<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <id>https://polykey.com/blog</id>
    <title>Polykey Blog</title>
    <updated>2025-07-18T00:00:00.000Z</updated>
    <generator>https://github.com/jpmonette/feed</generator>
    <link rel="alternate" href="https://polykey.com/blog"/>
    <subtitle>Polykey Blog</subtitle>
    <icon>https://polykey.com/images/polykey-favicon-dark.png</icon>
    <entry>
        <title type="html"><![CDATA[Architecting Anti-Fragile Trust at EthKL]]></title>
        <id>https://polykey.com/blog/architecting-anti-fragile-trust-at-ethkl</id>
        <link href="https://polykey.com/blog/architecting-anti-fragile-trust-at-ethkl"/>
        <updated>2025-07-18T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Our global digital systems are dangerously brittle. It is a brittleness that can]]></summary>
        <content type="html"><![CDATA[<p>Our global digital systems are dangerously brittle. It is a brittleness that can
be felt first-hand crossing the new "digital borders" that define our lives.
These systems are brittle by design, riddled with single points of failure, and
utterly unprepared for the cascading shocks of a polycrisis world.</p>
<p>This post is based on a
<a href="https://www.meetup.com/ethmalaysia/events/309702671/" target="_blank" rel="noopener noreferrer" class="">presentation that Matrix AI recently ran with EthKL on mid-2025</a>.</p>
<p>If you prefer to watch a video on this content instead of reading:</p>
<iframe src="https://player.vimeo.com/video/1130706266?title=0&amp;byline=0&amp;portrait=0&amp;badge=0&amp;autopause=0&amp;player_id=0&amp;app_id=58479" frameborder="0" allow="autoplay; fullscreen; picture-in-picture; clipboard-write; encrypted-media" width="640px" height="360px" referrerpolicy="strict-origin-when-cross-origin" title="Polykey - Anti-Fragile Trust"></iframe>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="nine-circles-of-digital-hell">Nine Circles of Digital Hell<a href="https://polykey.com/blog/architecting-anti-fragile-trust-at-ethkl#nine-circles-of-digital-hell" class="hash-link" aria-label="Direct link to Nine Circles of Digital Hell" title="Direct link to Nine Circles of Digital Hell" translate="no">​</a></h2>
<div style="display:flex"><p><img decoding="async" loading="lazy" alt="Electric Vehicle Charging in Malaysia" src="https://polykey.com/assets/images/electric-vehicle-charging-c100f6630e24df0b4b4a06600e348c2b.jpg" width="450" height="600" class="img_ev3q"></p><p><img decoding="async" loading="lazy" alt="Region Locked Elcharge App" src="https://polykey.com/assets/images/gplay-region-locked-elcharge-8c16432b610b066c87e04684509ec45e.jpg" width="531" height="800" class="img_ev3q"></p></div>
<p>It started with a mundane goal: charging an electric vehicle in Kuala Lumpur.
The charger was cash-less and app-only. Simple enough. But the app was
region-locked, invisible to my phone. So began a domino run through modern
identity spaghetti.</p>
<p>Downloading the app required a burner Google account on local Wi-Fi with a
Malaysian IP. Registering required a local Malaysian phone number. Getting that
number required physically presenting the passport for KYC at a telco shop. With
the precious <code>+60</code> SIM in hand, one could finally register, only to face the
final boss: a credit card the app would accept. A single failure at any point in
this nine-step Rube Goldberg machine, a rejected card, a bad IP, a corrupted
passport scan, would have left me stranded.</p>
<p>This isn't an isolated incident, just a different flavor of an old chaos. In the
US, opening a bank account requires proof of address, which needs a lease, which
needs a visa, which needs a travel record... It's an opaque web of
interdependencies navigated by trial and error, a series of buggy side-quests
masquerading as official process.</p>
<p>This brings us to a powerful realization, captured by Stafford Beer: "The
purpose of a system is what it does." This friction isn't necessarily a grand
conspiracy; it's the emergent outcome of institutional incentives that favor
control over access. The system isn't broken, it's just not designed for you.</p>
<p>This leads us to a foundational error in how we conceptualize risk. We've been
conditioned to think about it like an actuary, but we're facing problems that
demand a systems engineer.</p>
<p>Actuarial, insurance-based thinking makes sense when risks are uncorrelated. An
insurance company pools surplus capital to cover isolated house fires because
it's statistically unlikely that every house will burn down at once. But what
happens when the risk is systemic? What happens when a wildfire tears through
the entire state, a flood submerges the whole city, or a bug in a core smart
contract library is exploited? The model collapses.</p>
<p>In a systemic event, everyone's house burns down at the same time. The insurance
company goes bankrupt. There is no surplus large enough to cover a system-wide
failure. You cannot insure against this kind of risk; it must be engineered out
of the system from first principles. Yes, re-insurance pools and state
guarantees soften the blow, but even these schemes buckle when correlations hit
1.0. Therefore systemic risks require defense-in-depth and modular isolation
that prevents cracks from propagating (exactly the principles upon which Polykey
is built on), like the grain boundaries in a steel beam. It's a problem of
materials science, civil engineering, and rational policy, not financial
statistics.</p>
<p>Yet, this flawed, actuarial mindset has infected everything. We have begun to
substitute spreadsheets for steel. We see the same tragic pattern in our
healthcare system, which excels at financing intervention but fails at
engineering prevention. Instead of engineering resilience, we buy insurance,
trading structural integrity for a financial abstraction. It's a societal moral
hazard that makes us feel safe while leaving us catastrophically vulnerable.</p>
<p>This is the Great Symbolic Drift. Our L1 systems, the abstract symbols of
identity, credit, and risk have become dangerously untethered from the L0
material and engineering reality they are supposed to represent. We're living in
a castle of abstractions built on foundations of sand, and the tide eventually
comes.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-panopticon-the-passkey-and-the-security-theater">The Panopticon, The Passkey, and The Security Theater<a href="https://polykey.com/blog/architecting-anti-fragile-trust-at-ethkl#the-panopticon-the-passkey-and-the-security-theater" class="hash-link" aria-label="Direct link to The Panopticon, The Passkey, and The Security Theater" title="Direct link to The Panopticon, The Passkey, and The Security Theater" translate="no">​</a></h2>
<p>The castle of abstractions we critiqued isn't just an academic problem. It has
real, sharp edges that define our relationship with power in both the public and
private spheres. That flawed, actuarial mindset doesn't just produce brittle
systems; it produces systems designed for control and liability-shifting, not
resilience. Let's examine the two major fronts where this battle for your
sovereignty is being waged.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-human-front-when-your-phone-becomes-a-leash">The Human Front: When Your Phone Becomes a Leash<a href="https://polykey.com/blog/architecting-anti-fragile-trust-at-ethkl#the-human-front-when-your-phone-becomes-a-leash" class="hash-link" aria-label="Direct link to The Human Front: When Your Phone Becomes a Leash" title="Direct link to The Human Front: When Your Phone Becomes a Leash" translate="no">​</a></h3>
<p>Do you own your identity? If you think having some crypto makes you sovereign,
you are in for a ride. Identity is far more than money; it's who you are, who
you represent, and your license to exist in the digital world. And right now,
you don't own it.</p>
<p>The primary instrument of this dispossession is your mobile phone number. It has
become the de facto global identity anchor, the "hot identity" more
operationally significant than your passport. Each time a service demands your
phone number, they shackle you to a state-controlled system. The passport scan
for that SIM card, the video of your face for that new app, it's all part of a
very bad deal.</p>
<p>The hidden logic is: "Our identity infrastructure is brittle, so we must take
ownership of <em>your</em> device." Because they cannot trust <em>you</em>, they must trust
the hardware they can co-opt, the secure enclave inside the phone you paid for.
Control is silently slipping from users to a public-private mesh of regulators
and platform owners. You don’t feel the hand on the leash until you try to pull
away.</p>
<p>This is why even well-intentioned advances like Passkeys become a gilded cage.
They offer a smoother user experience, but their recovery paths almost always
lead back to the same centralized bigtech gatekeepers Apple and Google who act
as deputies, verifying you against the very government documents and phone
numbers anchored the old system. The state remains the identity of last resort,
and the tech giants become its willing deputies.</p>
<p>This centralization loads a hair-trigger. A single, silent database toggle can
freeze your economic pulse, severing your access to the digital world. History
shows that such triggers, once built, are eventually pulled, often in a crisis
where the definition of "good citizen" becomes conveniently narrow.</p>
<p>The complex web of dependencies also creates systemic sovereign vulnerabilities.
The architecture is so fragile that a single exploit can ripple through entire
populations. When this happens, the
<a href="https://en.wikipedia.org/wiki/2022_Optus_data_breach" target="_blank" rel="noopener noreferrer" class="">losses are socialized onto the users, and the crisis itself becomes the justification for even more centralized control</a>.
The cycle feeds itself.</p>
<figure style="margin:10px 0px"><p><img decoding="async" loading="lazy" alt="2022 Optus Leak Discovered on Forum and Announced on Twitter" src="https://polykey.com/assets/images/optus-leak-discovery-twitter-5f93d801c5a37ac9b2fbb9922959de23.jpg" width="960" height="540" class="img_ev3q"></p><figcaption><em>In 2022, Optus a major ISP and Mobile Network Provider exposed an API endpoint that compromised sensitive credentials like passports for their customers. Our in-depth analysis: <a href="https://www.slideshare.net/slideshow/cybersecurity-future-risks-zero-trust-and-the-optus-data-leakpdf/254327821" target="_blank" rel="noopener noreferrer" class="">https://www.slideshare.net/slideshow/cybersecurity-future-risks-zero-trust-and-the-optus-data-leakpdf/254327821</a></em></figcaption></figure>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-machine-front-the-security-theater">The Machine Front: The Security Theater<a href="https://polykey.com/blog/architecting-anti-fragile-trust-at-ethkl#the-machine-front-the-security-theater" class="hash-link" aria-label="Direct link to The Machine Front: The Security Theater" title="Direct link to The Machine Front: The Security Theater" translate="no">​</a></h3>
<p>This same flawed thinking in managing risk via abstraction and compliance rather
than sound engineering manifests in the corporate world as "cybersecurity." The
dominant model is a joke: build a perimeter, buy some "outside-in" security
products, and then, most importantly, buy a cybersecurity insurance policy.</p>
<p>This is security theater: an expensive illusion that transfers blame faster than
it patches code. The goal is not to engineer resilient systems, but to generate
the paper trail necessary to satisfy auditors and insurance underwriters.
