Trusted URLs via Cryptographic Signatures

(blog.certisfy.com)

13 points | by Edmond 2 hours ago

6 comments

  • tgma 43 minutes ago
    Google AMP had the concept of Signed Exchanges so that you can host content on a third party server while proving its integrity https://developer.chrome.com/blog/signed-exchanges

    Unfortunately, AMP itself was controversial and the system was not really adopted elsewhere, but it is something.

  • Edmond 2 hours ago
    SDK: https://github.com/CipherTrustee/certisfy-js

    Web of trust use case example: https://bsky.app/profile/bitlooter.bsky.social

    Experimenting with Keybase key holders as CAs:

    https://www.reddit.com/r/Keybase/comments/1q5ys71/using_keyb...

    Cryptographic Implementation of Exclusivity Agreements: https://github.com/CipherTrustee/certisfy-claim-recipes/tree...

    Build Your Own Trust Chain: https://blog.certisfy.com/2026/04/build-your-own-trust-chain...

    Some other examples of how you could leverage it: https://blog.certisfy.com/

    Happy to answer questions.

    • __MatrixMan__ 12 minutes ago
      This is cool. I'm glad to see others working in this space (you're further along than I am, nice work!)

      If I've understood it, certisfy makes it possible to do something like this:

          I-was-there-and-saw-this-happen(https://site.com/some-page-with-an-image)
      
      So maybe I follow the link and I see an image and since I trust you, I have reason to believe that the events depicted in the image are not AI generated.

      I'm building something similar. I've been avoiding URLs though because the above arrangement depends on site.com reliably serving the same image to all users. If you end up with a different image when you browse there, and you can falsify the claim, you don't know if I'm a liar, or if the underlying site changed.

      So my plan is to gossip fuzzy hashes around and use patterns in the data (rabin fingerpints, perceptual hashes, etc) to then go look up whether there are any claims about that data, attaching them after the DOM has rendered. Or maybe there's no DOM, maybe you're looking at a physical page of a book or something.

      Do you have any thoughts maybe supporting claims about a site's content rather than about its URL? I'm imagining something like:

          contains-an-image-with-hash(https://site.com/some-page-with-an-image, 0xabc123456def)
          I-was-there-and-saw-this-happen(0xabc123456def)
      
      That way it decomposes into separate claims which we can then verify or falsify separately, and I don't have to look like a liar when actually the site is the unreliable one. Also, if the site takes the image down, I might be able to use the hash in the claim to find whatever the claims refer to independently of where it's hosted.
    • AtHeartEngineer 2 hours ago
      Just emailed you, I'm working on something similar https://github.com/MinistryofMany

      it's basically an OIDC provider as an identity wallet using verifiable credentials, but I've got a "share link" system built in where you can share specific credentials/proofs with others.

    • pluto_modadic 2 hours ago
      what was the hardest part about this project?
      • Edmond 2 hours ago
        Everything :)

        But I wouldn't characterize it in terms of being hard.

        It's been a work in progress for many years,... so more of a problem solving and exploratory endeavor.

    • canadiantim 1 hour ago
      How do you foresee this being implemented or made popularly available?
  • skinfaxi 9 minutes ago
    What does this add over message signing?
  • Retr0id 1 hour ago
    What happens if the destination/contents of the URL changes after I sign it?
  • mahemm 1 hour ago
    How does this differ from e.g. S3 pre-signed URLs?
  • westurner 1 hour ago
    How to implement signed URLs with W3C DID keys and W3C Verifiable Credentials?