logoalt Hacker News

LtWorflast Saturday at 9:19 PM1 replyview on HN

Not really, uploading via trusted publishers I don't own any private key, as you probably know having implemented it yourself I presume.


Replies

woodruffwlast Saturday at 9:41 PM

Trusted Publishing doesn’t involve any signing keys (well, there’s an IdP, but the IdP’s signature is over a JWT that the index verifies, not an end signature). You’re thinking of attestations, which do indeed involve a local ephemeral private key.

Again, I must emphasize that this is identical in construction to the Web PKI; that was intentional. There are good criticisms of PKIs on grounds of centrality, etc., but “the end entity doesn’t control the private key” is facially untrue and sounds more like conspiracy than anything else.

show 1 reply