3 ms·
> The obvious way to do that has some drawbacks though, the big one being that if the private key ever leaks, your whole system is now useless and needs to be r
by _Nat_ 5y ago
> The obvious way to do that has some drawbacks though, the big one being that if the private key ever leaks, your whole system is now useless and needs to be replaced (cards, verifiers and all).
That's a problem addressed with [public key infrastructure (PKI)](https://en.wikipedia.org/wiki/Public_key_infrastructure https://en.wikipedia.org/wiki/Public_key_infrastructure).
In practice, it could be done pretty securely and cheaply.
- Dylan16807 5y ago> That's a problem addressed with [public key infrastructure (PKI)] I don't really agree. Yes, you want to use PKI. But it doesn't solve the problem of needing to immediately update all your equipment when there's a key leak, and replace or reprogram a huge number of cards. PKI just makes things a bit smoother in general. My suggestion is pretty simple. Have a few different locations that sign keys, have them all sign each card, and require multiple valid signatures. Exact details up to the implementer, but that way you could have at least one key leak without causing any user hassle.