Everything digital is a copy of a copy.
Tomorrow's history is built with today's digital artifacts, often stored on ephemeral storage media, without guarantees against backdated metadata or unobserved modifications.
Today's capabilities to generate large amounts of convincing fakes are improving fast, making it impossible to distinguish history from forged artifacts.
Bad actors will try to leverage this for their own profit, putting pressure on current preservation efforts, sowing doubt into the genuineness of the recorded past.
Now is our last chance to build foundations for tomorrow's trust.
Current digital archives are very successful at recording our present at scale. These repositories are part of the productive economy as anchors of trust.
Mechanized intelligence will soon be employed to wage war. Good operational security is extremely difficult and most archives cannot afford to become a target.
Modern public key infrastructures and software supply chains have already solved these problems, ensuring that billions of items are tamper-evident every day.
This can be done by integrating transparency logs into archival practices, making tamper-evident indexes public by default, to be retrieved and verified by anyone.
Start today by asking your archives to publish all their digests, now.
We build to support existing digital archives.
We want simple cryptography to ensure that future users will be able to check that your index is genuine. We want paper-printable text for the century scale.
We believe in public entities signing today all digital artifacts. Let's empower the archives to build verifiable trust they control, without putting them on the path of future attackers.
Transparency is what makes trust ecosystems possible at scale.
We build for local-first offline use as this is the best way to get these document indexes in lots of different places. We optimize for file storage instead of databases.
This is a long way to go. We are moving forward right now.
Don't wait for us: you can act right now!
We are building free and libre software to make Archive Transparency a reality. Our mission is to let anyone create tamper-evident logs that ensure the integrity of humanity's history.
This is critical infrastructure required to build lasting trust in all kinds of repositories. We are looking for partners to build verifiable digital preservation.
We are Resilient Internet Preservation and we want you to help!
Yes, but not only.
We trust documents we find online because they look authentic or because we found them in a website that seems legitimate. It is impossible to distinguish documents stored by a honest third-party from convincing fakes with backdated metadata.
Building trust is not straightforward and threats are materializing while people argue on how to fix this. Soon enough, in our lifetimes, it will be too late.
Let's stop arguing. Let's get the archives to publish all the cryptographic digests of their items on their website. Any format, any standard, make the hashes public.
Then, people can build their own defenses using this, without waiting for adoption of any kind of standards. Publishing enables fast progress for everyone, right now.
Making the archives transparent is how everyone together solve this!
Stop waiting: just do it yourself right now, make all the digests public!
Do not wait for anyone to tell you what to do!
Yes, this would be best done with shared industry standards build as commons, but coordination is hard. This makes all of us vulnerable.
What anyone can do without waiting is taking any kind of records in any format, containing any kind of useful digests of existing items, and making that public.
History yesterday was built out of a wide diversity of narrators. Keeping digital integrity private on grounds of a "fear of doing it wrong" does not work.
What works, is publishing the digests, letting anyone be a narrator for tomorrow.
Go talk to your digital librarian or archivist:
This enables any downstream tool to observe other people's items by digest. This is not perfect, but it creates a baseline for future trust. Making sure that existing items can be listed by anyone is the shortest path to enable society to build its defenses fast.
Don't argue about picking the right way, do it now! Let's not wait for adoption of common standards to do this: just make your existing records public.
Use what you have, any existing tool or workflow would do!
If you want an opinion, see below:
https://example.com/.well-known/digests/howto.txt
https://example.com/.well-known/digests/today/
sha256digest of items;
byte sizeof items, it helps verifiers;
blake3digest if you can: have two secure hashes;
md5,
sha1, file name or object identifier for cross-reference.
give away only the minimum!
What matters is making it accessible and letting people pick up the task of building their own defenses today. There will be time after to argue about standards.
This will not happen without you publishing digests first!.
Because we are all late to the party.
The need for authentication in the archival landscape has long been known. The LOCKSS project drafted its threat model two decades ago, the LTANS working group concluded fifteen years ago, and Webrecorder integrates trusted timestamping.
However, most data online today is still not obviously authenticated. Scale is hard, budgets are small and issues like copyright are limits that stop content-oriented approaches. Today bad actors have all the capabilities to leverage these weaknesses.
We strongly believe that making the integrity public is the path forward.
The solution to this must integrates on top of existing item repositories. Anyone needs to be able to build today a tamper-evident index of their own artifacts, but also of their favorite archives, in a way fit for long-term storage.
We also believe that transparency logs are perfect for this!
We believe that the ideas underlying Certificate Transparency, Sigsum and Sigstore can be adapted to build tamper-evident historical records for all. They are tracking every year billions of records in transparency logs, a scale comparable to existing digital archives.
There exists many standards for digital archives, each pairing items to their metadata in their own ways. We do not propose replacing these standards.
We propose to append supplemental index files, text-based, capturing just enough metadata together with cryptographic hashes, signatures and trusted timestamps. We want to empower anyone to build and share these indexes, public by default and discoverable through logs.
We deliberately keep things simple, you don't need a blockchain for this!
We are not any kind of root of trust.
We believe that distributed governance is key. We aim to use transparency logs to distribute trust between national institutions, non-profits, and individuals.
Let people be their own source of trust, we don't need more!
We design to integrate with the existing transparency ecosystem. We believe that logs only need to monitor that new entries added are never backdated. We aim to provide recovery paths from log corruption, as well as integrate several backup plans against cryptographic decay.
This will require transparency-enforcing tools and clients. We want to enable anyone to write their own. This requires open standards and we aim to assist the wider archiving community at making fast progress on transparency.
We want to enable both the small and large scale by enabling clients to interact offline with the index. Making this public by default is how this gets solved!
Let's enable anyone to protect their own favorite archives, large or small, and build tamper-evident logs of the artifacts they care about. This is shared infrastructure for the future.
The problems surrounding digital archives can be described as century-scale.
We do not aim to solve everything revolving around digital archives, but we do aim to bring into the long-term innovations like tamper-evident logs.
Scaling file formats and protocols to several decades is not a trivial task as we cannot predict the future. This is in some fundamental way a guess.
We still believe that some meaningful choices exist, from using text files, making everything paper-printable, to careful choices of technology.
Call it a ledger if you want!
Blockchain technologies spawned many innovations making full use of modern cryptography. However, we are solving for a different kind of problem. Yes, it is an append-only immutable trees of hashes. No, we are not building a blockchain.
We believe here that the limiting factor is not good cryptography!
We are making opinionated choices specific to long-term digital preservation and believe that transparency logs are a better fit for this. We also believe that blockchain-based notary services may have some role to play.
But society cannot afford to rely on them.
We are still in the early stages of the project.
We are currently working on a research prototype to experiment with the design space available to us. The short term goal is to build a small-scale deployment of 10 million items.
We invite you to contact us to help us scale to 10 billions of records!