BetterSign™.

BetterSign™

Lose the key. Keep the name.

Key loss is a rotation event, not an identity loss.

Compromised or lost a key? Rotate it — or use a stronger backup key to recover — without becoming a stranger to everyone you know.

Advertised keys live under /pubkey in the log's virtual key-value store. Rotate by appending an entry; recover via a Lamport threshold group set in the highest-precedence lock script.

  • Losing a key doesn't lose your identity
  • A trusted backup key brings you back
  • People still know you by the same name
  • an update op on /pubkey revokes the old key
  • threshold /recoverykey enables social recovery
  • the VLAD and full history remain intact

A stable name on the outside, freely changeable keys on the inside.

The picture

Like changing a smoke-detector battery

Even the best key doesn't stay perfect forever. Rotating to a fresh key on a regular basis means that even if an old one leaks, it's already retired and worthless. Rotation stops being an emergency and becomes healthy routine.

Each rotation appends an entry that updates /pubkey; the prior key is revoked by that update (or an explicit delete op). The blast radius of a leaked key is bounded to the window before the next rotation.

What it fixes

What changes for you

Without BetterSign

  • ✕Rotating a key can break every machine that trusted the old one
  • ✕Certificates expire and cause outages
  • ✕Secrets get copied by hand across servers
  • ✕Recovering a lost key means an out-of-band scramble

With BetterSign

  • ✓Your identity stays the same when keys change
  • ✓Renewal and rotation are routine, verified updates
  • ✓Watchers update SSH, TLS, and config automatically
  • ✓Recovery is a built-in, higher-priority backup key

How it works

What happens when you rotate a key

You create a fresh key on your own device

You add it as a new signed page in your logbook

The old key is marked retired, so it can no longer be used

Followers verify the change themselves and switch over automatically

Your VLAD — your identity — never changes through any of it

The building blocks

Four ideas do all the work

◇

Stable identity

A VLAD remains stable while its keys and protected metadata rotate.

⛓

Self-verifying history

Every state transition is hash-linked and authorized by the previous log state.

⇋

Decentralized discovery

VLADemlia helps peers locate current records without becoming the trust root.

↻

Routine rotation

Key changes become signed updates that followers can verify and apply.

The jargon, translated

Plain-English words for the deep stuff

VLAD
your permanent name; short for Verifiable Long-lived Address
plog
the signed logbook behind a VLAD that records every change
rotation
swapping an old key for a fresh one without changing your identity
revocation
marking a key as no longer usable, for example after it leaks
recovery
using a stronger backup key to fix things if a normal key is lost
VLADemlia
the network address book that helps peers find each other; it never decides who to trust

Questions

The things people ask first

Do I need to understand the cryptography?

No. Point your tools at a VLAD and BetterSign keeps the keys current for you — SSH that doesn't break when keys rotate, TLS that renews itself, API tokens you can rotate freely.

What if I lose my key?

Recovery is built in. A stronger, better-protected backup key can fix things if a normal key is lost or stolen — no out-of-band scramble.

Why is changing keys a good thing?

The longer a single key stays in use, the more chances a copy ends up somewhere it shouldn't. Rotating retires old risk — like changing the locks now and then.

Can a company take my identity away?

No. A VLAD is owned by you and no one else, proven by math anyone can check, and still verifiable years later — even offline.

A name you keep. Keys you can change.

Point your tools at a VLAD and BetterSign keeps the keys current for you.