this post was submitted on 25 Nov 2025
20 points (95.5% liked)

Hacker News

3182 readers
424 users here now

Posts from the RSS Feed of HackerNews.

The feed sometimes contains ads and posts that have been removed by the mod team at HN.

founded 1 year ago
MODERATORS
top 2 comments
sorted by: hot top controversial new old
[–] Samskara@sh.itjust.works 4 points 1 week ago

Working as designed.

[–] jbloggs777@discuss.tchncs.de 1 points 1 week ago* (last edited 1 week ago)

Requiring only two out of three keys leaves the system open to straightforward collusion. A threshold like three out of four, or three out of five, would raise the bar to something more like a coordinated conspiracy. There are likely additional human roles involved in the process as well (mitigating the risk), though I’m not fully familiar with the complete setup.

My assumption is that these keys are meant solely to control the timed release of the data, not to serve as the ultimate source of authority. The encrypted ballots are probably disclosed to the keyholders at the same moment the keys themselves are published.

It reminds me of a pet project I want to complete: An automated online timed release keymaster, publishing future-dated public keys, then publishing the secret keys on that date. One day soon... edit: it already exists, https://timelock.dev/