Topic: Public Key

4 chapters across the catalog

Episode 267: Chocolove
15:32 - 18:03

Episode 267: Chocolove

Podping Architecture Transition, Hardcoded Bootstrap Nodes

Dave Jones explains the decision to remove DHT from Podping due to stability issues with the Eero library. The system has transitioned to using five hardcoded bootstrap nodes located in Australia, Central, East, Europe, and West, which utilize permanent public keys for coordination.

Episode 263: Chat is Dead
59:01 - 1:03:02

Episode 263: Chat is Dead

Implementing Web-Bot-Auth and Key Signing

To resolve blocking issues, Dave Jones implemented HTTP signing using Cloudflare's "web-bot-auth" protocol. He repurposed existing Rust code from the ActivityPub bridge to publish public keys on podcastindex.org, though he notes that Cloudflare has yet to officially verify the bot despite the implementation.

Episode 262: Podcleanse
1:26:45 - 1:29:20

Episode 262: Podcleanse

Verified Apps, Cryptographic Signing

The discussion explores a hypothetical scenario where platforms like Spotify or Megaphone implement "verified apps" using cryptographic signing. Dave Jones suggests that much of the current industry abuse stems from "carelessness" in "Vibe Coding" rather than intentional malice.

Episode 260: Tennessee Trickshot
1:16:19 - 1:20:25

Episode 260: Tennessee Trickshot

OPAWG and Validated Public Key Repositories

The Open Podcast Analytics Working Group (OPAWG), led by John Spurlock and James Cridland, is suggested as a potential host for a repository of validated public keys. This system would allow hosting companies to restrict high-bandwidth content to verified clients, potentially solving the bot traffic problem without requiring a centralized blocklist.