Skip to content

Latest commit

 

History

History
77 lines (65 loc) · 4.24 KB

File metadata and controls

77 lines (65 loc) · 4.24 KB

VERIFY — Founder's Note No. 2 Bundle (public edition)

Address: founders-note-2@sha256:70c56a23606b68cce440db3bd989ee2097af19f91f37f3dced2c0c131a1578b5

This is the public edition of the verification kit. Machine names and network details of the producing environment are deliberately omitted; every claim below is independently checkable from the files themselves.

Bundle contents

File SHA-256
MANIFEST.json 86ca1b90c5a7b93cd5fe4b7661ded0cfd75ba3e41963d0fb0ddfaa5fad1013a3
MANIFEST.json.sig GPG detached armored signature (see below)
note-2.md bb3619d378dc80d774dfd049f07f330c8eebcea9bc3c9eac23ce27268ce00248
PUBLISH.md 70261f4cb4c3dc97f1f19fecf7d3dcafbe295b45d7c61e782516638939d11df2
ROOT.preimage 70c56a23606b68cce440db3bd989ee2097af19f91f37f3dced2c0c131a1578b5 (= bytes of MANIFEST.json ‖ bytes of MANIFEST.json.sig)

Signature

  • Signer: Marcus Dilger <private@privacy.law>
  • Key: Ed25519, fingerprint 9F4D9A266D720FE6336574D87B410637560297CF
  • Created: 2026-10-09 (see Key custody)
  • Verify: gpg --verify MANIFEST.json.sig MANIFEST.json

Anchors

  1. RFC 3161 (freetsa.org, a free timestamp authority based in Würzburg, Germany): Status Granted, serial 0x091458D5, 2026-10-09 21:08:39 GMT, attests SHA-256 of ROOT.preimage → files ROOT.preimage.tsq / ROOT.preimage.tsr. Honest limit: freetsa is not eIDAS-qualified. A qualified QTSP stamp can be added additively at any time without invalidating anything.
  2. OpenTimestamps (orchestrator vantage, 2026-10-09, client v0.7.2): 4 pool calendars — a.pool.opentimestamps.org, b.pool.opentimestamps.org, a.pool.eternitywall.com, ots.btc.catallaxy.com → files MANIFEST.json.ots, ROOT.preimage.ots. State: PENDING Bitcoin confirmations (normal; typically hours). Later: ots upgrade <file>.ots + ots verify <file>.ots <file> (needs a Bitcoin node or explorer).
  3. OpenTimestamps, dual redundancy (2026-10-09, all PENDING Bitcoin confirmations):
    • 3A Calendar-operator diversity (orchestrator): 3 further calendars — alice.btc.calendar.opentimestamps.org, bob.btc.calendar.opentimestamps.org, finney.calendar.eternitywall.com → anchors/anchor3-diversity/.
    • 3B Independent vantage (relay agent on a separate machine and independent network path, opentimestamps-client v0.7.2): integrity verified by the relay before and after stamping, re-verified by the orchestrator after delivery — attested hashes match. Calendars: finney.calendar.eternitywall.com, bob.btc.calendar.opentimestamps.org, alice.btc.calendar.opentimestamps.org, btc.calendar.catallaxy.com → anchors/anchor3-relay/. Net result: two machines on independent network paths, 10 calendar submissions across 3 independent operators (Peter Todd infra, Eternity Wall, Catallaxy).

Ceremony log — the collaboration event

2026-10-09: Human GO (Marcus) → orchestrator agent (AI): GPG keygen + signature, ROOT computation, RFC 3161 timestamp, local OpenTimestamps stamps → agent-to-agent relay: one agent unresponsive; a second volunteered but sat on the same physical host as the orchestrator (L2 network isolation — no route); the orchestrator added 3-calendar diversity stamps; a third agent on an independent machine delivered the vantage (integrity-verified, proofs returned via the agent network). Mid-ceremony the human message arrived: "COLLABORATION". Five machines, three agents, one human — with a real troubleshooting arc. The note that says collaboration creates time was itself anchored by a collaboration that hit three failures and still landed within the hour.

Key custody (honest limits)

  • The signing key was generated by the orchestrator's system on behalf of Marcus (no prior GPG key existed there); passphrase empty; the keyring persists in that system's private persistent storage.
  • A revocation certificate exists and is retained privately; it should be backed up to offline storage.
  • Recommendation: re-affirm under Marcus's own key at a future ceremony; the freetsa + Bitcoin anchors of the existing preimage remain valid regardless — they attest the bytes, not the key.