#x2F;&#x2F;conversations.im&#x2F;&quot;&gt;Conversations&lt;&#x2F;a&gt; (Android) for everyone.&lt;&#x2F;p&gt;
&lt;p&gt;Because there is no single server or client to rule them all, we call this is a &lt;em&gt;decentralized&lt;&#x2F;em&gt; network. I could use a different server and a different client than you do, but we would still be able to communicate with each other. Also, any server or client could cease to exist the next day without impacting the rest of the network.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Care_to_join_the_XMPP_ecosystem?&quot;&gt;Care to join the XMPP ecosystem?&lt;&#x2F;h2&gt;
&lt;p&gt;Joining the XMPP ecosystem is as simple as making an account on a server and logging in using any XMPP-compatible client. But which server? Which client?&lt;&#x2F;p&gt;
&lt;p&gt;While not the focus of this post, here is a &lt;a href=&quot;https:&#x2F;&#x2F;xmpp-servers.404.city&#x2F;&quot;&gt;list provided by 404.city&lt;&#x2F;a&gt; and a &lt;a href=&quot;https:&#x2F;&#x2F;list.jabber.at&#x2F;&quot;&gt;list provided by jabber.at&lt;&#x2F;a&gt; of XMPP servers.&lt;&#x2F;p&gt;
&lt;p&gt;Notable mention for &lt;a href=&quot;https:&#x2F;&#x2F;404.city&#x2F;&quot;&gt;404.city&lt;&#x2F;a&gt; itself. Not sponsored. Just a fan.&lt;&#x2F;p&gt;
&lt;p&gt;With regards to clients, the three mentioned above should get you started. Need a different client? Have a look at this &lt;a href=&quot;https:&#x2F;&#x2F;xmpp.org&#x2F;software&#x2F;clients.html&quot;&gt;list provided by xmpp.org&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;End-to-end_encryption:_OMEMO&quot;&gt;End-to-end encryption: OMEMO&lt;&#x2F;h2&gt;
&lt;p&gt;XMPP communication can be end-to-end encrypted with &lt;a href=&quot;https:&#x2F;&#x2F;conversations.im&#x2F;omemo&#x2F;&quot;&gt;OMEMO&lt;&#x2F;a&gt; (&lt;a href=&quot;https:&#x2F;&#x2F;xmpp.org&#x2F;extensions&#x2F;xep-0384.html&quot;&gt;XEP-0384&lt;&#x2F;a&gt;), the easiest and most common of &lt;a href=&quot;https:&#x2F;&#x2F;wiki.404.city&#x2F;en&#x2F;XMPP_client_encryption&quot;&gt;XMPP-compatible end-to-end encryption schemes&lt;&#x2F;a&gt;. Verifying OMEMO fingerprints is essential to trust your communication and keep it safe from Man-in-the-Middle attacks.&lt;&#x2F;p&gt;
&lt;p&gt;Each XMPP client you use will have its own OMEMO key, the content of which remains secured on your device but a &amp;quot;fingerprint&amp;quot; of which can be made public without a problem. These fingerprints are used to identify the different clients that have logged in on your XMPP account.&lt;&#x2F;p&gt;
&lt;p&gt;If you wish to secure your communication with OMEMO, make sure to choose a &lt;a href=&quot;https:&#x2F;&#x2F;omemo.top&#x2F;&quot;&gt;client with full support on this website&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;OMEMO_and_trust&quot;&gt;OMEMO and trust&lt;&#x2F;h2&gt;
&lt;p&gt;When you talk with someone over XMPP and you want to guarantee all communication is secured, it is recommended to use a different form of communication to compare and trust each others fingerprints. Ideally, you would meet in person and scan QR codes, a handy function of the &lt;strong&gt;Conversations&lt;&#x2F;strong&gt; app.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;XMPP_identity_proofs_and_Keyoxide&quot;&gt;XMPP identity proofs and Keyoxide&lt;&#x2F;h2&gt;
&lt;p&gt;As you can see, trusting OMEMO keys is an essential step in the process of ensuring communication is secure. Fortunately, &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide&lt;&#x2F;a&gt; can assist you in that process.&lt;&#x2F;p&gt;
&lt;p&gt;As of &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;keyoxide&#x2F;web&#x2F;releases&#x2F;tag&#x2F;0.4.0&quot;&gt;version 0.4&lt;&#x2F;a&gt;, Keyoxide generates QR codes for all &lt;strong&gt;verified&lt;&#x2F;strong&gt; XMPP accounts it detects. This makes it easy to add new contacts if your &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;xmpp&quot;&gt;XMPP identity proof&lt;&#x2F;a&gt; looks like this:&lt;&#x2F;p&gt;
&lt;pre style=&quot;background-color:#212733;color:#ccc9c2;&quot;&gt;&lt;code&gt;&lt;span&gt;proof@metacode.biz=xmpp:username@domain.org
&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Scan the resulting QR code on a Keyoxide profile page in the &lt;strong&gt;Conversations&lt;&#x2F;strong&gt; app and the contact is added. But the OMEMO keys are not yet trusted. Let&#x27;s solve that!&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Integrating_OMEMO_in_the_XMPP_identity_proof&quot;&gt;Integrating OMEMO in the XMPP identity proof&lt;&#x2F;h2&gt;
&lt;p&gt;It is also possible to add a more advanced &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;xmpp&quot;&gt;XMPP identity proof&lt;&#x2F;a&gt; to your OpenPGP key that includes the OMEMO fingerprints:&lt;&#x2F;p&gt;
&lt;pre style=&quot;background-color:#212733;color:#ccc9c2;&quot;&gt;&lt;code&gt;&lt;span&gt;proof@metacode.biz=xmpp:user@domain.org?omemo-sid-123456789=A1B2C3D4E5F6G7H8I9...
