Supersede vs verifiable erasure - how do they coexist in an append-only log? #34
Unanswered
source-origin
asked this question in
Q&A
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Read the semantics — correct a fact once and the old value stays retired; erase a person and prove it; show an auditor what the agent knew when it acted.
The seam I'd like your read on: supersede keeps the old value retired, while verifiable erasure removes it — and those pull in opposite directions for an append-only log. One says never lose history; the other says make a value provably unrecoverable, with a witness.
How do you reconcile them in one structure? Specifically, when a value is erased: does the prior chain / witness still let anyone prove that something was there (without revealing it), or does erasure leave a gap a third party can only take on the operator's word?
A related one: a "witness" is only worth as much as its independence — who is the witness here (a second process, a second operator, a transparency log?), and what stops the operator from being their own witness?
(Adjacent context: our ledger is append-only with supersede-not-rewrite, and erasure vs. permanent record is the seam we have not closed.)
All reactions