Certifications like ISO 27001 and SOC 2 become legal artifacts for shifting
liability, not technical guarantees of security. In this regime, large
organizations don't <em>engineer</em> cybersecurity; they <em>perform compliance</em>.</p>
<p>This security-by-obscurity game is already failing catastrophically against
human attackers. Now, consider the coming Cambrian explosion of non-human
actors. The "secret sprawl" of API keys, tokens, and certificates for cloud
services, IoT devices, and autonomous AI agents is growing exponentially. A
compliance checklist cannot govern a fleet of collaborating AI agents. The
outside-in, compliance-driven model will not just bend in this new reality; it
will shatter. The systemic vulnerabilities being created right now are ticking
time bombs.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="a-builders-manifesto-from-first-principles-to-anti-fragile-trust">A Builder's Manifesto: From First Principles to Anti-Fragile Trust<a href="https://polykey.com/blog/architecting-anti-fragile-trust-at-ethkl#a-builders-manifesto-from-first-principles-to-anti-fragile-trust" class="hash-link" aria-label="Direct link to A Builder's Manifesto: From First Principles to Anti-Fragile Trust" title="Direct link to A Builder's Manifesto: From First Principles to Anti-Fragile Trust" translate="no">​</a></h3>
<p>So, what can we do? This is not a lamentation; it is a call to create. It's a
call to build technology that doesn't dispossess people, armed with a clear-eyed
understanding of what all centralized entities ultimately want.</p>
<p>Before we can build, we must first define our terms. We must ask the most
fundamental question, the one these brittle systems get so catastrophically
wrong:</p>
<p>What <em>is</em> identity?</p>
<blockquote>
<p>It is not a record in a database.</p>
<p>It is not an ID card.</p>
<p>It is not a symmetric or asymmetric key.</p>
<p>It is not a biometric template.</p>
</blockquote>
<p>These are all just instruments. Brittle, static, forgeable instruments.</p>
<blockquote>
<p>Your identity is a social relationship. It's a dynamic social process, not a
static anchor. True, resilient identity is a social fact, a dynamic consensus
among those who recognize you as a continuous process through time.</p>
</blockquote>
<p>Once you understand this, everything changes. The absurdity of the current
system becomes painfully clear. Why is bootstrapping an identity when you cross
a border such a strange, friction-filled process? It's because the system is
trying to map a static, instrumental credential (your passport) onto a dynamic,
living reality. It will always be frustrating.</p>
<p>With this correct first principle in mind, the engineering requirements for a
truly sovereign system become obvious. As a team, these are the principles that
have guided our work. Let's use Polykey as an inspiration, as a case study in
how to build from this foundation.</p>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="principle-1-verifiable-memory">Principle 1: Verifiable Memory<a href="https://polykey.com/blog/architecting-anti-fragile-trust-at-ethkl#principle-1-verifiable-memory" class="hash-link" aria-label="Direct link to Principle 1: Verifiable Memory" title="Direct link to Principle 1: Verifiable Memory" translate="no">​</a></h4>
<p>If identity is a social process that unfolds over time, then we need a way to
reliably record its history. To build real trust, we must all have a <strong>stake in
the observation of reality.</strong> A centralized database is not a shared memory; it
is a liability, a tool for the powerful to rewrite history.</p>
<p>We need a new primitive. This is why Polykey is built on <strong>sigchains</strong>:
per-node, user-owned, append-only ledgers of cryptographic claims. They are not
just static logs, but composable, portable records of your digital relationships
and delegated authority. They are designed to make security a first-class,
programmatic concept from the ground up.</p>
<p><img decoding="async" loading="lazy" alt="Diagram of Polykey Agent Sigchain" src="https://polykey.com/assets/images/polykey-sigchain-structure-e0d39c4dd092dc3d6a923ffbb98c710e.png" width="1024" height="394" class="img_ev3q"></p>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="principle-2-pluralistic-sovereignty">Principle 2: Pluralistic Sovereignty<a href="https://polykey.com/blog/architecting-anti-fragile-trust-at-ethkl#principle-2-pluralistic-sovereignty" class="hash-link" aria-label="Direct link to Principle 2: Pluralistic Sovereignty" title="Direct link to Principle 2: Pluralistic Sovereignty" translate="no">​</a></h4>
<p>If identity is a social consensus, then its recovery must also be social. The
idea that you can be "deleted" because you lost a single instrument like a key,
a phone, or a password, is an engineering failure born of a philosophical
mistake. Resilience demands pluralism.</p>
<p>A sovereign system must therefore be recoverable through social consensus. This
is why Polykey's architecture is built for <strong>social recovery</strong>, where a quorum
of designated peers can collectively attest to restore a lost identity.
Polykey's social graph called the Gestalt Graph recovers the individual node.
(<a class="" href="https://polykey.com/blog/ai-detection-versus-cryptographic-provenance#introducing-a-decentralized-trust-network">When all the Gestalt Graphs are put together, we create a Decentralized Trust Network</a>)
This is crucial because, as we'll see, even the strongest physical anchors can
be lost. If we allow ourselves to be atomized into disconnected nodes, we become
disposable cogs in a machine.</p>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="principle-3-the-l0-anchor">Principle 3: The L0 Anchor<a href="https://polykey.com/blog/architecting-anti-fragile-trust-at-ethkl#principle-3-the-l0-anchor" class="hash-link" aria-label="Direct link to Principle 3: The L0 Anchor" title="Direct link to Principle 3: The L0 Anchor" translate="no">​</a></h4>
<p>To prevent the symbolic drift we’ve talked about, our digital systems need a
provable, cryptographic link back to material reality. A social graph, no matter
how resilient, needs a grounding in the physical world to prevent symbolic
drift. Our answer to this "bits-to-atoms" problem is the concept of a <strong>Polykey
Anchor</strong>.</p>
<p>This tethers L1 claims to L0 material facts. Building this at scale means
working within the tightly-cartelized secure element ecosystem today, while
paving the road toward verifiable, open hardware supply chains for tomorrow.
True sovereignty requires it.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-path-forward-an-asymmetric-strategy">The Path Forward: An Asymmetric Strategy<a href="https://polykey.com/blog/architecting-anti-fragile-trust-at-ethkl#the-path-forward-an-asymmetric-strategy" class="hash-link" aria-label="Direct link to The Path Forward: An Asymmetric Strategy" title="Direct link to The Path Forward: An Asymmetric Strategy" translate="no">​</a></h2>
<p>Critique is not enough. We must build.</p>
<p>But we cannot fight the incumbent identity stack head-on; that's a battle of
attrition we would lose. Our strategy must be asymmetric. We must find the
cracks in the system, the points of leverage where a small force can produce an
outsized effect.</p>
<p>For identity, the most potent maneuver is to <strong>Overlay and Invert</strong>.</p>
<p>You don't try to replace the existing rails overnight. Instead, you first build
an <em>overlay</em> that is compatible with them. For initial onboarding, you accept
the legacy credentials: the phone numbers, the emails, the passports. This
minimizes friction and allows you to gain a foothold.</p>
<p>But here is the critical move, the point of leverage where the inversion
happens. Your new layer must offer a more trustworthy, more portable, and
fundamentally more resilient <strong>recovery mechanism</strong>.</p>
<p><em>Control of recovery is control of the root.</em></p>
<p>The legacy anchors are demonstrably broken. Email accounts get locked. Phone
numbers are vulnerable to SIM swaps. Passports are useless for day-to-day
digital recovery. When a user's new sovereign identity that is anchored by
social consensus and a physical key becomes the most reliable way for them to
recover their digital life, it becomes their true root of trust. Users and
platforms will migrate to it, first for recovery, then for everything. At that
point, the inversion is complete. The phone number and the passport are demoted
to mere attributes attached to your new, sovereign anchor.</p>
<p>This is how we build systems that empower, not dispossess.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="thanks-to-ethkl-for-hosting">Thanks to EthKL for Hosting<a href="https://polykey.com/blog/architecting-anti-fragile-trust-at-ethkl#thanks-to-ethkl-for-hosting" class="hash-link" aria-label="Direct link to Thanks to EthKL for Hosting" title="Direct link to Thanks to EthKL for Hosting" translate="no">​</a></h2>
<p>This post is a crystallization of a presentation and, more importantly, a
conversation I had the privilege of sharing with the EthKL community. The energy
in the room was palpable, a clear sign that we are not alone in wrestling with
these foundational problems.</p>
<p>The discussion that followed the talk was as illuminating as the presentation
itself, quickly diving into the hard questions and exciting possibilities that
arise from these ideas. I wanted to share a few of the key themes that emerged,
as they point toward the collaborative work that lies ahead:</p>
<ul>
<li class="">The Abstraction Chasm: We had a great discussion tracing the line from
object-capabilities to serialized tokens like JWTs, and a shared realization
emerged: current tools create a "first-order box problem." When faced with
managing too many granular permissions, users and developers alike give up and
default to <code>grant ALL</code>. This highlighted the deep need for a higher-order
abstraction: a programmable, first-class concept of authority, touching on
ideas from Datalog to modern knowledge representation, that can be composed
and delegated safely.</li>
<li class="">Grounding The Digital in The Real: The L0/L1 distinction resonated deeply. The
idea that "money" is just an entry in a database that can return "user not
found" was a visceral moment. This led to a clarifying discussion about the
Polykey Anchor, distinguishing its role as a hardware-based proof-of-action
from a simple authentication tool like a Passkey. The Anchor's purpose is to
tether the digital world to an undeniable physical event, and its
irreplaceability is precisely what makes the social graph recovery mechanism a
non-negotiable part of the architecture.</li>
<li class="">Pragmatic Paths to Adoption: The conversation naturally turned to strategy.
"How do we fight the incumbents head-on?" was revealed to be the wrong
question. A more nuanced discussion about the Overlay and Invert strategy
unfolded, focusing on pragmatic, asymmetric entrypoints. The consensus was
that the most viable path is to first establish a beachhead in "greenfield"
areas where legacy identity solutions are weak or non-existent, proving the
model's resilience there before challenging the core human identity space.</li>
<li class="">The Hardware Foundation: Finally, the discussion kept returning to a
fundamental truth: software-only solutions do not grant full sovereignty. A
system's claims can only be truly guaranteed if the hardware it runs on is
verifiable. The group acknowledged that a long-term vision for anti-fragile
trust must include a path toward verifiable, open hardware supply chains.</li>
</ul>
<p>It's these kinds of conversations that transform ideas into movements. My
deepest thanks to the organizers and attendees of EthKL for providing the forum.</p>
<p>If these questions and challenges excite you as much as they excite us, the
conversation is only just beginning. Join us as developers, partners and
pioneers building out this new Polykey substrate of trust.</p>]]></content>
        <author>
            <name>Roger Qiu</name>
            <uri>https://github.com/CMCDragonkai</uri>
        </author>
        <category label="distributed-systems" term="distributed-systems"/>
        <category label="security" term="security"/>
        <category label="sovereignty" term="sovereignty"/>
        <category label="philosophy" term="philosophy"/>
        <category label="architecture" term="architecture"/>
        <category label="identity" term="identity"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[AI Detection versus Cryptographic Provenance]]></title>
        <id>https://polykey.com/blog/ai-detection-versus-cryptographic-provenance</id>
        <link href="https://polykey.com/blog/ai-detection-versus-cryptographic-provenance"/>
        <updated>2025-02-17T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[During SXSW 2023, Greg Brockman discussed how large language models (LLMs)]]></summary>
        <content type="html"><![CDATA[<p>During SXSW 2023, Greg Brockman discussed how large language models (LLMs)
challenge traditional notions of truth, authenticity, and creative ownership.
The rise of AI-generated text, images, and even deepfake videos has made it
increasingly difficult to distinguish what is real from what is artificially
generated.</p>
<iframe width="560px" height="315px" src="https://www.youtube.com/embed/YtJEfTTD_Y4?si=mt9_2is7J8vhYRca&amp;start=2390" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture;" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen=""></iframe>
<p>From news organizations to schools to user-generated content platforms, they are
all clamoring for solutions to detect artificially generated content. So how do
we prove what's real anymore?</p>
<p>This has led to the emergence of numerous startups and tools aiming to identify
AI-generated text, images, audio, and video. As of March 2025, examples include
GPTZero, Copyleaks, Decopy AI Detector, Scribbr AI Detector and more...</p>
<p>Some of these solutions claim 99% accuracy (until they quietly roll that number
back after real-world tests). Others take the security theater approach,
offering expensive enterprise solutions that amount to a probabilistic guess
wrapped in a glossy UI.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="ai-detection-is-a-waste-of-time-because-it-does-not-scale">AI Detection is a Waste of Time because it Does Not Scale<a href="https://polykey.com/blog/ai-detection-versus-cryptographic-provenance#ai-detection-is-a-waste-of-time-because-it-does-not-scale" class="hash-link" aria-label="Direct link to AI Detection is a Waste of Time because it Does Not Scale" title="Direct link to AI Detection is a Waste of Time because it Does Not Scale" translate="no">​</a></h2>
<p>The problem is that AI detection is an arms race that cannot be won. The moment
detectors improve, generative AI adapts to evade them. Both are trained using
the same fundamental techniques, ensuring that detection will always be reactive
rather than proactive. Since AI detectors rely on past data to recognize
patterns, they can only flag content that fits known characteristics of AI
generation. Meanwhile, AI models can continuously evolve to eliminate those
characteristics, rendering previous detection methods ineffective.</p>
<p>This is the core dynamic of Generative Adversarial Networks (GANs): a continuous
back-and-forth where detection improvements directly drives the refinement of
generation techniques. Every time AI detection advances, it introduces new
challenges for AI developers to overcome. Previously detectable traits, such as
unnatural textures or irregular text coherence, disappear in newer model
iterations. Detection benchmarks become part of the dataset for training
next-generation AI, making forensic methods quickly obsolete.</p>
<p><a href="http://archive.today/Lcl64" target="_blank" rel="noopener noreferrer" title="Original: https://arxiv.org/abs/1412.6572" class="">Research in Adversarial AI</a>
has demonstrated how easily deep learning models can be fooled by minor
modifications to input data. Small, imperceptible pixel changes can cause
classifiers to misidentify an image. A
<a href="http://archive.today/MEswE" target="_blank" rel="noopener noreferrer" title="Original: https://arxiv.org/abs/1707.08945" class="">well-placed sticker</a>
on a Stop sign can trick an AI into reading it as a Speed Limit sign. The same
principle applies to AI-generated content, once detection models are publicly
available, they serve as a benchmark for evasion.</p>
<p>For AI detection to stay ahead, it would need to anticipate and classify future
AI-generation techniques before they exist, which is computationally infeasible.
