Trusted peer
The definition of a trusted peer, a peer of an account that a local account has joined or that holds a grant from a local account, and the limited role trusted peers play in sync.

Part of Stem. This page defines trusted peer, the second peer class sync uses, and separates trust for delivery from trust for authority.

A trusted peer of a local account is a peer that has authenticated as an account the local account has joined (a contact with join true) or as an account that holds a live grant from the local account; a trusted peer is a peer the local daemon is willing to exchange scopes with beyond a space's authority peers.

Trust here is narrow and explicit. It says nothing about what the other account may read or write; that is the authority graph. It says only that this is a relationship the user chose, so exchanging data with that account's peers reveals interest only to someone the user already deals with. Trusted peers are how two members of a space keep each other current when the site is down, and how a follower gets a public space from another follower when its owner is offline.

How a peer becomes trusted

The local daemon derives the set from its own index, with no new blob type:

    For every local account, every contact resource it owns whose join is true names a subject account. Peers that authenticate as that subject are trusted.

    For every local account, every live Grant it signed with a key audience names a principal. Peers that authenticate as that principal are trusted. Members of a group the local account granted to are trusted as well.

    Peers that authenticate as a local account's other devices are trusted by rule 2 if the account delegated to them, and are authority peers for the account's own space in any case.

A peer that has not authenticated is never trusted, whatever its address.

What trusted peers are for

    A scope that the space's authority peers could not complete is reconciled with trusted peers next.

    A trusted peer may Offer a scope the local policy follows; the offer is still checked for authority and scope membership like any other.

    Trusted peers are told nothing extra. What a trusted peer may read is decided by readers, exactly as for any peer.

Today (HM24)

The daemon has no trusted-peer concept; after the authority tier it samples up to twenty peers from its table. The Network page states the design stance that "identity defines Seed's propagation graph" with eligible recipients being site owners, trusted contacts and explicit subscriptions. Stem defines the second of those precisely and drops the sampling.

Do you like what you are reading? Subscribe to receive updates.

Unsubscribe anytime