BetterSign™.

BetterSign™

Phishing has nothing to steal.

No bearer credential, no phishable surface.

Nobody can trick you into handing over a secret, because the thing that proves you're you isn't a secret at all.

The private key stays on-device and is never transmitted; only single-use detached signatures over fresh challenges cross the wire. Nothing on the network is replayable.

  • Your secret key never leaves your phone
  • A fake login page has nothing to grab
  • No codes to type, no links to click
  • Private key held on-device (phone / HSM / keyring)
  • Signed challenges are single-use and non-replayable
  • Verifier checks the signature against the plog, not a secret

A stable name on the outside, freely changeable keys on the inside.

The picture

A wax seal only you can stamp

Picture a signet ring — your private key — that stamps a mark no one else can reproduce. Everyone has a picture of your stamp — your public key — so they recognize your mark, yet still can't make it themselves. Change one word of the letter and the stamp no longer matches.

Signing produces a detached signature over the entry bytes; verification checks it against the advertised public key. Any change to the signed content invalidates the proof — tampering is self-evident.

What it fixes

Shared secrets vs. keys

Passwords, PINs, passphrases

  • ✕You have to hand the secret over to use it
  • ✕The same secret often gets reused in many places
  • ✕Can be guessed, phished, or stolen in a breach
  • ✕Only as safe as the weakest site that stored it
  • ✕A leaked one is instantly useful to a thief

Keys

  • ✓The secret never leaves your device
  • ✓A different key for every identity and purpose
  • ✓Nothing to phish, because you never send the secret
  • ✓You prove yourself without revealing anything
  • ✓Rotating to a fresh key retires the old risk

How it works

How a VLAD works

You create an identity, which gives you a VLAD — your permanent name

BetterSign starts a signed logbook for it

Every key change adds a new signed page to the logbook

Anyone can replay the logbook and check every page is legitimate

They always end up with your current, correct keys — without asking anyone

The building blocks

Four ideas do all the work

◇

Stable identity

A VLAD remains stable while its keys and protected metadata rotate.

⛓

Self-verifying history

Every state transition is hash-linked and authorized by the previous log state.

⇋

Decentralized discovery

VLADemlia helps peers locate current records without becoming the trust root.

↻

Routine rotation

Key changes become signed updates that followers can verify and apply.

The jargon, translated

Plain-English words for the deep stuff

VLAD
your permanent name; short for Verifiable Long-lived Address
plog
the signed logbook behind a VLAD that records every change
rotation
swapping an old key for a fresh one without changing your identity
revocation
marking a key as no longer usable, for example after it leaks
recovery
using a stronger backup key to fix things if a normal key is lost
VLADemlia
the network address book that helps peers find each other; it never decides who to trust

Questions

The things people ask first

Do I need to understand the cryptography?

No. Point your tools at a VLAD and BetterSign keeps the keys current for you — SSH that doesn't break when keys rotate, TLS that renews itself, API tokens you can rotate freely.

What if I lose my key?

Recovery is built in. A stronger, better-protected backup key can fix things if a normal key is lost or stolen — no out-of-band scramble.

Why is changing keys a good thing?

The longer a single key stays in use, the more chances a copy ends up somewhere it shouldn't. Rotating retires old risk — like changing the locks now and then.

Can a company take my identity away?

No. A VLAD is owned by you and no one else, proven by math anyone can check, and still verifiable years later — even offline.

A name you keep. Keys you can change.

Point your tools at a VLAD and BetterSign keeps the keys current for you.