Ask Lemmy
A Fediverse community for open-ended, thought provoking questions
Rules: (interactive)
1) Be nice and; have fun
Doxxing, trolling, sealioning, racism, toxicity and dog-whistling are not welcomed in AskLemmy. Remember what your mother said: if you can't say something nice, don't say anything at all. In addition, the site-wide Lemmy.world terms of service also apply here. Please familiarize yourself with them
2) All posts must end with a '?'
This is sort of like Jeopardy. Please phrase all post titles in the form of a proper question ending with ?
3) No spam
Please do not flood the community with nonsense. Actual suspected spammers will be banned on site. No astroturfing.
4) NSFW is okay, within reason
Just remember to tag posts with either a content warning or a [NSFW] tag. Overtly sexual posts are not allowed, please direct them to either !asklemmyafterdark@lemmy.world or !asklemmynsfw@lemmynsfw.com.
NSFW comments should be restricted to posts tagged [NSFW].
5) This is not a support community.
It is not a place for 'how do I?', type questions.
If you have any questions regarding the site itself or would like to report a community, please direct them to Lemmy.world Support or email info@lemmy.world. For other questions check our partnered communities list, or use the search function.
6) No US Politics.
Please don't post about current US Politics. If you need to do this, try !politicaldiscussion@lemmy.world or !uspolitics@lemmy.world
7) No Hit-and-Run questions.
Please don't delete your post for no apparent reason. If you plan on deleting a question later, say so in the post, or if you feel that you have a good reason to remove it, message a mod beforehand. It's not fair to the ones who took their time to answer, and it's not in the spirit of the community.
8) No Bots.
Posts or comments from bots, LLM's, AIs, Neural Networks, Transformers, or Marvin the Paranoid Android are not welcome in AskLemmy. Real humans only please.
Reminder: The terms of service apply here too.
Partnered Communities:
Logo design credit goes to: tubbadu
view the rest of the comments
You don't need a browser extension or an app for this.
Look at MEGA Upload for example. While it's primarily a cloud storage platform, it does allow for file/content sharing ... though not really in the social media kind of way I think you're getting at. But the technical way they implement it could help you.
When you sign up there, you set a password, and the hash of that password is then your encryption key. All your client (whether an independent app or just a script on a web page) needs is the ability to hash the user's password to be able to reconstruct the key and begin decrypting things.
The main weakness of this is that users must remember their own password. Due to the zero-knowledge encryption, the host cannot know the password and cannot recover it. So if the user forgets their password, then they're just shit out of luck, and all their content is forever inaccessible.
This would work as an independent app. But as a web page, it would be delivered by the web server, requiring you to trust that the server is not snooping on your decrypted content (by sending it back to the server post-decryption).
Anybody interested (and capable) enough could view the web page's source and verify that the scripts running on it are identical to what they're supposed to be, and if they want to, they can even go through the entire code line-by-line to verify.
Honestly, web scripts are easier to verify than a browser extension or stand-alone app, because you can quickly and easily view the (local) source code that you're actually running.
I'd say that browser extensions and apps are more difficult to verify. You can, of course, publish the source code, but unless end users are compiling it from source every time, you have an issue with them having a difficult time verifying that the compiled code they download and run is actually the same as the publicly visible source code. A malicious developer could publish clean source code, but then provide compromised compiled versions for download and install.
I suppose there is a frequency argument to be made, though. With a browser extension or standalone app, you only need to check and re-verify the code each time it's updated. But a script running on a web page would need to be verified every time you use it.