Mistress Emelia is a user on switter.at. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.
Mistress Emelia @MistressEmelia

Given a bcrypt password (the hash) and the secret key, and reasonably high complexity settings, would it be safe to assume that it wouldn’t be practical to bruteforce that data?

I’m wondering how a system could be built in which we don’t know details of reports for ugly mugs, but so that those lists can be shared. It must be searchable by those fields

· Amaroq · 1 · 3 · 6 · Reply

@MistressEmelia depends: size of key and relative security of those with the private key. Best to think perhaps in terms of something akin to block chain. Every user has their own private key and “transaxtions” between reporters and the repository have a trust and verify transparency before posting negative data.
Also provide means for reputation repair. The event and the reputation repair still exist in the document.

Hoping that makes sense. If not DM me.

@tribune I don’t think a blockchain is necessarily the answer here, as this is the cryptography within the document, not the signatures & history of the documents.

I would DM, but I have to go rest more.

That is, the way current ugly mugs systems work is by individuals sharing details in mailing lists, spreadsheets and private facebook groups (this is becoming ever more prevalent) — the main problem with this is the data privacy, I don’t think majority of providers link to a privacy policy in their ads, hence violating GDPR

So the question is, how can we store that data in a secure way, and allow it to be federated / distributed for resiliency without violating laws or breaching privacy?

SA adjacent Show more

@MistressEmelia if you have more questions about their technical setup you can e-mail brad@pinkdate.is. for general questions about provider safety policy, e-mail sarah@pinkdate.is or visit their slack:

join.slack.com/t/pinkdate/shar

@MistressEmelia this is a centralized solution, but @pinkdate is working on a very clever setup for screening /booking dates

they will require clients to go through tiered screening. providers can choose what level of screening they require. bad clients will be blacklisted from the service

their security setup is novel /extremely clever:
medium.com/@PinkDate/pink-app-

medium.com/@PinkDate/why-you-s