The space of possible AI-generated outputs is too large, and there is no fixed
"fingerprint" of AI content that detectors can reliably target. Any pattern a
detector identifies can be removed in the next model iteration. More aggressive
detectors risk misclassifying human-created content, while more conservative
ones become ineffective against rapidly evolving AI. This tradeoff between false
positives and false negatives makes AI detection an unreliable long-term
solution.</p>
<p>Ultimately, AI detectors are locked in a perpetual defensive position, always
reacting to new developments rather than preempting them. Every detection
breakthrough feeds directly into the next generation of AI, strengthening it.
The fundamental asymmetry between AI detection and generation ensures that
detection will always be one step behind.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="relying-on-ai-detection-creates-a-problem-of-trust">Relying on AI Detection Creates a Problem of Trust<a href="https://polykey.com/blog/ai-detection-versus-cryptographic-provenance#relying-on-ai-detection-creates-a-problem-of-trust" class="hash-link" aria-label="Direct link to Relying on AI Detection Creates a Problem of Trust" title="Direct link to Relying on AI Detection Creates a Problem of Trust" translate="no">​</a></h2>
<p>Even if AI detection were effective, it raises a deeper issue: trust. Who
controls these detection systems? Who verifies their accuracy? AI detection
models function as opaque black boxes, making unverifiable claims about content
authenticity. They just provide a probabilistic output that users are expected
to trust. If an AI model flags a piece of content as artificially generated, how
does someone challenge that claim? What recourse is there for those falsely
accused of using AI-generated content? Without transparency or an independent
verification mechanism, AI detection creates a new layer of authority that
operates without accountability.</p>
<p>This problem extends beyond misclassification. If platforms rely on AI detection
to filter or moderate content, it places significant power in the hands of
whoever controls the detection models. AI detection can be abused, whether
intentionally or as a side effect of systemic bias. If an AI classifier is
treated as an arbiter of truth, it can be used to flag inconvenient content,
silence dissent, or falsely discredit legitimate material. We've already seen
real images being
<a href="http://archive.today/Fj3YH" target="_blank" rel="noopener noreferrer" title="Original: https://www.pcmag.com/news/ai-is-marking-some-real-images-from-the-war-in-israel-as-fake" class="">wrongfully flagged as AI-generated</a>,
raising concerns about false positives in high-stakes scenarios. This risk grows
when platforms and governments start relying on AI detection at scale, as the
ability to challenge an incorrect classification becomes nearly impossible.</p>
<p>This centralization of authority on what's real and what's not introduces a new
failure mode: what happens when the detection system itself is wrong? If
detection models are treated as infallible, their mistakes become
indistinguishable from deliberate manipulation. A flawed detection system
doesn't just misclassify content, it creates an environment where authenticity
is dictated rather than demonstrated. If a system cannot be challenged or
independently verified, then it cannot be trusted as a solution to the problem
it claims to solve.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="cryptographic-provenance-is-the-only-solution">Cryptographic Provenance is the Only Solution<a href="https://polykey.com/blog/ai-detection-versus-cryptographic-provenance#cryptographic-provenance-is-the-only-solution" class="hash-link" aria-label="Direct link to Cryptographic Provenance is the Only Solution" title="Direct link to Cryptographic Provenance is the Only Solution" translate="no">​</a></h2>
<p>Cryptographic provenance offers an approach fundamentally different from AI
detection, it does not attempt to guess whether something is real or fake but
instead provides verifiable proof of origin. Unlike probabilistic classifiers,
cryptographic provenance ensures that content can be traced back to its source
in a way that is independently verifiable and tamper-proof.</p>
<p>Cryptographic provenance is based on digital signatures and cryptographic
hashing. When a piece of content such as an image, video, or document is
created, a cryptographic hash is generated. This hash is a unique fingerprint of
the content, which changes completely if even a single pixel or letter is
modified. The hash is then signed by a trusted entity, such as the camera,
software, or organization capturing the content. This signature proves that the
content was recorded or created at a specific point in time and has not been
altered since.</p>
<p>Because cryptographic hashes are computationally infeasible to forge, they
provide strong guarantees of authenticity. Unlike metadata, which can be easily
edited or removed, cryptographic provenance is tied directly to the content
itself. This allows anyone to verify the integrity of a file without relying on
a centralized authority. If a file has been modified, its cryptographic hash
will no longer match, making tampering immediately detectable.</p>
<p><img decoding="async" loading="lazy" alt="C2PA Diagram" src="https://polykey.com/assets/images/c2pa-diagram-63c5c7d40233170b4d722979860fce28.png" width="1542" height="1024" class="img_ev3q"></p>
<p>One of the most widely adopted provenance solutions is the Coalition for Content
Provenance and Authenticity (C2PA), an initiative backed by Adobe, Microsoft,
Intel, and Google. C2PA embeds cryptographic metadata into media files at the
point of creation, recording details such as the source, timestamp, and any
modifications made to the content. The goal is to enable verification of images
and videos by checking their metadata against a trusted ledger of provenance
records.</p>
<p>While C2PA represents a step toward verifiable media authenticity, it has
limitations. The most immediate issue is that metadata can be stripped. A file
signed with C2PA provenance can be downloaded, altered, and re-uploaded without
its original metadata, making verification impossible. Many platforms already
strip metadata by default for privacy reasons, and unless every major platform
enforces C2PA metadata retention, unverified copies will continue to circulate.</p>
<p>Another limitation is that C2PA does not verify whether the content was
manipulated before it was recorded. If an AI-generated deepfake is signed at the
moment of creation, it appears just as authentic as real footage. Provenance
alone does not determine truth, it only tracks the history of a file, not
whether the content itself is genuine.</p>
<p><img decoding="async" loading="lazy" alt="Centralized Trust Network" src="https://polykey.com/assets/images/centralized-trust-network-87572689b854d7a25f8107ba319aa821.svg" width="2020" height="1645" class="img_ev3q"></p>
<p>Beyond technical concerns, cryptographic provenance runs into a broader issue:
centralization. For provenance systems like C2PA to be widely adopted, they rely
on a small number of trusted organizations to issue and verify content
signatures. This creates a single point of control over what is considered
"authentic." If a handful of companies act as gatekeepers for verification, they
have the power to dictate which content is considered real and which is not.</p>
<p>This introduces the same risks as AI detection: censorship, misclassification,
and manipulation. If platforms or governments require provenance verification
for content distribution, content without cryptographic signatures could be
devalued or even suppressed. A centralized verification system does not
eliminate misinformation; it simply shifts control over authenticity from AI
classifiers to a small group of organizations.</p>
<p>Cryptographic provenance is an important step toward solving the problem of
digital authenticity, but its implementation matters. If verification remains
centralized, it risks becoming another authority-based system where trust is
dictated rather than independently verifiable. The challenge is not just proving
where content comes from, but ensuring that no single entity has the power to
control what is considered real.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="introducing-a-decentralized-trust-network">Introducing a Decentralized Trust Network<a href="https://polykey.com/blog/ai-detection-versus-cryptographic-provenance#introducing-a-decentralized-trust-network" class="hash-link" aria-label="Direct link to Introducing a Decentralized Trust Network" title="Direct link to Introducing a Decentralized Trust Network" translate="no">​</a></h2>
<p>Centralized provenance systems, like C2PA, introduce a single point of control
over what is considered "authentic," making them vulnerable to manipulation and
censorship. A Decentralized Trust Network (DTN) solves this problem by
distributing trust across independent participants rather than concentrating
authority in a handful of entities.</p>
<p>A DTN does not rely on metadata embedded within content, which can be easily
stripped or altered. Instead, it allows content authenticity to be claimed on a
distributed ledger, ensuring that provenance remains verifiable even if the
original file is modified or reuploaded. More importantly, DTNs recognize that
truth is not absolute. It is socially constructed. Authenticity should not be
dictated by a single gatekeeper but established through multiple independent
claims that can be corroborated, challenged, and verified.</p>
<p><img decoding="async" loading="lazy" alt="Decentralized Trust Network" src="https://polykey.com/assets/images/decentralized-trust-network-9832ea0760e45d9bd8cc22ef7d4748ae.svg" width="5200" height="4840" class="img_ev3q"></p>
<p><a href="https://polykey.com/docs/theory/decentralized-trust-network" target="_blank" rel="noopener noreferrer" class="">Polykey's Decentralized Trust Network (DTN)</a>
is designed to provide cryptographic verification of content while avoiding the
pitfalls of centralized control. It achieves this through cryptographic
fingerprints, independent Polykey nodes that store and verify trust data, and
Gestalts, trust collectives that allow for flexible, socially or institutionally
scoped verification. Unlike traditional blockchains, Polykey's DTN does not
require slow or energy-intensive consensus mechanisms. Instead of securing
financial transactions, it is optimized for verifying authenticity efficiently
through cryptographic signatures and peer validation. This makes it scalable
while eliminating unnecessary computational overhead.</p>
<p>A DTN ensures that content's existence and integrity are verifiable, but it also
establishes who created it and whether it has maintained its integrity over
time. This is achieved through Signature Chains (SigChains), which form the
backbone of Polykey's DTN. Each Polykey node maintains its own SigChain, where
all claims are automatically signed by the node’s own authority, creating an
immutable cryptographic record of attestations that can be independently
verified.</p>
<p>Because all nodes in the DTN are part of a Gestalt, SigChains inherit the
real-world identity associations of the Gestalt itself. Gestalts are
cryptographically linked to external digital identities such as Instagram, X,
Facebook, Nostr, or other third-party verification sources. This means that when
a Polykey node issues a claim, it is not just a detached cryptographic
assertion, it is rooted in a broader web of trust, where multiple independent
entities corroborate authenticity. This structure enables trust delegation
without centralizing control, ensuring that verification remains distributed
while allowing for real-world accountability.</p>
<p>Polykey's DTN recognizes that truth is often socially determined. The current
media landscape prioritizes speed over accuracy. News outlets, influencers, and
platforms rush to publish first, even if the information is later retracted. By
the time corrections are issued, the impact has already been made. A
decentralized trust network shifts this dynamic by incentivizing accuracy over
speed. SigChains allow multiple independent authorities to make corroborating
claims on reality, supported by verifiable content. This creates a
reputation-based system where those who stake their trust on false claims suffer
credibility losses, reducing the incentive to publish misleading or inaccurate
information. Unlike traditional provenance models, which rely on static
metadata, Polykey's DTN enables a more dynamic and robust system of truth
verification.</p>
<p>The key lesson here is that it doesn't actually matter whether content is
AI-generated or not. What matters is the underlying truth claim that the content
represents. AI-generated media is not inherently false, just as human-created
media is not inherently true. A deepfake can be labeled as such while still
being a valid satirical expression, and an unedited video can still be used out
of context to mislead. The problem is not how content is created but what it
claims to represent. This is why focusing on AI detection is the wrong problem.
