Damus
Râu Cao ⚡ · 2d
The others don't have to agree on the time if they still trust the master key anyway.
inkan profile picture
To trust a self-declared disavowal, you have to trust the *person* behind the master key.

When somebody retroactively disavows past events that were ostensibly signed on their behalf, then a question arises as to whether that disavowal is honest or not.

This question cannot be decided mechanically or by an algorithm. You have to look at the circumstances of the particular case, and you can only do so to the extent you have access to relevant information.

And an important piece of such information is the *time* at which the person made the disavowal, whether it was made retroactively or not, and, if so, which events fall within that retroactive window.

In many cases, you will simply believe the person who made the disavowal and not attribute the disavowed events to them. You can simply set the inkan client to not show these events, or if you operate a relay you may decide to delete them.
3
mleku · 2d
No, it's cryptographically identifiable. The key is already public. The revocation is published with the master signature. PGP has been doing this formyears. Look into pgp keyservers
inkan · 2d
Also: If others know and agree on the objective time of the revocation, they can *at least* agree that events that are dated subsequent to that revocation time should not be attributed to the revoker. They can do so regardless of whether or not they agree on how to handle events that are dated betw...
mleku · 2d
Ou trust the signature. A person cannot be proven on a network except via the proxy of cryptographic proof of control of a secret.