&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Obtaining the correct URI for the proof can be difficult when doing so manually. Fortunately, this can be assisted by the &lt;strong&gt;Conversations&lt;&#x2F;strong&gt; app. As you can tell, using the &lt;strong&gt;Conversations&lt;&#x2F;strong&gt; app brings a ton of advantages.&lt;&#x2F;p&gt;
&lt;p&gt;In the main menu of that app, press &lt;strong&gt;Manage accounts &amp;gt; [your account] &amp;gt; Share &amp;gt; Share as XMPP URI&lt;&#x2F;strong&gt; and add the resulting URI to your key using &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;xmpp&quot;&gt;this Keyoxide guide&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;Scan the resulting QR code on a Keyoxide profile page and not only is the contact added, their OMEMO fingerprints are also fully trusted and verified.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Why_trust_the_Keyoxide_identity_proof?&quot;&gt;Why trust the Keyoxide identity proof?&lt;&#x2F;h2&gt;
&lt;p&gt;Anyone can add any XMPP proof to their OpenPGP key, whether they own it or not. So why trust the identity proof on Keyoxide?&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;STEP 1&lt;&#x2F;strong&gt; The QR code is only shown if a XMPP identity proof is verified. Verifying a XMPP account requires the holder of said account to add a small line of code to their XMPP bio &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;xmpp&quot;&gt;as described in this guide&lt;&#x2F;a&gt;. Only a person with access to both the OpenPGP private key and the XMPP account can verify that XMPP account.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;STEP 2&lt;&#x2F;strong&gt; While Keyoxide assists as much as possible with trusting the right proofs, a critical mind is always an asset when dealing with trusting online identities, especially when securing your communication. Do you recognize any other proofs on this person&#x27;s profile page? Is this proof verified? If so, you can safely assume that the person who holds the OpenPGP key also has access to this &amp;quot;other proof&amp;quot;.&lt;&#x2F;p&gt;
&lt;p&gt;Combining the two steps above, you can trust that you are talking to the right person and verifying the right OMEMO fingerprints.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Example&quot;&gt;Example&lt;&#x2F;h2&gt;
&lt;p&gt;You are reading this post on &lt;a href=&quot;https:&#x2F;&#x2F;yarmo.eu&quot;&gt;yarmo.eu&lt;&#x2F;a&gt;. Whether or not you trust me, I&#x27;m telling you that my OpenPGP fingerprint is:&lt;&#x2F;p&gt;
&lt;pre style=&quot;background-color:#212733;color:#ccc9c2;&quot;&gt;&lt;code&gt;&lt;span&gt;9f0048ac0b23301e1f77e994909f6bd6f80f485d
&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;So you visit &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;9f0048ac0b23301e1f77e994909f6bd6f80f485d&quot;&gt;keyoxide.org&#x2F;9f0048ac0b23301e1f77e994909f6bd6f80f485d&lt;&#x2F;a&gt;. Indeed, whoever holds the key with that fingerprint also owns the &lt;a href=&quot;https:&#x2F;&#x2F;yarmo.eu&quot;&gt;yarmo.eu&lt;&#x2F;a&gt; domain.&lt;&#x2F;p&gt;
&lt;p&gt;Now, you scroll down until you reach the XMPP proof for &lt;strong&gt;yarmo@404.city&lt;&#x2F;strong&gt;. You read that the XMPP account is verified. Ergo, whoever holds the key with that fingerprint also has access to that XMPP account.&lt;&#x2F;p&gt;
&lt;p&gt;Final conclusion: whoever owns the &lt;a href=&quot;https:&#x2F;&#x2F;yarmo.eu&quot;&gt;yarmo.eu&lt;&#x2F;a&gt; domain also has access to the &lt;strong&gt;yarmo@404.city&lt;&#x2F;strong&gt; XMPP account. If you wish to talk with me securely, scan the QR code and be certain that you have just added me as a contact, and that are you verifying the right OMEMO fingerprints to ensure secure and fully encrypted communication between us.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Launching Keyoxide.org</title>
        <published>2020-07-01T12:00:00+00:00</published>
        <updated>2020-07-01T12:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yarmo.eu/blog/keyoxide/"/>
        <id>https://yarmo.eu/blog/keyoxide/</id>
        
        <content type="html" xml:base="https://yarmo.eu/blog/keyoxide/">&lt;p&gt;Today, I&#x27;m excited to launch &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt;, the lightweight and FOSS solution to make basic cryptography operations accessible to regular humans.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;What_is_Keyoxide.org?&quot;&gt;What is Keyoxide.org?&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt; offers easy encryption, signature verification and decentralized identity proof verification based on PGP keys while demanding little in-depth knowledge about the underlying encryption program from its users.&lt;&#x2F;p&gt;
