BetterSign™.

BetterSign™

Never reset a password again.

No shared secret means no secret-reset flow.

There's no password to lose — so there's no reset link, no lockout, and no "forgot it" loop.

Recovery is an authorized provenance-log entry, not a password-reset email. Control is re-established cryptographically, not by proving access to an inbox.

  • No reset emails, no waiting around
  • You can't get locked out
  • A trusted backup gets you back in
  • Recovery = a signed, lock-script-authorized log entry
  • Optional Lamport threshold group for social recovery
  • No email/SMS reset vector left to phish

A stable name on the outside, freely changeable keys on the inside.

The picture

Like changing a smoke-detector battery

Even the best key doesn't stay perfect forever. Rotating to a fresh key on a regular basis means that even if an old one leaks, it's already retired and worthless. Rotation stops being an emergency and becomes healthy routine.

Each rotation appends an entry that updates /pubkey; the prior key is revoked by that update (or an explicit delete op). The blast radius of a leaked key is bounded to the window before the next rotation.

What it fixes

Shared secrets vs. keys

Passwords, PINs, passphrases

  • ✕You have to hand the secret over to use it
  • ✕The same secret often gets reused in many places
  • ✕Can be guessed, phished, or stolen in a breach
  • ✕Only as safe as the weakest site that stored it
  • ✕A leaked one is instantly useful to a thief

Keys

  • ✓The secret never leaves your device
  • ✓A different key for every identity and purpose
  • ✓Nothing to phish, because you never send the secret
  • ✓You prove yourself without revealing anything
  • ✓Rotating to a fresh key retires the old risk

How it works

What happens when you rotate a key

You create a fresh key on your own device

You add it as a new signed page in your logbook

The old key is marked retired, so it can no longer be used

Followers verify the change themselves and switch over automatically

Your VLAD — your identity — never changes through any of it

The building blocks

Four ideas do all the work

◇

Stable identity

A VLAD remains stable while its keys and protected metadata rotate.

⛓

Self-verifying history

Every state transition is hash-linked and authorized by the previous log state.

⇋

Decentralized discovery

VLADemlia helps peers locate current records without becoming the trust root.

↻

Routine rotation

Key changes become signed updates that followers can verify and apply.

The jargon, translated

Plain-English words for the deep stuff

VLAD
your permanent name; short for Verifiable Long-lived Address
plog
the signed logbook behind a VLAD that records every change
rotation
swapping an old key for a fresh one without changing your identity
revocation
marking a key as no longer usable, for example after it leaks
recovery
using a stronger backup key to fix things if a normal key is lost
VLADemlia
the network address book that helps peers find each other; it never decides who to trust

Questions

The things people ask first

Do I need to understand the cryptography?

No. Point your tools at a VLAD and BetterSign keeps the keys current for you — SSH that doesn't break when keys rotate, TLS that renews itself, API tokens you can rotate freely.

What if I lose my key?

Recovery is built in. A stronger, better-protected backup key can fix things if a normal key is lost or stolen — no out-of-band scramble.

Why is changing keys a good thing?

The longer a single key stays in use, the more chances a copy ends up somewhere it shouldn't. Rotating retires old risk — like changing the locks now and then.

Can a company take my identity away?

No. A VLAD is owned by you and no one else, proven by math anyone can check, and still verifiable years later — even offline.

A name you keep. Keys you can change.

Point your tools at a VLAD and BetterSign keeps the keys current for you.