Hacker News new | ask | show | jobs
by Lama9901 99 days ago
mostly theoretical right now — but that's the point of building it before it's needed.

anyone submitting results for audit or regulatory review has an incentive to make numbers look right. strip the evidence, recompute hashes — if only integrity is being checked, the attack is silent and undetectable.

i kept asking myself "what would i do if i wanted to cheat this?" that was the first answer. so it became an adversarial test: tests/steward/test_cert02_*

the protocol shouldn't assume good faith. especially not in regulated domains.

and thanks on the site — built that solo too.