3 ms·
If you dig below the surface you might see why it does. For example, how would you imagine a system could implement key revocation and signed statement revocat
by shea256 11y ago
If you dig below the surface you might see why it does.
For example, how would you imagine a system could implement key revocation and signed statement revocation?
- murbard2 11y agoYou publish a signed statement revoking your key. Publications are kept and replicated by volunteer nodes or in a DHT. There is no need for consensus or coordination, which is what a blockchain achieves because you act as the central authority regarding your own identity.
- jude- 11y agoOrder matters. Suppose my key is compromised, stolen, or lost. If my revocation preceeds a subsequent signature from my key, then the subsequent signature can be considered invalid as well. Unlike a DHT, the blockchain provides everyone with my key's history with respect to every other key's history, so my stolen key cannot be used to impersonate me after I revoke it. Moreover, the blockchain grows at a constant rate, so attempts to censor the revocation will get noticed quickly, since I will notice when my transaction does not get accepted, and other principals will notice when blocks are not propagated.
- murbard2 11y agoOnce you lose a master key, blockchain or no blockchain, your identity splits. The person who stole your key can impersonate you perfectly. Having a blockchain does not help at all in telling the attackers from the honest party. What a blockchain lets you do is arbitrarily decide on a single one of the parties as the canonical branch.This is crucial for money, but of no practical value for identity.
- jude- 11y ago> Once you lose a master key, blockchain or no blockchain, your identity splits. The person who stole your key can impersonate you perfectly. I agree that there is a race between you broadcasting your revocation and the attacker using your key. Until all relevant parties receive your revocation, your attacker impersonates you perfectly. However, using the blockchain as a broadcast medium for revocations places an upper bound on how soon your revocation will received by the rest of the these parties (assuming the blockchain itself remains available during the compromise). This is not the case with existing PKI systems, which make no such provisions at the protocol level beyond a simple (and usually optional) key expiration. Moreover, the fact that blockchains are extremely difficult to convincingly forge means that your well-formed revocation transaction would be hard to censor in a way that you could not detect, so an unavailability attack would not leave you falsely believing that your revocation has been sent.