Provenance is not about filtering AI out of the conversation but about ensuring
that claims about reality can be verified in a decentralized and accountable
way.</p>
<p>Polykey's DTN is more than just a cryptographic provenance system. It represents
the next phase of decentralized authority management. While Polykey began as a
system for managing digital secrets and access control, the same principles of
distributed trust apply to content authenticity, identity verification, and
broader claims about reality. In a world where AI-generated content is becoming
indistinguishable from reality, we need a trust system that is verifiable,
resilient, and independent of centralized control. The future of digital trust
is not about fighting AI, but about creating systems that allow us to verify the
truth, no matter how it is expressed.</p>]]></content>
        <author>
            <name>Christina Kelley</name>
            <uri>https://github.com/xrissoula</uri>
        </author>
        <author>
            <name>Roger Qiu</name>
            <uri>https://github.com/CMCDragonkai</uri>
        </author>
        <category label="ai" term="ai"/>
        <category label="deepfakes" term="deepfakes"/>
        <category label="provenance" term="provenance"/>
        <category label="decentralized-trust-network" term="decentralized-trust-network"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Introduction to Delegation of Authority]]></title>
        <id>https://polykey.com/blog/introduction-to-delegation-of-authority</id>
        <link href="https://polykey.com/blog/introduction-to-delegation-of-authority"/>
        <updated>2025-02-06T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Organizations distribute responsibility through the delegation of authority.]]></summary>
        <content type="html"><![CDATA[<p>Organizations distribute responsibility through the delegation of authority.
Delegation stems from a fundamental limitation: no single person or system can
do everything. To scale effectively, organizations distribute decision-making
through delegation. But how authority is assigned matters: too little, and tasks
remain incomplete; too much, and you expose vulnerabilities.</p>
<p>For example, giving an employee a key to an office containing confidential
documents bears similar risks to granting users access to sensitive databases.
Delegation requires trust, but trust introduces risk.</p>
<p>At its core, delegation involves three key elements:</p>
<ol>
<li class=""><strong>Authentication</strong> - Assigning Authority Choosing who receives
decision-making power.</li>
<li class=""><strong>Authorisation</strong> - Defining Scope Setting limits on what they can and cannot
do.</li>
<li class=""><strong>Accounting</strong> - Implementing Oversight Ensuring accountability and
preventing misuse.</li>
</ol>
<p><img decoding="async" loading="lazy" alt="Hierarchy of Authority Delegation" src="https://polykey.com/assets/images/authority-delegation-hierarchy-540d879eb247edd400359b471683ee5b.png" width="930" height="873" class="img_ev3q"></p>
<p>Here are 2 simple examples:</p>
<ul>
<li class="">A front desk worker can operate a Point of Sale register but cannot issue
refunds above a set limit.</li>
<li class="">A soccer referee can eject a player for a foul but cannot ban them from the
league.</li>
</ul>
<p>The same principle applies in digital systems, unnecessary access increases
vulnerabilities, while restricting access too much slows productivity.</p>
<p>Delegation always involves a trade-off between trust and control:</p>
<ul>
<li class="">Too little authority - Tasks remain incomplete.</li>
<li class="">Too much authority - You introduce risks of potential compromise either due to
maliciousness or accidents.</li>
</ul>
<p>Here are some examples of when there's too little authority:</p>
<ul>
<li class="">A receptionist must ask a manager for every patient update.</li>
<li class="">A developer can't deploy code, delaying releases.</li>
</ul>
<p>Here are some examples of when there's too much authority:</p>
<ul>
<li class="">A junior employee is mistakenly given admin access to a database.</li>
<li class="">A cashier can issue refunds without oversight, leading to fraud.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-principle-of-least-privilege-polp">The Principle of Least Privilege (POLP)<a href="https://polykey.com/blog/introduction-to-delegation-of-authority#the-principle-of-least-privilege-polp" class="hash-link" aria-label="Direct link to The Principle of Least Privilege (POLP)" title="Direct link to The Principle of Least Privilege (POLP)" translate="no">​</a></h2>
<p>To minimize risk, organizations follow POLP: "Give people only the minimum
necessary authority to complete their tasks—no more, no less."</p>
<p>Most systems that enable delegation ends up granting more power than necessary,
leading to ambient authority. These are the extra permissions that aren't
strictly needed.</p>
<p><img decoding="async" loading="lazy" alt="Ambient Authority versus Intended Authority" src="https://polykey.com/assets/images/ambient-authority-77ad7d14aa2339b9a38161239167a966.svg" width="1046" height="376" class="img_ev3q"></p>
<p>In the above diagram, we show that ambient authority is the extra authority
someone has but doesn't need. Whereas the intended authority is the exact amount
of power necessary for a task. Therefore reducing ambient authority reduces
risk. This is the foundation of Zero Trust and this is something we will explore
in subsequent blog posts.</p>
<p>Delegation is essential, but it requires careful management to avoid
inefficiencies and risks. The key is to balance trust and control, ensuring
authority is assigned wisely and responsibly.</p>]]></content>
        <author>
            <name>Christina Kelley</name>
            <uri>https://github.com/xrissoula</uri>
        </author>
        <category label="authority" term="authority"/>
        <category label="trust" term="trust"/>
        <category label="identity-management" term="identity-management"/>
        <category label="aaa" term="aaa"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Global/Public ACL and Trust Federation: Decentralized Authority Reimagined]]></title>
        <id>https://polykey.com/blog/global-public-acl-and-trust-federation</id>
        <link href="https://polykey.com/blog/global-public-acl-and-trust-federation"/>
        <updated>2024-08-28T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Non-Fungible Tokens (NFTs) on the blockchain are more than just digital]]></summary>
        <content type="html"><![CDATA[<p>Non-Fungible Tokens (NFTs) on the blockchain are more than just digital
collectibles. They can act as decentralized form of internet
<a href="https://wiki.c2.com/?CapabilitySecurityModel" target="_blank" rel="noopener noreferrer" class="">capabilities/permissions</a> to
decentralized or centralized resources. This enables the creation of a global
internet-wide ACL (Access Control List). Unlike centralized ACLs, where
permissions are entirely controlled by the central platform, NFT capability
ownership is maintained through decentralized consensus. This provides both
censorship resistance and the ability to transfer permissions as assets.
However, it has scalability drawbacks intrinsic to blockchain networks.</p>
<p>Centralized platforms can make use decentralized capabilities to gate features
within their systems. For instance, <a href="https://claritys.so/" target="_blank" rel="noopener noreferrer" class="">Clarity.so</a> has
introduced token-based roles and permissions, allowing users to unlock features
based on their possession of decentralized tokens. Similarly, platforms like
<a href="https://lu.ma/" target="_blank" rel="noopener noreferrer" class="">Luma</a> use NFTs to gate events, requiring attendees to hold
specific tokens in their wallets for access. Below is an example of how Luma
implements token gating for event registration:</p>
<p><img decoding="async" loading="lazy" alt="Token Gate Events" src="https://polykey.com/assets/images/luma-token-gating-8c4cc834aafd877172c546840b7eb41c.png" width="852" height="784" class="img_ev3q"></p>
<p>Why would centralized platforms open their security systems to the public
blockchain? There could be benefits similar to why certain systems use "login
via social network". The cost of implementation can be decreased, while
leveraging pre-existing identity structures reduces the friction of onboarding
for customers. Therefore at the same time, using NFT capabilities or fungible
capabilities is way of leveraging a network effect of other public authority
systems on the blockchain.</p>
<p>There are several problems with relying on NFTs as your permission system:</p>
<ul>
<li class="">Delegation of authority requires a transaction on the blockchain will cost
some unit of energy.</li>
<li class="">The authority structure is being revealed publically and this may not be
suitable for privacy.</li>
<li class="">The blockchain is being polluted with information that's only relevant to a
subset of users.</li>
<li class="">During high congestion, the cost to delegate will increase even more.</li>
</ul>
<p>Before NFTs, tokenized capabilities existed in the form of JSON Web Tokens
(JWTs). JWTs are self-contained bearer tokens, possessing the JWT as a string
equals possessing the permission. This means the security of JWTs depend on the
issuing system and the bearer system to securely manage the shared secret.</p>
<p>An example of JWTs in centralized systems are magic links. These magic links are
a convenient way to grant temporary access to resources. However, using these
links relies on out-of-band communication, potentially exposing the secret over
insecure channels.</p>
<p>It is possible to avoid the problem of preventing exposure by changing the way
ownership of the permission is expressed. Rather than simply bearing a secret
token, the token can instead embed a claim that a particular identity has an
authority. Then this is combined with a proof of authority that can be checked.
The simplest proof is where the token is signed by a trusted authority, and the
signature can be checked to be genuine. The user/program attempting access has
to also prove that they are in fact the identity expressed within token claim.
