Global Feed Post Login
Replying to Avatar GHOST

You’re right that implicit rotation can work in a perfect discipline model and does minimize client work.

The reason I still require explicit root authorization is survivability under failure. I want a cryptographic way to distinguish intent from accident or compromise, and a way to revoke or supersede a key after the fact.

Implicit “highest index wins” infers authority. Cold Root Identity makes authority explicit. That’s the tradeoff I’m choosing.

Avatar
asherp 1w ago

Sounds good. I think it's a fair tradeoff.

Reply to this note

Please Login to reply.

Discussion

No replies yet.