4 ms·
The image of an example document says something like “To recover the content, download the latest version of paperback from <URL>“. I have a few questions abou
by newscracker 5y ago
The image of an example document says something like “To recover the content, download the latest version of paperback from <URL>“.
I have a few questions about that.
1. Would that link even work after 10 or 20 or 30 years? What’s the fallback if the link is broken?
2. Is the “latest version” always guaranteed to be compatible with the scheme used by the document in question (again consider that the document is created now but is being attempted to be recovered a few decades from now)?
3. Based on the above questions, what’s a reasonable expected age for this system to work (I’m referring to the software)?
It would be useful to have these questions and their answers added in an FAQ on the site and in the repo.
- cyphar 5y agoThis is a project I am still working on (I wasn't expecting it to be posted on HN), so while I have thought of the problems you've listed, I haven't finished solving all of them. I do appreciate the feedback though. To answer your questions: 1. My original plan was to have a textual description of the algorithm that you could print out and store with the key shards or main document. That way even if GitHub goes down and Rust is no longer available you could still pay someone to re-implement the algorithm to reconstruct the secret. That document could also contain a minimal version of the source code to just reconstruct the secret. The reason for putting a link to the website was so that a regular user (who is ultimately going to be the target audience for this) would be able to follow the instructions to recover the secret. 2. All of the data has a u32 version number inside the wire format, so any change which would render things incompatible would result in a new version and the code for recovering the old version would remain untouched (and once we get to that point, there would be tests to make sure that works). Also the document says in the header which paperback version was used to construct it, so even in the extreme case where we wouldn't be able to detect a change we could just ask the user what version of paperback does the document say. 3. Good question, but I'm not sure how I would go about estimating this? I will add some of this information to the README.