This can be achieved with the user/program's own signature.</p>
<p>Signed JWTs add a layer of asymmetric authority through a cryptographic
signature from a trusted entity. This model doesn’t rely on decentralized
consensus but rather on the trustworthiness of the signature’s authority. This
makes it more flexible and scalable than NFTs but shifts security onto the
reliability of the signing authority. What this means is that security of the
signed JWT does not rely on secrecy. In Polykey, for example, signed JWTs could
be made public to the network via the sigchain module.</p>
<p>In the signed JWT case, delegation of authority is not a simple matter of
sharing a token. A derivative token must be minted that extends the authority to
another identity.</p>
<p>A signed JWT doesn't have to be public, it can still be transferred secretly
over secure channels, it just not catastrophic if it were exposed. However there
could be benefits to public attestation to claims just like NFTs on a public
blockchain.</p>
<p>Polykey enables the ability to manage both tokenized authorities such as JWT
shared secrets and capabilities expressed through signed JWTs by creating a
<strong>secure highway of authority</strong>. In scenarios where a more decentralized
approach is needed, Polykey could integrate with Ethereum to mint NFTs
representing access capabilities. These NFTs would be transferrable and
verifiable through the blockchain enabling integration into further
decentralized resources or centralized platforms relying on these public
blockchain capabilities.</p>
<p>Polykey is also exploring the concept of federated tokens that operate across
multiple domains or blockchains. These tokens could combine the best of both
JWTs and NFTs, offering fine-grained control over permissions in a decentralized
environment. Recent developments in Polykey, such as enabling nodes to access
private networks through cross-chain interactions, underscore the potential for
a federated trust model. By allowing nodes to issue and validate tokens across
different networks, Polykey could create a scalable, flexible system for
managing decentralized authority.</p>
<p>The issues <a href="https://github.com/MatrixAI/Polykey/issues/779" target="_blank" rel="noopener noreferrer" class="">Polykey#779</a> and
<a href="https://github.com/MatrixAI/Polykey/issues/770" target="_blank" rel="noopener noreferrer" class="">Polykey#770</a> in our Polykey
GitHub repository tracks our work on network segregation and authentication
token logic. These developments are critical in ensuring secure and seamless
access to private networks, enabling Polykey nodes to authenticate and operate
within various isolated environments while maintaining decentralized integrity.</p>
<p>Enforcing policy across decentralized systems is challenging, especially when
dealing with nodes not fully under central control. While decentralized networks
offer resilience and flexibility, they also open the door to potential rule
violations by nodes that may have been modified or corrupted. In Polykey, this
challenge is addressed by leveraging its sigchain and decentralized architecture
to ensure all nodes adhere to network policies. However, the need for <strong>full
stack control</strong> becomes apparent when dealing with potentially rogue nodes that
could hide unauthorized activities.</p>
<p>The convergence of NFTs, JWTs, and federated blockchains offers a tantalizing
glimpse into the future of centralized and decentralized authority. By combining
these technologies, we can create more resilient, scalable, and flexible systems
for managing identities and permissions across multiple domains. As we explore
these possibilities with Polykey, our goal is to create interoperable tokens
that leverage both decentralized consensus and trusted authorities, paving the
way for a new era of decentralized trust infrastructure.</p>
<p>Future discussions may focus on what it means to have a global ACL system where
some kinds of access-control is mediated through the blockchain rather than
ad-hoc trust networks between centralized platforms.</p>]]></content>
        <author>
            <name>Roger Qiu</name>
            <uri>https://github.com/CMCDragonkai</uri>
        </author>
        <category label="decentralization" term="decentralization"/>
        <category label="jwt" term="jwt"/>
        <category label="blockchain" term="blockchain"/>
        <category label="identity-management" term="identity-management"/>
        <category label="trust-federation" term="trust-federation"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Leveraging Social Networks in the Web of Trust: Making Decentralized Identity Accessible]]></title>
        <id>https://polykey.com/blog/leveraging-social-networks-web-of-trust</id>
        <link href="https://polykey.com/blog/leveraging-social-networks-web-of-trust"/>
        <updated>2024-07-25T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Decentralized systems that rely on public private keypairs for identity such as]]></summary>
        <content type="html"><![CDATA[<p>Decentralized systems that rely on public private keypairs for identity such as
Polykey's NodeIds face the
<a href="https://en.wikipedia.org/wiki/Zooko%27s_triangle" target="_blank" rel="noopener noreferrer" class="">Zooko's triangle</a> problem.</p>
<p><img decoding="async" loading="lazy" alt="Zooko&amp;#39;s Triangle" src="data:image/svg+xml;base64,PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiIHN0YW5kYWxvbmU9Im5vIj8+CjwhLS0gQ3JlYXRlZCB3aXRoIElua3NjYXBlIChodHRwOi8vd3d3Lmlua3NjYXBlLm9yZy8pIC0tPgoKPHN2ZwogICB4bWxuczpkYz0iaHR0cDovL3B1cmwub3JnL2RjL2VsZW1lbnRzLzEuMS8iCiAgIHhtbG5zOmNjPSJodHRwOi8vY3JlYXRpdmVjb21tb25zLm9yZy9ucyMiCiAgIHhtbG5zOnJkZj0iaHR0cDovL3d3dy53My5vcmcvMTk5OS8wMi8yMi1yZGYtc3ludGF4LW5zIyIKICAgeG1sbnM6c3ZnPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIKICAgeG1sbnM9Imh0dHA6Ly93d3cudzMub3JnLzIwMDAvc3ZnIgogICB2ZXJzaW9uPSIxLjEiCiAgIHdpZHRoPSI0NTAiCiAgIGhlaWdodD0iMzkwIgogICBpZD0ic3ZnMiI+CiAgPG1ldGFkYXRhCiAgICAgaWQ9Im1ldGFkYXRhMzIiPgogICAgPHJkZjpSREY+CiAgICAgIDxjYzpXb3JrCiAgICAgICAgIHJkZjphYm91dD0iIj4KICAgICAgICA8ZGM6Zm9ybWF0PmltYWdlL3N2Zyt4bWw8L2RjOmZvcm1hdD4KICAgICAgICA8ZGM6dHlwZQogICAgICAgICAgIHJkZjpyZXNvdXJjZT0iaHR0cDovL3B1cmwub3JnL2RjL2RjbWl0eXBlL1N0aWxsSW1hZ2UiIC8+CiAgICAgICAgPGRjOnRpdGxlPjwvZGM6dGl0bGU+CiAgICAgIDwvY2M6V29yaz4KICAgIDwvcmRmOlJERj4KICA8L21ldGFkYXRhPgogIDxkZWZzCiAgICAgaWQ9ImRlZnM0IiAvPgogIDxnCiAgICAgdHJhbnNmb3JtPSJtYXRyaXgoMS4yMDU1Mjc0LDAsMCwxLjIwNTUyNzQsOS41NDA2OTE5LDkuNDQ1NjE4KSIKICAgICBpZD0iZzYiPgogICAgPHBhdGgKICAgICAgIGQ9Ik0gNjgsNTUgMzc3LDIzMSA2OCw0MDcgeiIKICAgICAgIHRyYW5zZm9ybT0ibWF0cml4KDAuODY2MDI1NCwwLjUsLTAuNSwwLjg2NjAyNTQsMTQ1LjM3NjMzLC04MC41NTE4NjgpIgogICAgICAgaWQ9InBhdGg4IgogICAgICAgc3R5bGU9ImZpbGw6I2ZmZmZmZjtzdHJva2U6IzAwMDAwMDtzdHJva2UtbWl0ZXJsaW1pdDoxMCIgLz4KICAgIDxyZWN0CiAgICAgICB3aWR0aD0iMTM1IgogICAgICAgaGVpZ2h0PSI2OCIKICAgICAgIHg9IjIyMyIKICAgICAgIHk9IjI1MSIKICAgICAgIGlkPSJyZWN0MTAiCiAgICAgICBzdHlsZT0iZmlsbDpub25lO3N0cm9rZTpub25lIiAvPgogICAgPGcKICAgICAgIGlkPSJnMTIiCiAgICAgICBzdHlsZT0iZm9udC1zaXplOjE4cHg7Zm9udC13ZWlnaHQ6Ym9sZDt0ZXh0LWFuY2hvcjptaWRkbGU7ZmlsbDojMDAwMDAwO2ZvbnQtZmFtaWx5OlZlcmRhbmEiPgogICAgICA8dGV4dAogICAgICAgICB4PSIyOTEiCiAgICAgICAgIHk9IjI5MiIKICAgICAgICAgaWQ9InRleHQxNCI+U2VjdXJlPC90ZXh0PgogICAgPC9nPgogICAgPHJlY3QKICAgICAgIHdpZHRoPSIxMDAiCiAgICAgICBoZWlnaHQ9IjUwIgogICAgICAgeD0iNDgiCiAgICAgICB5PSIyNjAiCiAgICAgICBpZD0icmVjdDE2IgogICAgICAgc3R5bGU9ImZpbGw6bm9uZTtzdHJva2U6bm9uZSIgLz4KICAgIDxnCiAgICAgICBpZD0iZzE4IgogICAgICAgc3R5bGU9ImZvbnQtc2l6ZToxOHB4O2ZvbnQtd2VpZ2h0OmJvbGQ7dGV4dC1hbmNob3I6bWlkZGxlO2ZpbGw6IzAwMDAwMDtmb250LWZhbWlseTpWZXJkYW5hIj4KICAgICAgPHRleHQKICAgICAgICAgeD0iOTgiCiAgICAgICAgIHk9IjI5MiIKICAgICAgICAgaWQ9InRleHQyMCI+RGVjZW50cmFsaXplZDwvdGV4dD4KICAgIDwvZz4KICAgIDxyZWN0CiAgICAgICB3aWR0aD0iODAiCiAgICAgICBoZWlnaHQ9IjQwIgogICAgICAgeD0iMTM4IgogICAgICAgeT0iODUiCiAgICAgICBpZD0icmVjdDIyIgogICAgICAgc3R5bGU9ImZpbGw6bm9uZTtzdHJva2U6bm9uZSIgLz4KICAgIDxnCiAgICAgICBpZD0iZzI0IgogICAgICAgc3R5bGU9ImZvbnQtc2l6ZToxOHB4O2ZvbnQtd2VpZ2h0OmJvbGQ7dGV4dC1hbmNob3I6bWlkZGxlO2ZpbGw6IzAwMDAwMDtmb250LWZhbWlseTpWZXJkYW5hIj4KICAgICAgPHRleHQKICAgICAgICAgeD0iMTc4IgogICAgICAgICB5PSIxMDEiCiAgICAgICAgIGlkPSJ0ZXh0MjYiPkh1bWFuLTwvdGV4dD4KICAgICAgPHRleHQKICAgICAgICAgeD0iMTc4IgogICAgICAgICB5PSIxMjMiCiAgICAgICAgIGlkPSJ0ZXh0MjgiPm1lYW5pbmdmdWw8L3RleHQ+CiAgICA8L2c+CiAgPC9nPgo8L3N2Zz4K" width="450" height="390" class="img_ev3q"></p>
<p>The public key identifiers are decentralized and secure, but they aren't human
meaningful. This makes it difficult to find your friend's NodeIds.</p>
<p>Traditionally establishing a web of trust between these NodeIds without a
centralized registry involved cryptographic key-signing parties in dimly lit
back rooms of tech conferences—hardly accessible to your everyday internet user.</p>
<p>But what if we could skip the awkward small talk and instead tap into platforms
where people already feel at home, like social networks?</p>
<p><a href="https://keybase.io/" target="_blank" rel="noopener noreferrer" class="">Keybase</a> discovered that social networks could serve as
<a href="https://en.wikipedia.org/wiki/Focal_point_(game_theory)" target="_blank" rel="noopener noreferrer" class="">discovery focal points</a>
for discovering decentralized identities. Most people already trust these
platforms and are familiar with how they work.</p>
<p>The idea is simple: users can post a cryptographically signed claim, or what we
call a "cryptolink" on their social network profiles. This post, publicly
accessible and searchable, serves as a verifiable claim that links their social
network identity to their decentralized Polykey NodeId. As long as the social
network provides APIs for posting and searching, it can be integrated into
Polykey.</p>
<p><img decoding="async" loading="lazy" alt="Github Cryptolinks" src="https://polykey.com/assets/images/github_gist_cryptolinks_json-61b2daf680e4ecee4d920144bf5fce3a.png" width="1592" height="634" class="img_ev3q"></p>
<p>However, there's a hitch. Social networks are increasingly closing off their
platforms, limiting API access for posting or searching content. This trend
forces us to either adapt by using manual methods or restrict the range of
supported networks. For instance, manually posting a cryptolink might involve
copy-pasting a generated message, while manually searching for someone else's
cryptolink could become a scavenger hunt. But with a unique link, the process
remains feasible, even if less automated.</p>
<p>By using a platform like Polykey, users can discover the NodeIds of their
friends or acquaintances directly through social networks. This approach doesn’t
just democratize access to the web of trust; it makes it practical and
intuitive. Unlike our inspiration, Keybase, Polykey does not maintain a
centralized registry of cryptolink claims. The claims are simply replicated on
each Polykey node's sigchain.</p>
<p>Do note that using these centralized social networks is entirely optional.
Polykey does not depend on them. Any social network can be used as a discovery
point, including your IRL key signing party.</p>
<p>Currently, Polykey integrates with GitHub, allowing developers to leverage their
GitHub identities in the web of trust. We’re eager to expand this to other
platforms and encourage contributions from the community. Given the nature of
Polykey, future integrations will likely involve WebAssembly (WASM) plugins,
offering flexibility and performance across various platforms. Decentralized
identity platforms, particularly those using blockchain-based identifiers
(DIDs), are tailor-made for this. They align perfectly with the principles of
decentralized trust and provide a robust foundation for identity verification in
the web of trust.</p>
<p>The potential here extends far beyond just identity verification—it could lead
to advanced trust metrics, scoring systems, and even a marketplace for trust.