&lt;p&gt;This project aims to offer comparable functionality as services like &lt;a href=&quot;https:&#x2F;&#x2F;keybase.io&quot;&gt;Keybase&lt;&#x2F;a&gt; while reducing friction and being more open.&lt;&#x2F;p&gt;
&lt;p&gt;The project is MIT licensed, uses &lt;a href=&quot;https:&#x2F;&#x2F;github.com&#x2F;openpgpjs&#x2F;openpgpjs&quot;&gt;openpgpjs&lt;&#x2F;a&gt; and is hosted on &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;yarmo&#x2F;keyoxide&quot;&gt;Codeberg&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Why_only_encryption_and_signature_verification?&quot;&gt;Why only encryption and signature verification?&lt;&#x2F;h2&gt;
&lt;p&gt;These are the operations that are available when only having access to public keys instead of private keys. If you wish to decrypt messages and sign them, you need a keypair. If you have a keypair, you probably have the knowledge to use dedicated tools like the CLI or Kleopatra. And if you do, you probably won&#x27;t be using &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt; directly yourself.&lt;&#x2F;p&gt;
&lt;p&gt;Indeed, if you possess a PGP keypair, &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt; is the tool you send to others to interact with your public key more easily. Allow them to encrypt a message for you, to verify one of your signatures, to verify your online identities using decentralized proofs.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;What_are_those_decentralized_identity_proofs_you_keep_mentioning?&quot;&gt;What are those decentralized identity proofs you keep mentioning?&lt;&#x2F;h2&gt;
&lt;p&gt;You know how Keybase allows you to prove you have control over accounts on certain websites and services? A great function! Fortunately for you, this function can be even better and more secure by using &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;openpgp-proofs&quot;&gt;decentralized OpenPGP identity proofs&lt;&#x2F;a&gt;. &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt; will prove your identity on multiple platforms at the same time and yet, you are not required to make an account to use this function. How is that possible?&lt;&#x2F;p&gt;
&lt;p&gt;Well, it&#x27;s called &lt;em&gt;decentralized&lt;&#x2F;em&gt; for a reason: &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt; doesn&#x27;t hold your proofs, your key does! Any software that can access your public key can verify these proofs for anyone. When better tooling comes around, you could verify those proofs using a mobile app, using a command-line utility, you name it. No single service holds your proof, only you do, stored inside your keypair.&lt;&#x2F;p&gt;
&lt;p&gt;I have written a &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&quot;&gt;guide&lt;&#x2F;a&gt; on how to add a proof for every platform currently supported by this website: &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;dns&quot;&gt;domains&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;lobsters&quot;&gt;Lobste.rs&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;twitter&quot;&gt;Twitter&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;github&quot;&gt;Github&lt;&#x2F;a&gt;, a &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&quot;&gt;bunch more&lt;&#x2F;a&gt; and work is in progress to support even more still. Is your beloved service not in the list? &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;yarmo&#x2F;keyoxide&quot;&gt;Open an issue or make a PR&lt;&#x2F;a&gt;! Free open-source software FTW!&lt;&#x2F;p&gt;
&lt;p&gt;Oh, that reminds me, any &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;mastodon&quot;&gt;Mastodon&lt;&#x2F;a&gt; instance can be used to prove your identity. Yes, &lt;a href=&quot;https:&#x2F;&#x2F;github.com&#x2F;keybase&#x2F;keybase-issues&#x2F;issues&#x2F;3385&quot;&gt;any&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;So_how_does_it_compare_to_Keybase?&quot;&gt;So how does it compare to Keybase?&lt;&#x2F;h2&gt;
&lt;p&gt;There&#x27;s a more complete &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;feature-comparison-keybase&quot;&gt;guide on the Keyoxide website&lt;&#x2F;a&gt;, but in a nutshell:&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;more privacy-friendly by not forcing you to create an account and handing over data&lt;&#x2F;li&gt;
