3 ms·
> persistent global public identity Certificate Transparency could be reused/abused to host it. If, for example, you issued a cert for name <key>.contact.examp
by Leace 7y ago
> persistent global public identity
Certificate Transparency could be reused/abused to host it. If, for example, you issued a cert for name <key>.contact.example.com and the tooling would check CT logs this could be a very powerful directory of contacts. Using CT monitors you could see if/when someone tampers with your domain name contact keys.
Mozilla is planning something similar for signing software: https://wiki.mozilla.org/Security/Binary_Transparency https://wiki.mozilla.org/Security/Binary_Transparency
- Natanael_L 7y agoThis is basically the keybase.io log system. Although they too rely on PGP currently
- Leace 7y agoMinus the network of independent logs as from what I remember only keybase.io runs their own log system. Although they do timestamp their Merkle tree roots into Bitcoin.