3 ms·
(author here) That's fair. The real world applications are slim, but interesting. Maybe I'm a whistleblower with thousands of files, but I don't want to release
by makeworld 3y ago
(author here) That's fair. The real world applications are slim, but interesting. Maybe I'm a whistleblower with thousands of files, but I don't want to release them all right now. This tool allows you to easily prove that a file you release later was part of the original collection.
Another use case might be an organization that has a large archive of important files. This tool allows them to efficiently sign all of these files by signing the root hash.
Edit: added this to the README
- mtlynch 3y ago>Maybe I'm a whistleblower with thousands of files, but I don't want to release them all right now. This tool allows you to easily prove that a file you release later was part of the original collection. That makes it more concrete. Thanks! >Another use case might be an organization that has a large archive of important files. This tool allows them to efficiently sign all of these files by signing the root hash. This one, I'm still a bit confused. Sign them for what purpose? If they're signing a bunch of documents to vouch for their authenticity, don't they have to cryptographically hash all the documents anyway? Or is the idea that instead of hash+sign N documents, they hash N documents, but they only have to sign one thing?
- makeworld 3y agoYes, it means you have to sign only once. Maybe for signing this doesn't matter, but sometimes these authenticity operations you are doing can be more expensive. Maybe you're adding hashes to a blockchain or something. Plus the size of signatures can really add up depending on the number of files and algo.