الأربعاء، 8 سبتمبر 2021
https://ift.tt/2Cgnnid
Show HN: Stamp – A Cryptographic Identity System Hi, everyone. Been playing around with this recently as a sort of PGP successor. It's not all there yet, and I know it's missing some things from PGP, but I figured why not get a start and see what kind of interest/support it might get. https://ift.tt/3nguCzp Effectively, this is a key management system that allows building and signing ("stamping") various claims about yourself and about others. The eventual goal is to create easy-to-use implementations of the protocol that allow logging in to websites or managing cryptographic keys for various security-conscious applications. Secure, simple distributed key management for cryptography and identity management. Currently Stamp uses crypto primitives found in libsodium, but is also built such that different algorithms can be added as needed. The identity itself is set up as a DAG which is appended to by signing transactions with an opinionated set of keys. A DAG was chosen so parallel offline updates could be made and merged later. One of Stamp's main features is it allows recovery of the identity via a pre-determined recovery policy, using signatures from trusted keys (friends, family, institutional providers). Think of it as sort of a multisig recovery mechanism. A few things I'm actively exploring: - A storage network (https://ift.tt/3zWFBBO). This would necessarily need to be some sort of p2p system, and hopefully not blockchain-based as I believe the consensus/validation used in blockchain systems are superfluous to identity storage and retrieval. - Putting stamp on USB keys/embedded devices (ARM TrustZone, RISC-V PMP, etc) so it can be used in more trusted environments. - Some sort of FIDO2 interop would be great so Stamp could act as a login system without having to re-tool a bunch of stuff. There's also a somewhat-incomplete CLI implementation of the protocol here: https://ift.tt/3z649ap. This allows creation of identities, creating and stamping claims, automatic verification of certain claims (www/DNS), as well as cryptographic messaging/signing tools. Let me know what you think! What's good, what's bad, what's missing, etc. Obviously it's early days so more feedback is better. September 8, 2021 at 11:07PM
الاشتراك في:
تعليقات الرسالة (Atom)
������ �����
خدمات طبيه https://www.cut-titles.com/Y4ZR
-
https://ift.tt/3jx13Vs via /r/aww https://ift.tt/2DjFQ1K
-
Show HN: Lists.sh – A Microblog for Lists Greetings, creator here! I've been working on a new blogging platform specifically for lists o...
-
https://ift.tt/3d6Rzzs via /r/aww https://ift.tt/3qiBmMM
-
Show HN: Polka Jot v1.0 (just a scratch pad) https://ift.tt/3JwqCDN December 31, 2021 at 11:12PM
-
Show HN: Touca – a better alternative to snapshot testing Hi everyone, Almost 2 years ago, I left my full-time job at Canon to build tooling...
-
Медицинскийуризм в Турции Турция занимает 3е место в мире по количеству иностранных пациентов согласно отчету Глобального ал...