Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No security that needs time should be based on an insecure clock. Is there any kind of network "verified time" facility using PKC?


You'd need interactive signatures to prevent replays of very old timestamps, which significantly hurts scalability of the signed timestamps. However, I suppose with a weaker trust model one could have a federated signed timestamp service, where you could get timestamps over TLS/SSL.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: