4 ms·
> As long as AP cryptographically signs the outcome of the game (as they do for all HTTPS served content) I looked into this use case before and came to the co
by milkey_mouse 4y ago
> As long as AP cryptographically signs the outcome of the game (as they do for all HTTPS served content)
I looked into this use case before and came to the conclusion that it can't work because TLS is not non-repudiable. Once the initial public-key handshake is finished, the rest of the session uses a symmetric cipher. Because anyone with the symmetric cipher's key can encrypt their own data with it, you could encrypt your own spoofed response from the server in any transcript of the session.
https://crypto.stackexchange.com/questions/29751/are-https-web-sessions-non-repudiable https://crypto.stackexchange.com/questions/29751/are-https-w...
One solution to this is to use the site's public key to sign a Web Bundle instead of using TLS:
https://web.dev/web-bundles/ https://web.dev/web-bundles/
https://wicg.github.io/webpackage/draft-yasskin-http-origin-signed-responses.html https://wicg.github.io/webpackage/draft-yasskin-http-origin-...
Web bundles can be served from any origin (and I'd imagine can be verified by oracles) as the data itself is signed. However, this requires the server to use web bundles in the first place, which likely isn't happening any time soon. Mozilla considers the proposal harmful: they expect Google will serve the majority of web bundles, allowing them to see what sites the user is visiting.
https://github.com/mozilla/standards-positions/issues/264 https://github.com/mozilla/standards-positions/issues/264
https://www.ghacks.net/2020/08/30/google-proposed-web-bundles-could-threaten-the-web-as-we-know-it/ https://www.ghacks.net/2020/08/30/google-proposed-web-bundle...
- tomhallett 4y agoBut even if you look past the technicals, the example of the AP being a trusted source for who won the super bowl has issues. What if the AP announces team a won, but then 2 months later it comes out that team a cheated and the NFL retroactively changes the winner (similar to lance armstrong getting wins taken away, or in some years the tour determined there was no winner because there was so much doping.). Is the expectation that the AP will update their page which says who won? While I will concede the example I give above is an extreme edge case, I would also argue that “who won the super bowl” is also an overly simple example.
- milkey_mouse 4y agoI suppose you'd have to write your resolution as "apnews.com will at some point publish a page with the <title> tag containing '49ers', 'win', 'Super Bowl'" and hope the possibility of some sort of retraction would be priced into the market.
- RileyJames 4y agoTLS-n, which is a protocol extension, and therefore not supported by default, does enable non-repudiation via TLS. Video is better explanation than the repos. https://m.youtube.com/watch?v=HnrFsekayrM https://m.youtube.com/watch?v=HnrFsekayrM So it could be done. Tho it would require the server to add support. Repos: https://github.com/tls-n https://github.com/tls-n
- milkey_mouse 4y agoMuch like Signed HTTP Exchanges/Web Bundles, the value of an opt-in protocol such as TLS-n is much less than one that would work with all the HTTPS sites already out there. I doubt the Associated Press wants to get into the blockchain oracle business.