Skip to content

Fails the laziness doctrine #3

Description

@ramriot

Since the local hash is the same as the vendor hash there is nothing to stop a lazy user from building a database that asserts little but looks like it asserts everything.

Much better to have an algo that requires the code to be local plus integrates the keys and perhaps method statement into it i.e.
sign( hmac( {code}, public_key ), private_key) = code.sig
sign( code.sig + origin.{id}, private_key ) = method.sig
This verifies at least that the private_key owner has a local copy of the code and asserts their method in conjunction with its output.

I'm sure this is not the only way or even the best way of accomplishing this. I leave it here as a discussion point.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions