BetterSign™.
01

We solved passwords.

Provenance-based identity replaces shared secrets.

No passwords to forget, phish, reset, or leak. Your identity is a permanent name made of math — not a secret you have to guard.

Authentication is a detached signature over a fresh challenge, verified against your provenance log. There is no password database and no bearer credential to exfiltrate.

02

One name. Forever.

A VLAD is a stable identifier decoupled from key material.

Your identity stays the same for life while the keys securing it rotate freely — like keeping your phone number when you swap the SIM.

A Verifiable Long-lived ADdress binds a nonce to the CID of a WASM verification function. It commits to a verifier, not a key, so it survives unlimited rotations.

03

Never reset a password again.

No shared secret means no secret-reset flow.

There's no password to lose — so there's no reset link, no lockout, and no "forgot it" loop.

Recovery is an authorized provenance-log entry, not a password-reset email. Control is re-established cryptographically, not by proving access to an inbox.

04

Phishing has nothing to steal.

No bearer credential, no phishable surface.

Nobody can trick you into handing over a secret, because the thing that proves you're you isn't a secret at all.

The private key stays on-device and is never transmitted; only single-use detached signatures over fresh challenges cross the wire. Nothing on the network is replayable.

05

Lose the key. Keep the name.

Key loss is a rotation event, not an identity loss.

Compromised or lost a key? Rotate it — or use a stronger backup key to recover — without becoming a stranger to everyone you know.

Advertised keys live under /pubkey in the log's virtual key-value store. Rotate by appending an entry; recover via a Lamport threshold group set in the highest-precedence lock script.

06

Rotate your keys. Don't break the internet.

Key rotation without invalidating external references.

Good security means changing keys often. Today that breaks every system that trusted the old one. Here, a key change is just a signed, self-verifying update.

Because links point at the VLAD, not at a public key, rotation never breaks references. Each new entry satisfies the prior entry's lock script and the DHT forward pointer advances automatically.

07

The last account you'll ever make.

A single self-sovereign identity, provider-independent.

Create your identity once. It works everywhere, outlives any company, and never needs a new signup.

Your identity is a provenance log in content-addressable storage, discoverable by VLAD. No service owns it, and any relying party can verify it without an account on their side.

08

No passwords. No logins. No middleman.

Decentralized PKI with no trusted third party.

No central authority, no "sign in with Big Tech," no key server to trust or get hacked. Just you, provable directly.

No certificate authority, key server, or bootstrap node holds leverage. Discovery uses a Kademlia-style DHT (VLADemlia); trust derives from the provenance log itself.

09

Certificates expire. You don't.

Long-lived identifiers eliminate expiry-driven outages.

No more 2 a.m. outages because a cert lapsed or a secret went stale. Your identity is long-lived by design.

A VLAD has no expiration; it stays valid as long as it is unchanged. There are no certificates to renew and no rotation deadlines that break trust.

10

Prove it's really you — forever.

A cryptographically verifiable history of control.

Every change to your identity is cryptographically signed and linked, so your whole history is verifiable by anyone, any time — even offline.

Provenance logs are hash-linked entries, each authorized by the previous entry's lock script. The chain binds the VLAD at both the genesis and head entries for closed-loop verification.

11

Finally, a Web of Trust that holds together.

Restorable links make the trust network metastable.

The old web of trust never happened because keys break the links between people. BetterSign uses stable names that heal themselves, so trust accumulates instead of shattering.

Pubkey links are binary valid/invalid and never restorable. VLAD links map back to the current head, so a stale pubkey resolves to its successor — the property that lets THE network accrete.

12

Your keys. Your rules. Your recovery.

Programmable authorization via WACC lock scripts.

Set up a stronger backup key to recover if a key is lost — no company, no support ticket, no permission needed.

Each entry carries WASM lock scripts defining what the next entry must satisfy. Encode threshold signatures, delegation, and revocation policy directly in the log.