BetterSign™.

BetterSign™

We solved passwords.

Provenance-based identity replaces shared secrets.

No passwords to forget, phish, reset, or leak. Your identity is a permanent name made of math — not a secret you have to guard.

Authentication is a detached signature over a fresh challenge, verified against your provenance log. There is no password database and no bearer credential to exfiltrate.

  • There's no secret for anyone to steal
  • Nothing to reset and nothing to forget
  • The same you, trusted everywhere you go
  • Challenge-response signed by your current key
  • Verifier resolves your VLAD to the plog head via the DHT
  • Key compromise is contained by rotation, not account takeover

A stable name on the outside, freely changeable keys on the inside.

The picture

A wax seal only you can stamp

Picture a signet ring — your private key — that stamps a mark no one else can reproduce. Everyone has a picture of your stamp — your public key — so they recognize your mark, yet still can't make it themselves. Change one word of the letter and the stamp no longer matches.

Signing produces a detached signature over the entry bytes; verification checks it against the advertised public key. Any change to the signed content invalidates the proof — tampering is self-evident.

What it fixes

Shared secrets vs. keys

Passwords, PINs, passphrases

  • ✕You have to hand the secret over to use it
  • ✕The same secret often gets reused in many places
  • ✕Can be guessed, phished, or stolen in a breach
  • ✕Only as safe as the weakest site that stored it
  • ✕A leaked one is instantly useful to a thief

Keys

  • ✓The secret never leaves your device
  • ✓A different key for every identity and purpose
  • ✓Nothing to phish, because you never send the secret
  • ✓You prove yourself without revealing anything
  • ✓Rotating to a fresh key retires the old risk

How it works

How a VLAD works

You create an identity, which gives you a VLAD — your permanent name

BetterSign starts a signed logbook for it

Every key change adds a new signed page to the logbook

Anyone can replay the logbook and check every page is legitimate

They always end up with your current, correct keys — without asking anyone

The building blocks

Four ideas do all the work

◇

Stable identity

A VLAD remains stable while its keys and protected metadata rotate.

⛓

Self-verifying history

Every state transition is hash-linked and authorized by the previous log state.

⇋

Decentralized discovery

VLADemlia helps peers locate current records without becoming the trust root.

↻

Routine rotation

Key changes become signed updates that followers can verify and apply.

The jargon, translated

Plain-English words for the deep stuff

VLAD
your permanent name; short for Verifiable Long-lived Address
plog
the signed logbook behind a VLAD that records every change
rotation
swapping an old key for a fresh one without changing your identity
revocation
marking a key as no longer usable, for example after it leaks
recovery
using a stronger backup key to fix things if a normal key is lost
VLADemlia
the network address book that helps peers find each other; it never decides who to trust

Questions

The things people ask first

Do I need to understand the cryptography?

No. Point your tools at a VLAD and BetterSign keeps the keys current for you — SSH that doesn't break when keys rotate, TLS that renews itself, API tokens you can rotate freely.

What if I lose my key?

Recovery is built in. A stronger, better-protected backup key can fix things if a normal key is lost or stolen — no out-of-band scramble.

Why is changing keys a good thing?

The longer a single key stays in use, the more chances a copy ends up somewhere it shouldn't. Rotating retires old risk — like changing the locks now and then.

Can a company take my identity away?

No. A VLAD is owned by you and no one else, proven by math anyone can check, and still verifiable years later — even offline.

A name you keep. Keys you can change.

Point your tools at a VLAD and BetterSign keeps the keys current for you.