Docs / Keys
Keys
PubPhys signs every record and every log checkpoint with its platform key. The key is introduced by a record signed with the recovery key, which is kept offline by two people and is used only to introduce or revoke platform keys. How this works.
Fingerprints
- Recovery key:
8958cdba40c6b8f89211ac5a710d3c3739004515a7d3e48eadf883d6ff999b33 - Platform key 1 (current):
c6afc19b31429869751f06879c75cd64ea92654423d15b44be775bf1310a60da— introducing record
Where else they are published
Compare these fingerprints with at least one other source before trusting them:
- the DNS TXT record
_pubphys.pubphys.com; - the public mirror repository
Galitski-group/pubphys-log(trust.jsonand the key records underkeys/); - the trust file of this site: /.well-known/pubphys-trust.json.
If they ever differ, do not trust the site's copy. The verifier never takes keys from the site: it starts from the recovery key you pinned and checks every key record itself.