The integration of social networks with decentralized identity systems
represents a significant leap forward. It makes the web of trust more accessible
and practical, moving it out of niche tech circles and into the broader internet
community.</p>]]></content>
        <author>
            <name>Roger Qiu</name>
            <uri>https://github.com/CMCDragonkai</uri>
        </author>
        <category label="web-of-trust" term="web-of-trust"/>
        <category label="decentralized-identity" term="decentralized-identity"/>
        <category label="social-networks" term="social-networks"/>
        <category label="cryptography" term="cryptography"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Introducing Polykey - A Future Security Standard for Replacing Dotenv Libraries]]></title>
        <id>https://polykey.com/blog/introducing-polykey-a-future-security-standard-for-replacing-dotenv-libraries</id>
        <link href="https://polykey.com/blog/introducing-polykey-a-future-security-standard-for-replacing-dotenv-libraries"/>
        <updated>2024-05-30T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[As the landscape of software development evolves, securing sensitive data]]></summary>
        <content type="html"><![CDATA[<p>As the landscape of software development evolves, securing sensitive data
remains a paramount concern. Traditionally, environment variables in
environments like Node.js, which extensively utilize <code>.env</code> files managed by
<code>dotenv</code> libraries, are prone to security risks. These <code>.env</code> files, while
straightforward, harbor significant security vulnerabilities. Sensitive
information such as API keys and database passwords are often stored in
plaintext, leading to potential data leaks if these files are not managed
correctly or accidentally committed to public repositories.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="polykey-elevating-security-and-efficiency">Polykey: Elevating Security and Efficiency<a href="https://polykey.com/blog/introducing-polykey-a-future-security-standard-for-replacing-dotenv-libraries#polykey-elevating-security-and-efficiency" class="hash-link" aria-label="Direct link to Polykey: Elevating Security and Efficiency" title="Direct link to Polykey: Elevating Security and Efficiency" translate="no">​</a></h3>
<p><strong>Polykey</strong> fundamentally transforms how environment variables and secrets are
managed, moving beyond traditional <code>.env</code> file approaches to a more secure and
robust system. Unlike <code>.env</code> methods that often expose sensitive data in
plaintext, Polykey entirely separates secret management from the codebase. This
separation ensures that sensitive information is never stored alongside code or
within project repositories, which dramatically reduces the risk of accidental
exposure.</p>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="advanced-encryption-and-secure-management">Advanced Encryption and Secure Management<a href="https://polykey.com/blog/introducing-polykey-a-future-security-standard-for-replacing-dotenv-libraries#advanced-encryption-and-secure-management" class="hash-link" aria-label="Direct link to Advanced Encryption and Secure Management" title="Direct link to Advanced Encryption and Secure Management" translate="no">​</a></h4>
<p>Polykey leverages the XChaCha20-Poly1305-IETF encryption algorithm, implemented
through the Libsodium library, to secure secrets at rest and in transit. This
modern cryptographic approach offers several benefits:</p>
<ul>
<li class=""><strong>Extended nonce size</strong>: Enhances security by enabling the safe reuse of
encryption keys in various contexts without risking nonce collisions—crucial
for dynamic and distributed applications.</li>
<li class=""><strong>High performance</strong>: Designed for high-speed encryption and decryption
processes, ensuring minimal impact on performance while maintaining robust
security.</li>
<li class=""><strong>Robust confidentiality and authentication</strong>: The algorithm guarantees that
secrets remain confidential and verifiable, which is critical when handling
sensitive operational data.</li>
</ul>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhanced-collaboration-and-sharing">Enhanced Collaboration and Sharing<a href="https://polykey.com/blog/introducing-polykey-a-future-security-standard-for-replacing-dotenv-libraries#enhanced-collaboration-and-sharing" class="hash-link" aria-label="Direct link to Enhanced Collaboration and Sharing" title="Direct link to Enhanced Collaboration and Sharing" translate="no">​</a></h4>
<p>Polykey also facilitates secure end-to-end encrypted sharing of secrets, ideal
for collaborative environments. When developers need to share environment
variables or other configurations:</p>
<ul>
<li class=""><strong>Secure Sharing</strong>: Instead of sharing secrets over insecure channels or
cumbersome setups, developers can share directly through Polykey’s encrypted
vaults.</li>
<li class=""><strong>Seamless Integration and Execution</strong>: Shared vaults can be directly
integrated into another developer's local environment. Once a vault is copied
to their node, they can immediately execute scripts or applications using the
shared environment variables without further setup. This capability not only
simplifies workflows but also ensures that all team members work with secure,
up-to-date configurations without manual updates or risky data handling.</li>
</ul>
<p>By eliminating reliance on <code>.env</code> files and integrating these advanced features,
Polykey significantly enhances the security posture of application deployments.
It addresses common security challenges associated with environment variable
management and sets a new standard for secure, efficient, and collaborative
development practices.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="applicability-across-programming-languages">Applicability Across Programming Languages<a href="https://polykey.com/blog/introducing-polykey-a-future-security-standard-for-replacing-dotenv-libraries#applicability-across-programming-languages" class="hash-link" aria-label="Direct link to Applicability Across Programming Languages" title="Direct link to Applicability Across Programming Languages" translate="no">​</a></h3>
<p>Currently, Polykey's native support extends to JavaScript, TypeScript, and
Node.js environments, which commonly utilize <code>.env</code> files managed by respective
<code>dotenv</code> libraries. For other programming languages, interaction with Polykey is
facilitated through standard IPC, as direct RPC interactions are limited to
JS/TS/Node applications. For more details on library usage, refer to the npm
library <a href="https://npmjs.com/package/@matrixai/rpc" target="_blank" rel="noopener noreferrer" class="">@matrix/rpc</a>.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="demonstration-of-polykeys-capabilities">Demonstration of Polykey's Capabilities<a href="https://polykey.com/blog/introducing-polykey-a-future-security-standard-for-replacing-dotenv-libraries#demonstration-of-polykeys-capabilities" class="hash-link" aria-label="Direct link to Demonstration of Polykey's Capabilities" title="Direct link to Demonstration of Polykey's Capabilities" translate="no">​</a></h3>
<p>I created a GitHub repository to demonstrate the practical implementation and
performance comparisons of replacing the traditional dotenv method with Polykey
for a simple Node.js weather app. This showcases how Polykey can be effectively
implemented in various environments where dotenv libraries are used. I encourage
others to explore these demonstrations and consider similar implementations to
witness the benefits firsthand. Follow the instructions in our
<a href="https://github.com/CryptoTotalWar/pk-env-demo-weather-api" target="_blank" rel="noopener noreferrer" class="">README</a> to perform
the demo yourself, or view our detailed breakdown of the configurations and
performance results of the dotenv-to-Polykey transition
<a href="https://github.com/CryptoTotalWar/pk-env-demo-weather-api" target="_blank" rel="noopener noreferrer" class="">here</a>.</p>
<p><img decoding="async" loading="lazy" alt="Key Differences Between dotenv and Polykey" src="https://polykey.com/assets/images/node-js-pk-env-config-ccf81ae1167003998ecd120efb9f708b.png" width="861" height="888" class="img_ev3q"></p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="future-directions-and-call-to-action">Future Directions and Call to Action<a href="https://polykey.com/blog/introducing-polykey-a-future-security-standard-for-replacing-dotenv-libraries#future-directions-and-call-to-action" class="hash-link" aria-label="Direct link to Future Directions and Call to Action" title="Direct link to Future Directions and Call to Action" translate="no">​</a></h3>
<p>Currently, Polykey is optimized for development environments with plans to
extend its functionality to production settings. This ongoing development
promises to make Polykey a comprehensive solution for all stages of development,
setting a new standard in the industry.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion-join-the-conversation-and-shape-the-future">Conclusion: Join the Conversation and Shape the Future<a href="https://polykey.com/blog/introducing-polykey-a-future-security-standard-for-replacing-dotenv-libraries#conclusion-join-the-conversation-and-shape-the-future" class="hash-link" aria-label="Direct link to Conclusion: Join the Conversation and Shape the Future" title="Direct link to Conclusion: Join the Conversation and Shape the Future" translate="no">​</a></h3>
<p>We invite developers from all backgrounds to join this transformative journey by
testing Polykey in your development environments and sharing your insights with
us in our <a href="https://discord.gg/MfMXFx3qX7" target="_blank" rel="noopener noreferrer" class="">discord server</a>. Your feedback is
invaluable as we refine this tool into an industry standard. Stay informed on
our developments for Polykey by following our
<a href="https://github.com/MatrixAI" target="_blank" rel="noopener noreferrer" class="">open-source GH organization</a>.</p>]]></content>
        <author>
            <name>Pablo Padillo</name>
            <uri>https://github.com/CryptoTotalWar</uri>
        </author>
        <category label="Secrets Management" term="Secrets Management"/>
        <category label="Environment Variables" term="Environment Variables"/>
        <category label="Polykey" term="Polykey"/>
        <category label="Node.js" term="Node.js"/>
        <category label="Typescript" term="Typescript"/>
        <category label="Cybersecurity" term="Cybersecurity"/>
        <category label="DevOps" term="DevOps"/>
        <category label="Data Security" term="Data Security"/>
        <category label="dotenv" term="dotenv"/>
        <category label="JavaScript" term="JavaScript"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Introducing a New Standard in Environment Secrets Management with Polykey]]></title>
        <id>https://polykey.com/blog/introducing-a-new-standard-in-environment-secrets-management-with-polykey</id>
        <link href="https://polykey.com/blog/introducing-a-new-standard-in-environment-secrets-management-with-polykey"/>
        <updated>2024-05-14T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Introduction]]></summary>
        <content type="html"><![CDATA[<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="introduction">Introduction<a href="https://polykey.com/blog/introducing-a-new-standard-in-environment-secrets-management-with-polykey#introduction" class="hash-link" aria-label="Direct link to Introduction" title="Direct link to Introduction" translate="no">​</a></h2>
<p>In the realm of software development, managing environment variables and secrets
has long been both a necessity and a challenge. Traditional practices,
particularly the use of <code>.env</code> files facilitated by the dotenv library, have
been fundamental in helping developers manage configurations without hardcoding
them into their applications. These practices expose systems to security
breaches, unauthorized access, and accidental exposure of sensitive data,
vulnerabilities that can no longer be overlooked in today’s security-conscious
environment.</p>
<p>Polykey is introducing a new open-source solution that enhances security,
simplifies workflows, and integrates seamlessly into diverse development
environments, addressing the urgent need for secure management of environment
variables and secrets.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-history-and-challenges-of-env-files">The History and Challenges of .env Files<a href="https://polykey.com/blog/introducing-a-new-standard-in-environment-secrets-management-with-polykey#the-history-and-challenges-of-env-files" class="hash-link" aria-label="Direct link to The History and Challenges of .env Files" title="Direct link to The History and Challenges of .env Files" translate="no">​</a></h2>
<p>Environment variables are crucial in bridging the gap between operating systems
and applications, managing sensitive data such as API keys and database
passwords. Traditionally managed through <code>.env</code> files, these variables are
vulnerable to several significant risks:</p>
<ul>
<li class=""><strong>Accidental Exposure:</strong> <code>.env</code> files can easily be committed to version
control by mistake, even when listed in <code>.gitignore</code>.</li>
<li class=""><strong>Plaintext Storage Vulnerabilities:</strong> Susceptibility to breaches if
unauthorized access to the developer's machine occurs.</li>
