Edit history

[Self-Hosted/Federation] Fluxer-managed (centralized) community verifications has not been edited, so there are no earlier versions.

Current version | Original by Jonah
Show

[Self-Hosted/Federation] Fluxer-managed (centralized) community verifications

Current problem

When federation drops, especially when user federation is completed and communities from multiple servers are visible in the same view, I am already very concerned about self-hosted servers being used for phishing purposes. For example, I run a privacy/cybersecurity community geared towards people who are not knowledgeable about either of those topics. I think this is a particularly high-risk group when it comes to scams/phishing, and I can think of a lot of other (especially financial or cryptocurrency) communities where the same would apply. I think that the potential for third-party servers to abuse the verification badges would make me seriously question whether I would migrate my existing community on Matrix to Fluxer. At the same time, I think it is important that third-party communities can get these badges. I know federation is a bit far out still, but I think this is something that could begin to be discussed today.

Proposed change

This is definitely a hot take, but I think that community verification badges should be handled by the client app Fluxer publishes, based on a centralized list maintained by the Fluxer team, rather than the server. Or, that official Fluxer clients only show community badges from servers trusted by the Fluxer team. Self-hosters are still not limited:
  • Our own hosted web client can show whatever verification status we want.
  • We can also compile their own desktop/mobile clients, if we really want a complete experience we control.
  • Self-hosted communities could still be verified (see below)
However, self-hosters of communities which wish to be verified in the apps you publish should still have to go through your current partner/verified process. Maybe an Operators Pass perk could include:
  1. Expedited reviews of self-hosted communities by your team, and/or
  2. A self-hoster could request their server be allow-listed to be able to verify/partner communities on its own, but that privilege can be revoked by the Fluxer team if it is abused.

Platform

macOS, Windows, Linux, Web, Android, iOS, Self-hosting

Additional information

Maybe Bluesky's decentralized verification model could be considered as a possible way to implement this:
  • Self-hosted servers could vouch for communities to be verified (even remote communities), and the client lets you choose which servers you as a user trust to vouch for Fluxer communities.
    • The Fluxer client could come with a list of highly-trusted servers including the official Fluxer instance by default, and users could add/remove servers as they see fit.
  • Multiple servers could vouch for a single community. You hover over the verified badge and it would say "Verified By Fluxer", "Verified By ABC", "Verified By XYZ", etc. alongside each instance's icon.