Home | Search


2026-08-03

Ethereum smart contracts cannot trustlessly verify authenticity of web data (by verifying TLS and CA chain-of-trust) or emails (by verifying DKIM headers)

Disclaimer

Main


P.S.

My current understanding (could be incorrect) of the steps in a modern TLS 1.3 connection

Looking at this makes it even more clear to me why a third-party (not involved in ECDHE key generation process) has no reason to trust the ECDHE shared secret or anything encrypted or authenticated by keys ultimately derived from the ECDHE shared secret. Also, an ethereum smart contract cannot directly participate in ECDHE key generation directly because a smart contract (i.e. thousands of ethereum nodes) cannot keep a secret.

P.S.

Subscribe

Enter email or phone number to subscribe. You will receive atmost one update per month.

Alternatively, you can subscribe via RSS, or a third-party service like blogtrottr

Comment

Enter comment