Reproducible verification for retained logs (RFC 8785 canonicalisation + OpenTimestamps)
David A. Wheeler
dwheeler at dwheeler.com
Fri Jul 10 21:16:37 UTC 2026
> On Jul 10, 2026, at 12:10 AM, Colin Winter <hello at markovianprotocol.com> wrote:
>
> Chris Lamb suggested this list might find the following of general interest, so I am bringing it here for comment.
>
> Reproducible builds remove trust in the builder: anyone re-derives the same artifact from the same source, byte for byte. The same shape applies one layer over, to a retained record. Most record-keeping regimes (the EU AI Act's Article 12 logging is the current example) require that events be recorded and logs retained, but not that a retained log be verifiable, by a party who was not present, as unaltered and existing when claimed. That leaves an integrity obligation resting on trusting the party being audited....
I think you'd need to record exactly *who* performed the verification (along with their signature), which might not be the same org posting somewhere. After all, an attacker can do a build too. People should only be interested in the records from someone who they trust.
--- David A. Wheeler
More information about the rb-general
mailing list