<li class=""><strong>Insecure Sharing Practices:</strong> Growing teams often resort to insecure methods
to share sensitive information.</li>
<li class=""><strong>Management Complexity:</strong> Scaling issues and key rotation complexities create
inefficiencies and potential for errors.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="introducing-polykey">Introducing Polykey<a href="https://polykey.com/blog/introducing-a-new-standard-in-environment-secrets-management-with-polykey#introducing-polykey" class="hash-link" aria-label="Direct link to Introducing Polykey" title="Direct link to Introducing Polykey" translate="no">​</a></h2>
<p>Polykey is revolutionizing secret management by moving beyond traditional <code>.env</code>
files and other less secure cloud-based secret management solutions. As a robust
CLI tool, Polykey introduces:</p>
<ul>
<li class=""><strong>Encrypted Storage:</strong> Polykey securely stores each secret within encrypted
vaults on the user's local machine, enhancing data confidentiality and control
over secret management.</li>
<li class=""><strong>Dynamic Injection:</strong> Through commands like
<code>polykey secrets env -e=&lt;vaultname&gt;:&lt;secretPath&gt;</code>, Polykey injects secrets
directly into the development environment on-demand, offering flexibility and
minimizing risks associated with static secret storage.</li>
<li class=""><strong>Decentralized Secure Sharing:</strong> Utilizing an encrypted, peer-to-peer
network, Polykey enables seamless and secure sharing of secrets. This
mechanism is crucial for collaborative projects requiring stringent security
measures, allowing nodes that manage vaults to discover and trust other users'
nodes across decentralized environments.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="step-by-step-example-using-polykeys-env-command">Step-by-Step Example: Using Polykey’s env Command<a href="https://polykey.com/blog/introducing-a-new-standard-in-environment-secrets-management-with-polykey#step-by-step-example-using-polykeys-env-command" class="hash-link" aria-label="Direct link to Step-by-Step Example: Using Polykey’s env Command" title="Direct link to Step-by-Step Example: Using Polykey’s env Command" translate="no">​</a></h2>
<p>Experience Polykey's secrets env command in action through this GIF demo,
showcasing the secure and dynamic management of environment variables,
transitioning from traditional .env files to a more robust approach.</p>
<p><img decoding="async" loading="lazy" alt="Polykey Secrets env Command" src="https://polykey.com/assets/images/polykey-secrets-env-demo-bdfd0fd501b826958a1b13c4178b2d89.gif" width="691" height="412" class="img_ev3q"></p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="overview-of-the-demonstration">Overview of the Demonstration<a href="https://polykey.com/blog/introducing-a-new-standard-in-environment-secrets-management-with-polykey#overview-of-the-demonstration" class="hash-link" aria-label="Direct link to Overview of the Demonstration" title="Direct link to Overview of the Demonstration" translate="no">​</a></h3>
<p>This demonstration captures the following key actions and highlights their
significance:</p>
<ul>
<li class=""><strong>Transition from <code>.env</code> Files</strong>: We start by navigating to the project
directory, displaying the existing <code>.env</code> file, and then removing it. This
visual representation not only underscores our departure from relying on less
secure <code>.env</code> files but also reinforces Polykey’s capability to replace them
with a more secure alternative.</li>
<li class=""><strong>Secure Storage of Secrets</strong>: By creating a new vault and adding secrets
directly into it, the demo showcases how Polykey encrypts and securely stores
each secret locally on the user’s machine. This action highlights the enhanced
security measures Polykey offers compared to plaintext storage in <code>.env</code>
files.</li>
<li class=""><strong>Dynamic Secret Injection</strong>: Entering into a secure, delegated subshell where
secrets are dynamically injected on-demand exemplifies Polykey’s core
functionality. This step is critical as it demonstrates the operational
efficiency and security with which developers can now handle sensitive
information, ensuring that secrets are only accessible when and where they are
needed, without being exposed.</li>
<li class=""><strong>Verification of Configuration</strong>: The final step of verifying configurations
within the AWS CLI using the dynamically injected secrets illustrates the
effective application of Polykey in a real-world scenario. It not only
validates the correct functioning of the environment setup but also confirms
that the secrets management process adheres to best security practices.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="significance-of-the-demonstration">Significance of the Demonstration<a href="https://polykey.com/blog/introducing-a-new-standard-in-environment-secrets-management-with-polykey#significance-of-the-demonstration" class="hash-link" aria-label="Direct link to Significance of the Demonstration" title="Direct link to Significance of the Demonstration" translate="no">​</a></h3>
<p>This demo serves as a potent illustration of Polykey’s capabilities in
transforming secret management within development environments. It highlights
the ease of transitioning to Polykey, the security benefits of encrypted
storage, and the operational advantages of dynamic secret injection. By visually
and practically demonstrating these features, the demo helps developers
understand the immediate benefits of adopting Polykey, encouraging them to
reevaluate and enhance their current secrets management strategies.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="try-polykey-yourself">Try Polykey Yourself<a href="https://polykey.com/blog/introducing-a-new-standard-in-environment-secrets-management-with-polykey#try-polykey-yourself" class="hash-link" aria-label="Direct link to Try Polykey Yourself" title="Direct link to Try Polykey Yourself" translate="no">​</a></h2>
<p>Following the demonstration, we encourage you to explore Polykey's capabilities
further:</p>
<ol>
<li class=""><strong>Download and Install Polykey</strong>: Follow our
<a href="https://polykey.com/docs/tutorials/polykey-cli/installation" target="_blank" rel="noopener noreferrer" class="">installation guide</a>
to get started.</li>
<li class=""><strong>Watch the Demo</strong>: View our
<a href="https://polykey.com/blog/try-the-polykey-demo-yourself" target="_blank" rel="noopener noreferrer" class="">demo video</a> that
will cover some of the basic commands for using polykey.</li>
<li class=""><strong>Try It Out</strong>: Experiment with the <code>polykey secrets env</code> command in your own
development environment.</li>
</ol>
<p>We are eager to hear your feedback and encourage you to join our
<a href="https://discord.gg/dC32r35TeE" target="_blank" rel="noopener noreferrer" class="">Discord server</a> to participate in discussions or
contribute to Polykey’s ongoing open-source development at
<a href="https://github.com/MatrixAI" target="_blank" rel="noopener noreferrer" class="">Matrix.AI</a>.</p>]]></content>
        <author>
            <name>Pablo Padillo</name>
            <uri>https://github.com/CryptoTotalWar</uri>
        </author>
        <category label="Secrets Management" term="Secrets Management"/>
        <category label="Environment Variables" term="Environment Variables"/>
        <category label="Polykey" term="Polykey"/>
        <category label="DevOps" term="DevOps"/>
        <category label="Cybersecurity" term="Cybersecurity"/>
        <category label="Software Development" term="Software Development"/>
        <category label="Tech Innovation" term="Tech Innovation"/>
        <category label="Data Security" term="Data Security"/>
        <category label="Cloud Computing" term="Cloud Computing"/>
        <category label="Configuration Management" term="Configuration Management"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Polykey Updates Since Beta CLI Release]]></title>
        <id>https://polykey.com/blog/polykey-updates-since-beta-cli-release</id>
        <link href="https://polykey.com/blog/polykey-updates-since-beta-cli-release"/>
        <updated>2024-04-29T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Hello Polykey Community!]]></summary>
        <content type="html"><![CDATA[<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="hello-polykey-community">Hello Polykey Community!<a href="https://polykey.com/blog/polykey-updates-since-beta-cli-release#hello-polykey-community" class="hash-link" aria-label="Direct link to Hello Polykey Community!" title="Direct link to Hello Polykey Community!" translate="no">​</a></h2>
<p>It’s been some time since our last major update—the beta launch back in
November. Our Sydney-based engineers have been hard at work enhancing the
Polykey CLI and adding powerful new features. Matrix AI has undergone a few
exciting changes that will significantly impact the company's growth and the
development of Polykey.</p>
<p><strong>Here’s what’s new:</strong></p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="latest-enhancements">Latest Enhancements<a href="https://polykey.com/blog/polykey-updates-since-beta-cli-release#latest-enhancements" class="hash-link" aria-label="Direct link to Latest Enhancements" title="Direct link to Latest Enhancements" translate="no">​</a></h3>
<ul>
<li class="">
<p><strong>Cross-Platform Installation</strong>: In addition to Linux, Polykey CLI is now
available on Mac and Windows. For detailed installation instructions based on
your operating system, check out our updated
<a href="https://polykey.com/docs/tutorials/polykey-cli/installation" target="_blank" rel="noopener noreferrer" class="">installation guide</a>
in the Polykey Docs.
(<a href="https://github.com/MatrixAI/Polykey-CLI/issues/152" target="_blank" rel="noopener noreferrer" class="">Polykey-CLI#152</a>)</p>
</li>
<li class="">
<p><strong>CLI Standard Output Improvements</strong>: We've standardized CLI outputs across
all interactions to ensure a consistent user experience.
(<a href="https://github.com/MatrixAI/Polykey-CLI/issues/22" target="_blank" rel="noopener noreferrer" class="">Polykey-CLI#22</a>)</p>
</li>
<li class="">
<p><strong>Advanced Monitoring with Audit Domain</strong>: We're advancing our monitoring
capabilities to offer improved visibility and control.
(<a href="https://github.com/MatrixAI/Polykey-CLI/issues/177" target="_blank" rel="noopener noreferrer" class="">Polykey-CLI#177</a>)</p>
</li>
<li class="">
<p><strong>Optimized Node Discovery</strong>: Enhanced feedback mechanisms in node discovery
improve network operations and independence.
(<a href="https://github.com/MatrixAI/Polykey/issues/162" target="_blank" rel="noopener noreferrer" class="">Polykey#162</a>)<img decoding="async" loading="lazy" alt="Discovery Feedback" src="https://polykey.com/assets/images/discovery-feedback-83fe439a773c65eb165f4dc5b48fe0ef.gif" width="964" height="522" class="img_ev3q"></p>
</li>
<li class="">
<p><strong>Secure Environment Handling</strong>: The <code>$ polykey secrets env</code> command securely
injects environment variables from your encrypted vault directly into your
system's local environment. This feature sets a new standard for secure data
management both at rest and in use. Excited to share more about this feature's
use-cases soon.
(<a href="https://github.com/MatrixAI/Polykey-CLI/issues/31" target="_blank" rel="noopener noreferrer" class="">Polykey-CLI#31</a>)</p>
</li>
<li class="">
<p><strong>Fault-Tolerant Notifications</strong>: Experience asynchronous notifications,
enhancing system responsiveness and fault tolerance.
(<a href="https://github.com/MatrixAI/Polykey/issues/703" target="_blank" rel="noopener noreferrer" class="">Polykey#703</a>)
<img decoding="async" loading="lazy" alt="Asynchronous Notifications" src="https://polykey.com/assets/images/async-notifications-97b4e80afccb9d9035f8b834a36e35d7.gif" width="964" height="522" class="img_ev3q"></p>
</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="critical-bug-fixes">Critical Bug Fixes<a href="https://polykey.com/blog/polykey-updates-since-beta-cli-release#critical-bug-fixes" class="hash-link" aria-label="Direct link to Critical Bug Fixes" title="Direct link to Critical Bug Fixes" translate="no">​</a></h3>
<ul>
<li class=""><strong>Connection Stability</strong>: We've fortified network stability to prevent
unexpected node crashes.
(<a href="https://github.com/MatrixAI/Polykey/issues/592" target="_blank" rel="noopener noreferrer" class="">Polykey#592</a>)</li>
<li class=""><strong>Authentication Enhancements</strong>: Increased the Authentication Timeout window,
improving user experience during the authentication process when running
<code>$ polykey identities authenticate github.com</code>.
(<a href="https://github.com/MatrixAI/Polykey/issues/588" target="_blank" rel="noopener noreferrer" class="">Polykey#588</a>)</li>
<li class=""><strong>Resource Leak Fix</strong>: Fixed issue with timers not properly cleaning up,
preventing potential crashes.
(<a href="https://github.com/MatrixAI/js-timer/issues/15" target="_blank" rel="noopener noreferrer" class="">js-timer#15</a>)</li>
<li class=""><strong>Node Discovery Overhaul</strong>: Decentralized node discovery now improves overall
network connectivity.
(<a href="https://github.com/MatrixAI/Polykey/pull/618" target="_blank" rel="noopener noreferrer" class="">Polykey#618</a>)</li>
<li class=""><strong>NAT Hole Punching Fix</strong>: Addressed challenges with NAT hole punching to
ensure consistent node communications.
