BetterSign™.

BetterSign™

No passwords. No logins. No middleman.

Decentralized PKI with no trusted third party.

No central authority, no "sign in with Big Tech," no key server to trust or get hacked. Just you, provable directly.

No certificate authority, key server, or bootstrap node holds leverage. Discovery uses a Kademlia-style DHT (VLADemlia); trust derives from the provenance log itself.

  • No company stands between you and proof
  • Nothing in the middle to hack or shut down
  • No one else can lock you out
  • no CA and no key-server dependency
  • VLAD to CID resolution over the DHT
  • validity comes from replaying the plog, not from the DHT

A stable name on the outside, freely changeable keys on the inside.

The picture

A network address book, not a gatekeeper

Instead of hand-delivering keys, you publish the change once to VLADemlia — a shared network address book. Each follower pulls your latest verified state and checks it themselves. VLADemlia only helps peers find each other; it never gets to decide what is true.

VLADemlia is a Kademlia-style DHT mapping a VLAD to its current head CID. It provides discovery only; validity is determined by replaying the provenance log, not by trusting the DHT.

What it fixes

A name anyone can check, anytime

Ordinary identifiers

  • ✕Owned by a company that can revoke or redirect it
  • ✕Proven only when a middleman vouches for you
  • ✕Can be impersonated if the provider is fooled
  • ✕Stops working if the service disappears

A VLAD

  • ✓Owned by you and no one else
  • ✓Proven by math that anyone can check
  • ✓Cannot be forged without breaking the cryptography
  • ✓Still verifiable years later, even offline

How it works

Publish once, everyone follows

You add the new key as a signed page in your logbook

You announce the update to VLADemlia, the network address book

Anyone following your VLAD looks you up and pulls the change

Each follower verifies it on their own, so the network is never trusted

They switch to your new key automatically, with nothing hand-delivered

The building blocks

Four ideas do all the work

◇

Stable identity

A VLAD remains stable while its keys and protected metadata rotate.

⛓

Self-verifying history

Every state transition is hash-linked and authorized by the previous log state.

⇋

Decentralized discovery

VLADemlia helps peers locate current records without becoming the trust root.

↻

Routine rotation

Key changes become signed updates that followers can verify and apply.

The jargon, translated

Plain-English words for the deep stuff

VLAD
your permanent name; short for Verifiable Long-lived Address
plog
the signed logbook behind a VLAD that records every change
rotation
swapping an old key for a fresh one without changing your identity
revocation
marking a key as no longer usable, for example after it leaks
recovery
using a stronger backup key to fix things if a normal key is lost
VLADemlia
the network address book that helps peers find each other; it never decides who to trust

Questions

The things people ask first

Do I need to understand the cryptography?

No. Point your tools at a VLAD and BetterSign keeps the keys current for you — SSH that doesn't break when keys rotate, TLS that renews itself, API tokens you can rotate freely.

What if I lose my key?

Recovery is built in. A stronger, better-protected backup key can fix things if a normal key is lost or stolen — no out-of-band scramble.

Why is changing keys a good thing?

The longer a single key stays in use, the more chances a copy ends up somewhere it shouldn't. Rotating retires old risk — like changing the locks now and then.

Can a company take my identity away?

No. A VLAD is owned by you and no one else, proven by math anyone can check, and still verifiable years later — even offline.

A name you keep. Keys you can change.

Point your tools at a VLAD and BetterSign keeps the keys current for you.