5 ms·
Great use case for blockchain technology
by toppy 7y ago
Great use case for blockchain technology
- LeonM 7y agoCT logs are already chained
- Ajedi32 7y agoI'd say it's more of a tree than a chain, but yes. https://www.certificate-transparency.org/log-proofs-work https://www.certificate-transparency.org/log-proofs-work
- village-idiot 7y agoIts creators also make it very clear that it is not a blockchain. It’s centralized and lacks the consensus mechanism that’s a hallmark of blockchains (PoW or PoS).
- icebraining 7y agoUnfortunately people have started taking the pre-existing components of the Blockchain, like Merkle Trees, and calling them "blockchain" too. See "permissioned blockchain".
- village-idiot 7y agoIf I had $1 for every time I’ve heard “did you know git is a blockchain”...
- floatboth 7y agohttps://twitter.com/whitequark/status/946887056424341504 https://twitter.com/whitequark/status/946887056424341504
- icebraining 7y agoBlockchain is also a tree, it's just that every branch except one is (usually) abandoned rapidly. That said, that's just because both use Merkle trees. CT isn't a blockchain.
- westurner 7y ago> Great use case for blockchain technology >> CT logs are already chained Trillian is a centralized Merkle tree: it doesn't support native replication (AFAIU?) and there is a still a password that can delete or recreate the chain (though we can track for any such inappropriate or errant modifications (due to e.g. solar flares) by manually replicating and verifying every entry in the chain, or trusting that everything before whatever we consider to be a known hash (that could be colliding) is unmodified (since the last time we never verified those entries)). According to the trillian README, trillian depends upon MySQL/MariaDB and thus internal/private replication is as good as the SQL replication model (which doesn't have a distributed consensus algorithm like e.g. paxos). A Merkle tree alone is not a blockchain; though it provides more assurance of data integrity than a regular tree, verifying that the whole chain of hashes actually is good and distributed replication without configuring e.g. SSL certs are primary features of blockchains.
- skybrian 7y agoThere are multiple certificate issuers, multiple logs, and multiple log verifiers. With no single point of failure, that doesn't sound centralized to me?
- westurner 7y agoWhich components of the system are we discussing? PKI is necessarily centralized: certs depend upon CA certs which can depend upon CA certs. If any CA is compromised (e.g. by theft or brute force (which is inestimably infeasible given current ASIC resources' preference for legit income)) that CA can sign any CRL. A CT log and a CT log verifier can help us discover that a redundant and so possibly unauthorized cert has been issued for a given domain listed in an x.509 cert CN/SAN. The CT log itself - trillian, for Google and now LetsEncrypt, too - though, runs on MySQL; which has one root password. The system of multiple independent, redundant CT logs is built upon databases that depend upon presumably manually configured replication keys. Does my browser call a remote log verifier API over (hopefully pinned with a better fingerprint than MD5) HTTPS?
- 7y ago
- theamk 7y agoI'd say "great replacement for blockchain technology" (in some applications)