BetterSign™.

BetterSign™

Rotate your keys. Don't break the internet.

Key rotation without invalidating external references.

Good security means changing keys often. Today that breaks every system that trusted the old one. Here, a key change is just a signed, self-verifying update.

Because links point at the VLAD, not at a public key, rotation never breaks references. Each new entry satisfies the prior entry's lock script and the DHT forward pointer advances automatically.

  • Change your keys as often as you want
  • Nothing else stops working when you do
  • Old keys stop being a worry
  • lock / unlock scripts authorize each new entry
  • DHT PUT validates the entry before updating the head CID
  • references stay restorable through the VLAD mapping

A stable name on the outside, freely changeable keys on the inside.

The picture

Like changing a smoke-detector battery

Even the best key doesn't stay perfect forever. Rotating to a fresh key on a regular basis means that even if an old one leaks, it's already retired and worthless. Rotation stops being an emergency and becomes healthy routine.

Each rotation appends an entry that updates /pubkey; the prior key is revoked by that update (or an explicit delete op). The blast radius of a leaked key is bounded to the window before the next rotation.

What it fixes

What changes for you

Without BetterSign

  • ✕Rotating a key can break every machine that trusted the old one
  • ✕Certificates expire and cause outages
  • ✕Secrets get copied by hand across servers
  • ✕Recovering a lost key means an out-of-band scramble

With BetterSign

  • ✓Your identity stays the same when keys change
  • ✓Renewal and rotation are routine, verified updates
  • ✓Watchers update SSH, TLS, and config automatically
  • ✓Recovery is a built-in, higher-priority backup key

How it works

What happens when you rotate a key

You create a fresh key on your own device

You add it as a new signed page in your logbook

The old key is marked retired, so it can no longer be used

Followers verify the change themselves and switch over automatically

Your VLAD — your identity — never changes through any of it

The building blocks

Four ideas do all the work

◇

Stable identity

A VLAD remains stable while its keys and protected metadata rotate.

⛓

Self-verifying history

Every state transition is hash-linked and authorized by the previous log state.

⇋

Decentralized discovery

VLADemlia helps peers locate current records without becoming the trust root.

↻

Routine rotation

Key changes become signed updates that followers can verify and apply.

The jargon, translated

Plain-English words for the deep stuff

VLAD
your permanent name; short for Verifiable Long-lived Address
plog
the signed logbook behind a VLAD that records every change
rotation
swapping an old key for a fresh one without changing your identity
revocation
marking a key as no longer usable, for example after it leaks
recovery
using a stronger backup key to fix things if a normal key is lost
VLADemlia
the network address book that helps peers find each other; it never decides who to trust

Questions

The things people ask first

Do I need to understand the cryptography?

No. Point your tools at a VLAD and BetterSign keeps the keys current for you — SSH that doesn't break when keys rotate, TLS that renews itself, API tokens you can rotate freely.

What if I lose my key?

Recovery is built in. A stronger, better-protected backup key can fix things if a normal key is lost or stolen — no out-of-band scramble.

Why is changing keys a good thing?

The longer a single key stays in use, the more chances a copy ends up somewhere it shouldn't. Rotating retires old risk — like changing the locks now and then.

Can a company take my identity away?

No. A VLAD is owned by you and no one else, proven by math anyone can check, and still verifiable years later — even offline.

A name you keep. Keys you can change.

Point your tools at a VLAD and BetterSign keeps the keys current for you.