5 ms·
How about this? Write your bug report. Sign the bug report with your private key. Anonymously publish the bug report, the signature and the public key. Later wh
by yori 7y ago
How about this? Write your bug report. Sign the bug report with your private key. Anonymously publish the bug report, the signature and the public key. Later when required, prove that you wrote the bug report by using your private key to sign a new message or a challenge message sent by any challenger.
- RL_Quine 7y agoThe idea is to replace social proof (that the timestamps are correct wherever it is published) with cryptographic proof, but I commented below on some of the pitfalls of doing so.
- lawn 7y agoThis could work, as long as you trust the ones you file your bug report to. This isn't always the case for white hat hackers who interact with big corporations for example. You also don't always want to disclose the actual vulnerability beforehand to everyone either, to give them time to fix them. If these things don't hold then you still need to find a trusted way to publish your hash or encrypted message so you can get your timestamp.