|
|
|
|
|
by deejaybog
3409 days ago
|
|
It would require a prohibitive amount of engineering resources to be done right, i.e. a chain of guarantees that from creation time to the moment they are inspected it can be proven that the logs cannot be tampered with by nonauthorized users. There are other requirements e.g. separation of roles that are expected on audit subsystems. I am positive it would not pass an adversary expert analysis. |
|
Google also has an internal PKI CA - I think they meet and exceed that security baseline for rigor.