metastream
metastream copied to clipboard
Show pubkey before accepting/declining join
It would be great if I, as a host, could somehow verify that a friend who asks to join is really that friend, instead of some stranger. It seems like the general infrastructure for that exists, just no UI.
I would suggest http://bohwaz.net/archives/web/Bubble_Babble.html or diceware (EFF wordlist) encoding of a truncated-to-128bit hash, because a birthday attack isn't possible.
Glitch's "friendly words" list could be used to prevent people from having to use a code like "hufed-dwhgs-wdhsj". It's a lot harder to share than something like "shrouded-millenium". Maybe they could also be used for default usernames.