Current problem
When federation drops, especially when user federation is completed and communities from multiple servers are visible in the same view, I am already very concerned about self-hosted servers being used for phishing purposes.
For example, I run a privacy/cybersecurity community geared towards people who are not knowledgeable about either of those topics. I think this is a particularly high-risk group when it comes to scams/phishing, and I can think of a lot of other (especially financial or cryptocurrency) communities where the same would apply.
I think that the potential for third-party servers to abuse the verification badges would make me seriously question whether I would migrate my existing community on Matrix to Fluxer. At the same time, I think it is important that third-party communities can get these badges.
I know federation is a bit far out still, but I think this is something that could begin to be discussed today.
Proposed change
This is definitely a hot take, but I think that community verification badges should be handled by the client app Fluxer publishes, based on a centralized list maintained by the Fluxer team, rather than the server. Or, that official Fluxer clients only show community badges from servers trusted by the Fluxer team.
Self-hosters are still not limited:
- Our own hosted web client can show whatever verification status we want.
- We can also compile their own desktop/mobile clients, if we really want a complete experience we control.
- Self-hosted communities could still be verified (see below)
- Expedited reviews of self-hosted communities by your team, and/or
- A self-hoster could request their server be allow-listed to be able to verify/partner communities on its own, but that privilege can be revoked by the Fluxer team if it is abused.
Platform
macOS, Windows, Linux, Web, Android, iOS, Self-hosting
Additional information
Maybe Bluesky's decentralized verification model could be considered as a possible way to implement this:
- Self-hosted servers could vouch for communities to be verified (even remote communities), and the client lets you choose which servers you as a user trust to vouch for Fluxer communities.
- The Fluxer client could come with a list of highly-trusted servers including the official Fluxer instance by default, and users could add/remove servers as they see fit.
- Multiple servers could vouch for a single community. You hover over the verified badge and it would say "Verified By Fluxer", "Verified By ABC", "Verified By XYZ", etc. alongside each instance's icon.
Comments
No comments yet.