logoalt Hacker News

6510today at 3:45 PM0 repliesview on HN

Could have a distributed system so physical access gives you nothing. Could have the vendor pick a time for release. If all nodes agree the time has arrived release the payload. Make it so that nothing can be released silently. Give the vendor some time to sound the alarm if something goes wrong.

I don't know to what extend you could do a key update on illegitimate released. It seems you have bigger problems to worry about at that point.

To do it earlier you could have judges sign for release and require one or more judge keys to decrypt the vendor keys.