inkan's avatar
inkan
dv@www.inkan.cc
npub16xnp...6z6l
inkan's avatar
inkan 2 hours ago
If you've followed Inkan you know the core trick: your signing key gets compromised, you revoke it, swap in a new one, and you keep your identity and your followers. Key dies, identity survives. But there was one gap left. Say your key gets stolen Saturday 4:39am. You don't notice. You wake up, post a few notes, run errands. It's now Saturday 3:19pm you finally see something's off and revoke the key. That's great, but for 10ยฝ hours the thief held a valid signer key. Anything they posted in that window, they can get it Bitcoin-timestamped, and then it looks like you. They can't touch your timeline before 4:39am or after 3:19pm. But that window is polluted. So here's what's new in Inkan. When you revoke, you can now retroactively disavow that window. You do this on-chain. You basically say "Nothing signed by that signing key between 4:39am and 3:19pm speaks for me." A delegation-enabled client can then mark everything in that window as disavowed and can filter it out of your timeline. Impersonation gone. One problem though. You yourself also posted in that window. Your real posts get disavowed along with the fake ones. Baby with bathwater. That's the second new piece: re-ratification. You go through the disavowed window, pick out the events that are actually yours, and publish a re-ratification, also Bitcoin-timestamped. Those events come back and stay on your timeline, marked as re-ratified. Net result: key stolen, key revoked, window disavowed, your own posts rehabilitated. The attacker's stuff is chased out, yours stays. Timeline repaired. Live now on
inkan's avatar
inkan 3 days ago
As a heads-up, you need to make sure that all of your events get OTS timestamps *shortly* after they are created. Currently this means that you'll need to include wss://relay.inkan.cc among your write relays (until someone else runs a relay with an attached timestamping server), and you'll then also need to make sure that your inkan client is set to periodically fetch the timestamps from the timestamping server and distristribute them as "31045" events to relays. The default Inkan settings do this for you. If you don't do this, you'll see your events disappearing on your identity profile starting about 4 hours after their creation since the client will filter them out as "not validly dated." See below for some more discussion of this, and let me know if you have any questions. ๐Ÿ‘‡ View quoted note โ†’
โ†‘