4 ms·
Looked at the slides, I kind of undestand something now, and it looks intriguing if not really interesting. Have you thought about key revocation, how is it han
by zz1 12y ago
Looked at the slides, I kind of undestand something now, and it looks intriguing if not really interesting.
Have you thought about key revocation, how is it handled?
- jchrisa 12y agoNo it's hard and could lead to sad stories. Say your phone holds a few wallets and a hacker breaks in a starts double spending. That would ruin those wallets and I guess there are simpler cases like you just lost your wallet / forgot your password that might be as troubling. So key handling is totally one of those things I'd love to outsource. Actually please let me outsource as much of of the crypto as possible, I don't want to be inventing things. To that end http://www.w3.org/TR/WebCryptoAPI/ http://www.w3.org/TR/WebCryptoAPI/ looks like a reasonable start. I've also been reading http://datatracker.ietf.org/doc/draft-ietf-jose-cookbook/ http://datatracker.ietf.org/doc/draft-ietf-jose-cookbook/ and generally trying to get a sense of the least opinionated path I can take. Luckily our iOS lead at Couchbase is experienced writing apps that use cryptographic signing, so he's written up the beginnings of a spec that we'll likely evolve: https://github.com/couchbase/couchbase-lite-ios/wiki/Signed-Documents https://github.com/couchbase/couchbase-lite-ios/wiki/Signed-... If you want to join in the implementation nitty gritty feel free to start a thread in our group: https://groups.google.com/forum/#!forum/mobile-couchbase https://groups.google.com/forum/#!forum/mobile-couchbase I've always used my own application development goals to find interesting directions at Couchbase so this project is just an example of how we work.
- MarkPNeyer 12y agomy friend and i have been working on something like this, which may have the answer to the key revocation problem. in our system (which we are calling dewdrop - https://github.com/neyer/dewdrop https://github.com/neyer/dewdrop - still very much a work in progress) you don't pass coins around; you make statements. you can make statements of the form 'i trust person X', and then statements made by person X are given more weight for you, as are statements by those X trusts, etc. in our system, key revocation would be just another statement. if i say "hey this is mark, my phone was captured at this time and these N transactions are invalid", my friends - if they believe me - can say 'i believe he is telling the truth here.' everyone who trusts us will then ignore statements made from that address during that time period. the statements will still be on the network, but people who trust me and my friends will not believe i made them. because there is no transfer of coins - just statements that anyone can make - there's no issue of 'do we really need to revoke the key?' people who trust me, and who trust my friends, will see those statements as having been revoked; people who don't trust me will need to decide for themselves on this.
- jchrisa 12y agoNeat that sounds really cool. There's a team at Microsoft building essentially a p2p crypto enabled web view application container for all desktops plus Android: http://thali.cloudapp.net/mediawiki/index.php?title=Main_Page http://thali.cloudapp.net/mediawiki/index.php?title=Main_Pag... Might be a good fit for your project.