&lt;li&gt;more secure by not asking you to trust the service with your private keys&lt;&#x2F;li&gt;
&lt;li&gt;open-source servers (&lt;a href=&quot;https:&#x2F;&#x2F;github.com&#x2F;keybase&#x2F;client&#x2F;issues&#x2F;24105&quot;&gt;a must&lt;&#x2F;a&gt;)&lt;&#x2F;li&gt;
&lt;li&gt;encrypt&#x2F;verify with every public key accessible on the internet, not just those that have been uploaded to a proprietary server&lt;&#x2F;li&gt;
&lt;li&gt;almost all processing is done in the browser, no data is sent to servers*&lt;&#x2F;li&gt;
&lt;li&gt;no vendor lock-in&lt;&#x2F;li&gt;
&lt;li&gt;selfhostable&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;* Only exception is decentralized identity proof verification: some service providers do not have the correct CORS headers (like Reddit) or require APIs (like Twitter). In these rare cases, simple PHP scripts (also open-source) run the proof verification instead.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Can_I_get_an_account?&quot;&gt;Can I get an account?&lt;&#x2F;h2&gt;
&lt;p&gt;No. &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt; doesn&#x27;t need your data on its servers. There are already several ways of exposing public keys on the internet, including &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;web-key-directory&quot;&gt;web key directory&lt;&#x2F;a&gt; (WKD) and dedicated servers like &lt;a href=&quot;https:&#x2F;&#x2F;keys.openpgp.org&quot;&gt;keys.openpgp.org&lt;&#x2F;a&gt;. Let&#x27;s use those instead of making yet another service where you need to upload your keys to.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Can_I_get_a_profile_page_then?&quot;&gt;Can I get a profile page then?&lt;&#x2F;h2&gt;
&lt;p&gt;Yes! Append your PGP fingerprint or WKD id to the URL and there it is!&lt;&#x2F;p&gt;
&lt;p&gt;Want an example? Here&#x27;s  my profile at&lt;br &#x2F;&gt;
&lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;9f0048ac0b23301e1f77e994909f6bd6f80f485d&quot;&gt;https:&#x2F;&#x2F;keyoxide.org&#x2F;9f0048ac0b23301e1f77e994909f6bd6f80f485d&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;Now you know what accounts on various services are mine, where to follow me if you wish to get updates on the project and if you wish to send me an encrypted message, that&#x27;s also just two clicks away.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;What_about_my_private_keys?&quot;&gt;What about my private keys?&lt;&#x2F;h2&gt;
&lt;p&gt;Don&#x27;t upload your private keys to the internet, period. If a service wants your private keys on their (proprietary) servers, say no.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;You_said_selfhostable?&quot;&gt;You said selfhostable?&lt;&#x2F;h2&gt;
&lt;p&gt;Well, yes! It&#x27;s not a fully supported use case just yet, but the browser does all the processing, the server is mostly just there to deliver the files to the user to perform the operations. &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;yarmo&#x2F;keyoxide&quot;&gt;Grab the code&lt;&#x2F;a&gt; and put it on your own PHP server!&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Any_closing_words?&quot;&gt;Any closing words?&lt;&#x2F;h2&gt;
&lt;p&gt;I built this to provide better tooling around modern-day encryption programs and reduce the friction for less tech-savvy people when interacting with public keys.&lt;&#x2F;p&gt;
&lt;p&gt;For those who wish to use encryption programs beyond OpenPGP, &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;yarmo&#x2F;keyoxide&#x2F;issues&quot;&gt;let&#x27;s talk about this&lt;&#x2F;a&gt;. Keyoxide doesn&#x27;t have any reference to PGP in its name for a reason: it could serve as a platform for easy interaction with any public key, no matter the underlying encryption program.&lt;&#x2F;p&gt;
&lt;p&gt;And above all, I hope you see the same benefit and potential in &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt; as I do and would like to see it grow as an open and accessible platform to push forward the democratization of online privacy and security.&lt;&#x2F;p&gt;
&lt;p&gt;Privacy is not a luxury.&lt;&#x2F;p&gt;
&lt;p&gt;Many thanks to &lt;a href=&quot;https:&#x2F;&#x2F;metacode.biz&#x2F;@wiktor&quot;&gt;Wiktor&lt;&#x2F;a&gt; for helping with the decentralized identity proofs.&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