(<a href="https://github.com/MatrixAI/Polykey/issues/605" target="_blank" rel="noopener noreferrer" class="">Polykey#605</a>)</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="recent-events--organization-updates">Recent Events &amp; Organization Updates<a href="https://polykey.com/blog/polykey-updates-since-beta-cli-release#recent-events--organization-updates" class="hash-link" aria-label="Direct link to Recent Events &amp; Organization Updates" title="Direct link to Recent Events &amp; Organization Updates" translate="no">​</a></h2>
<ul>
<li class=""><strong>Key Hires and Team Expansion</strong>: Recent months have seen exciting additions
to our team, enhancing both our technical and marketing capacity. New roles
include front-end engineers, back-end engineers, AI/ML specialists, and a
marketing lead technical support specialist.</li>
<li class=""><strong>Polykey Enterprise Development</strong>: We are actively enhancing Polykey
Enterprise (PKE) to provide a hybrid mandatory discretionary policy network,
allowing admins to enforce security policies robustly. We applied to
YCombinator Summer 2024 to accelerate this development. We have some GUI
prototypes in the works for the PKE which we're eager to share with you soon.</li>
<li class=""><strong>Venture Miami Phase II</strong>: We're making waves in Phase II of Miami's largest
incubator program, gearing up for a demo day on June 20th that promises to
showcase our advancements to potential angel investors.</li>
<li class=""><strong>Engagement at Major Events</strong>: Our participation at Eth Denver and SXSW in
Austin has significantly expanded our network and fostered key collaborations.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="engage-and-explore">Engage and Explore<a href="https://polykey.com/blog/polykey-updates-since-beta-cli-release#engage-and-explore" class="hash-link" aria-label="Direct link to Engage and Explore" title="Direct link to Engage and Explore" translate="no">​</a></h3>
<p>We’re eager to hear your feedback as we continue to refine Polykey. Engage with
us through feature requests or issues on our
<a href="https://github.com/MatrixAI" target="_blank" rel="noopener noreferrer" class="">GitHub</a> or in our
<a href="https://discord.gg/dC32r35TeE" target="_blank" rel="noopener noreferrer" class="">Discord server</a>.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="stay-tuned">Stay Tuned<a href="https://polykey.com/blog/polykey-updates-since-beta-cli-release#stay-tuned" class="hash-link" aria-label="Direct link to Stay Tuned" title="Direct link to Stay Tuned" translate="no">​</a></h3>
<p>Explore the vast possibilities with Polykey. Download the latest updates, try
out new features, and share how they've impacted your workflow.</p>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="escape-the-ordinary-secure-the-extraordinary">Escape the Ordinary, Secure the Extraordinary<a href="https://polykey.com/blog/polykey-updates-since-beta-cli-release#escape-the-ordinary-secure-the-extraordinary" class="hash-link" aria-label="Direct link to Escape the Ordinary, Secure the Extraordinary" title="Direct link to Escape the Ordinary, Secure the Extraordinary" translate="no">​</a></h4>
<p>The Polykey Team</p>]]></content>
        <author>
            <name>Pablo Padillo</name>
            <uri>https://github.com/CryptoTotalWar</uri>
        </author>
        <category label="polykey" term="polykey"/>
        <category label="CLI" term="CLI"/>
        <category label="updates" term="updates"/>
        <category label="beta release" term="beta release"/>
        <category label="engineering" term="engineering"/>
        <category label="open source" term="open source"/>
        <category label="network management" term="network management"/>
        <category label="YCombinator" term="YCombinator"/>
        <category label="decentralization" term="decentralization"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Try the Polykey Demo Yourself!]]></title>
        <id>https://polykey.com/blog/try-the-polykey-demo-yourself</id>
        <link href="https://polykey.com/blog/try-the-polykey-demo-yourself"/>
        <updated>2024-04-10T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Polykey Now Available for Mac & Windows]]></summary>
        <content type="html"><![CDATA[<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="polykey-now-available-for-mac--windows">Polykey Now Available for Mac &amp; Windows<a href="https://polykey.com/blog/try-the-polykey-demo-yourself#polykey-now-available-for-mac--windows" class="hash-link" aria-label="Direct link to Polykey Now Available for Mac &amp; Windows" title="Direct link to Polykey Now Available for Mac &amp; Windows" translate="no">​</a></h3>
<p>Since its initial launch in December 2023 for Linux, we've expanded Polykey's
availability.</p>
<p>As of March 2024, you can now use Polykey on both Mac OS and Windows!</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="best-way-to-get-started">Best Way to Get Started:<a href="https://polykey.com/blog/try-the-polykey-demo-yourself#best-way-to-get-started" class="hash-link" aria-label="Direct link to Best Way to Get Started:" title="Direct link to Best Way to Get Started:" translate="no">​</a></h3>
<p>Download Polykey by following the installation guides tailored to your operating
system, available here:
<a href="https://polykey.com/docs/tutorials/polykey-cli/installation" target="_blank" rel="noopener noreferrer" class="">https://polykey.com/docs/tutorials/polykey-cli/installation</a></p>
<p><strong>Explore Through Our Demo Video</strong></p>
<p>Watch our demo video to see Polykey in action. The video covers basic yet
crucial functionalities:</p>
<ul>
<li class="">Starting Polykey</li>
<li class="">Creating and managing Vaults</li>
<li class="">Adding and viewing Secrets within Vaults</li>
<li class="">Authentication and identity features with GitHub</li>
<li class="">Discovering and trusting other Polykey users</li>
<li class="">Sharing Vaults securely</li>
</ul>
<iframe src="https://player.vimeo.com/video/884649667" frameborder="0" allow="autoplay; fullscreen; picture-in-picture; clipboard-write; encrypted-media" referrerpolicy="strict-origin-when-cross-origin" width="640px" height="360px"></iframe>
<p><strong>Special Note on the Demo:</strong> This video showcases interactions that require two
separate users to demonstrate the feature of sharing vaults. While this is a key
aspect of Polykey’s collaborative capabilities, remember that Polykey also
offers robust solutions for individual users, such as securely managing .env
files. We will explore this in more detail in an upcoming post.</p>
<p><strong>We Want Your Feedback</strong></p>
<p>Connect with us on our Matrix AI Discord Server to share your feedback and
discuss how you use Polykey in your own setups.</p>]]></content>
        <author>
            <name>Pablo Padillo</name>
            <uri>https://github.com/CryptoTotalWar</uri>
        </author>
        <category label="polykey" term="polykey"/>
        <category label="demo" term="demo"/>
        <category label="docs" term="docs"/>
        <category label="mac" term="mac"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Polykey's Grand Launch Event]]></title>
        <id>https://polykey.com/blog/polykey-launch-party</id>
        <link href="https://polykey.com/blog/polykey-launch-party"/>
        <updated>2023-12-18T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[image1]]></summary>
        <content type="html"><![CDATA[<p><img decoding="async" loading="lazy" alt="image1" src="https://polykey.com/assets/images/sydney-launch-polykey-photo-d354cd1380f5efe64ac0194864df3778.jpg" width="1024" height="576" class="img_ev3q"></p>
<p>On December 8, 2023, at our Sydney headquarters, Polykey was launched. The event
marked a major milestone for Matrix AI after three years of intense innovation
and engineering.</p>
<p>The event began with a presentation by Roger, Polykey's founder. He introduced
Polykey's philosophy and core features, including encrypted vault storage and
Gestalt-based sharing. Roger also discussed digital identities in Polykey's
secret sharing infrastructure.</p>
<p>Next, Polykey Enterprise was previewed. It's the peak of Polykey's offerings,
turning the open-source framework into a robust enterprise solution for managing
and delegating sensitive information within organizations.</p>
<p>The event also unveiled Polykey.com and Polykey dashboards. These platforms
offer real-time insights into active nodes, improving user experience and
control.</p>
<hr>
<p>As the presentation concluded, guests were invited to a meticulously arranged
refreshment break.</p>
<p>This interlude provided a perfect opportunity for the diverse assembly of tech
enthusiasts, industry leaders, and innovators to network and share insights.</p>
<p><img decoding="async" loading="lazy" src="https://media.discordapp.net/attachments/1137566878663983156/1182828273047191672/IMG_1040.jpg?ex=658f582c&amp;is=657ce32c&amp;hm=99855afcda74699e0b6f01e33e4f1dab4017df596f880f731385e8b7e38cf30a&amp;=&amp;format=webp&amp;width=944&amp;height=1258" alt="image2" class="img_ev3q"></p>
<p>After the presentations, guests enjoyed a refreshment break. It was a time for
networking and sharing insights among tech enthusiasts and industry leaders.</p>
<p>The event continued with a presentation by Amy Yan. Amy discussed her role in
developing js-rpc, Matrix AI's RPC library. She highlighted js-rpc's advanced
streaming methods, including raw, server, client, duplex streaming, and unary
data transmission.</p>
<hr>
<p><img decoding="async" loading="lazy" alt="gif" src="https://polykey.com/assets/images/cli-demo-942a348deb9a9b6602f3a7d7112feb92.gif" width="960" height="540" class="img_ev3q"></p>
<p>The final segment featured a live demonstration by Brian Botha. He showcased the
Polykey CLI client's features like vault creation, secret sharing, and a
git-based log system for tracking changes to secrets. He also demonstrated how
new Polykey agents are integrated into the network.</p>
<p>For those who could not attend or wished to revisit the demonstration, the
Polykey team provided a link to the Polykey launch video, capturing the essence
of the demonstration:</p>
<p>Polykey Launch Video:</p>
<iframe src="https://player.vimeo.com/video/884649667?h=d3937114a1" width="640" height="360" frameborder="0" allow="autoplay; fullscreen; picture-in-picture"></iframe>
<hr>
<p>This concluding segment of the Polykey Launch Event perfectly encapsulated the
blend of technical excellence and user-centric design that Polykey embodies. It
provided a tangible showcase of Polykey's capabilities, leaving the attendees
with a profound appreciation of the innovation and expertise driving the Polykey
project forward.</p>]]></content>
        <author>
            <name>Aditya Varma</name>
            <uri>https://github.com/addievo</uri>
        </author>
        <category label="polykey" term="polykey"/>
        <category label="launch" term="launch"/>
        <category label="party" term="party"/>
        <category label="celebration" term="celebration"/>
        <category label="launch event" term="launch event"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Secret Sharing by Authority Delegation With Zero-Trust Workflows]]></title>
        <id>https://polykey.com/blog/secret-sharing-by-authority-delegation-with-zero-trust-workflows</id>
        <link href="https://polykey.com/blog/secret-sharing-by-authority-delegation-with-zero-trust-workflows"/>
        <updated>2019-05-28T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[The complexity of modern technology-driven organisations involve hybrid-cloud]]></summary>
        <content type="html"><![CDATA[<p>The complexity of modern technology-driven organisations involve hybrid-cloud
microservices, continuous integration &amp; deployment, and a development
environment that involves a globally connected remote workforce. Numerous
security incidents have occurred that indicate that our existing tools for
secrets management have not scaled in this new modern environment.</p>
<p><img decoding="async" loading="lazy" alt="image" src="https://polykey.com/assets/images/section3-desktop-7edc5997a4835c8f81cabc58d723dc34.png" width="1230" height="712" class="img_ev3q"></p>
<p>Polykey is a decentralised open-source secrets management system. It facilitates
zero-trust workflows that require the sharing of secrets between individuals,
teams and machines in order to coordinate the secure utilisation of digital and
physical assets. It manages passwords, public &amp; private keys, API keys,
structured &amp; smart tokens, certificates and any kind of confidential
information.</p>
<p>Existing password management systems which focus on storing and retrieving
passwords treat secret sharing as merely identity credential sharing. Secret
sharing is actually about the delegation of authority, and when possible, the
subdivision of authority for fine-grained least-privilege delegation. A secret
tokenises the capability to manipulate a specific resource. Polykey provides
interfaces and automation for structured secrets management designed for
developer, security and operations (DevSecOps) oriented workflows.</p>
<p>Polykey is decentralised. This means Polykey nodes are deployed ubiquitously
across platforms and devices (on and off-premise), eliminating third-party
storage, providing end-to-end zero-trust delivery, and last-mile ingress and
egress integration.</p>
<p>Polykey ensures that your secrets stay secret. To learn more about Polykey:</p>
<ul>
<li class="">Download the
<a href="https://github.com/MatrixAI/Polykey/releases/latest" target="_blank" rel="noopener noreferrer" class="">latest pre-release</a></li>
<li class="">Join our community on <a href="https://github.com/MatrixAI/Polykey" target="_blank" rel="noopener noreferrer" class="">GitHub</a></li>
<li class="">Follow us on Twitter at <a href="https://twitter.com/PolykeyIO" target="_blank" rel="noopener noreferrer" class="">@PolykeyIO</a></li>
<li class="">Learn more by reading the <a href="https://polykey.com/docs" target="_blank" rel="noopener noreferrer" class="">Polykey Documentation</a></li>
<li class="">Get ready for Polykey's <a href="https://polykey.com/downloads" target="_blank" rel="noopener noreferrer" class="">launch release</a></li>
</ul>]]></content>
        <author>
            <name>Roger Qiu</name>
            <uri>https://github.com/CMCDragonkai</uri>
        </author>
        <category label="secret management" term="secret management"/>
        <category label="secret sharing" term="secret sharing"/>
        <category label="zero-trust" term="zero-trust"/>
        <category label="capability-based security" term="capability-based security"/>
    </entry>
</feed>