So, the bottom line is that if your solution requires an authentication server (AS), you’re compromised. I reached a similar conclusion with OAuth2.0

The cynical side of me is that mainstream industry is perfectly happy with MLS because when an authority leans on them to comply with chat control, etc., they can do it.

nostr:note1pchmla6y3nmn7yyr9l5xmq22eszq8gz9kkdrkajnnwtu0n0e04askysj4q

This post and comments are published on Nostr.