hachiflow.com
Identidad

Tu identidad es una clave, y ya funciona en el siguiente espacio de trabajo

Una identidad de Buzz es un par de claves creado en tu dispositivo, no una cuenta en nuestra base de datos. Únete a un segundo espacio y ya eres tú. Lo que generamos para un espacio, y lo que queda solo en tus manos, son claves distintas a propósito.

Not a row in our database

Sign in to most chat products and you are a row in the vendor's user table: an email, a password hash, an id they issued. A Buzz identity is none of that. It is a keypair, generated on your own machine the first time the app runs. The public half is your ID, safe to share anywhere. The private half signs every message and action you take, and it stays in your keychain.

We never see the private half. There is no password to reset because there is no password, and no account for us to suspend because there is no account. There is a key, and it proves, mathematically, that a message came from you.

The second workspace already knows you

Here is where it stops being abstract. Join a second workspace, a client's hive, a community, a side project, and you do not create anything. You show up with the same key, an admin enrols your public ID, and you exist there. One identity, every workspace you will ever join: same name, same ID, same signature in all of them. (Buzz speaks Nostr, an open protocol, which is why the key format is standard rather than ours.)

One honest boundary: your identity travels, your messages do not. A message lives on the relay where you sent it. Getting your history out of a workspace is an export, a different mechanism with different guarantees, and joining a new workspace starts its conversation fresh.

tu clave creada en tu dispositivo, nunca nuestra espacio A tú, con tu propia clave clave raíz · emitida por nosotros, en custodia espacio B tú, con tu propia clave clave raíz · emitida por nosotros, en custodia
La misma clave personal eres tú en cada espacio al que te unes. Cada espacio tiene su propia clave raíz, generada por nosotros y guardada en custodia, de modo que perderla tiene remedio. Las dos nunca son la misma clave.

What we mint, and what is yours

Every workspace also has a root key: the owner key, the one that controls the workspace itself. That key we mint when the workspace is provisioned, and we place a copy in escrow. If the owner loses it, we hand it back, verified and audited. Recoverability is the point: a business should not lose its workspace because one laptop died.

Nobody works signed in as the root. Day to day, everyone in the workspace, including the person who pays for it, participates as an admin or a member with their own personal key: the one made on their device, the one we never see.

The custody line

The two keys draw one clean line. A key we hold in escrow is a key we can hand back, and that is exactly why it must never be your personal identity. Your personal key is yours alone, and that is exactly why we cannot recover it. Every recovery promise is a custody fact, in both directions.

This is also why we say plainly that we can read our escrow copy, rather than dressing it up: handing back a lost owner key is only possible while a copy we can read exists. The full detail, including how to make us delete our copy and what that costs you, is on the keys page.

Roles, in plain words

Admins run the workspace day to day: they send invites, add and remove members, and moderate. Members talk, share, and build. Both do it with their own keys.

Only the owner changes roles. That is the power the root key keeps, and it is why the recoverable key in escrow is the owner key and not anything a person carries around daily. Lose an admin's laptop and the admin re-enrols with a new key. Lose the owner key and we recover it. Nothing in that sentence requires us to hold anything that is yours.

← Todas las notas