• Saik0@lemmy.saik0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      So looking at that spec… Nothing there is validation that current messages originate from an “original” server…

      I don’t think either of these signature options for Server to Server communications means that my current lemmy.saik0.com instance can’t be torn down (delete LXC container) and reconfigured as a brand new instance (New LXC container) and other instances wouldn’t know that there’s been a change to the instance running here… or more accurately would flag a change. I think these signatures are all about not being able to spoof OTHER instances. eg, lemmy.ml can’t send messages on behalf of lemmy.world.