Prototypes Prototype docsP11 · Docs and assistant
Signed documents (P2)
DocsPage 3 of 30

Signed documents (P2)

A file is signed with a key kept in the browser, and anyone with the signature file can check whether the file changed.

The key

The signing key is an Ed25519 key pair, or ECDSA P-256 in a browser without Ed25519. The private key is kept in IndexedDB and cannot be exported, and the button New key replaces the pair with a new one.

The signature file

The signature file holds the file's name, size and SHA-256, the time of signing, the public key, and a signature over all of it. For a text file up to 2 MB it also holds a salted hash of every line. The salt is new for every signature, so a line cannot be guessed from its hash.

Checking a file

Drop the file and its signature file together. The page verifies the signature with the public key in the signature file and compares the hashes. When the file changed, the line hashes show which lines were changed, added or removed. An edited signature file fails the signature check. A signature proves that the file matches what the key signed; compare the fingerprint with the signer to know whose key it is.

Previous: Encrypted messages (P1). Next: Ask the chart (P3).

How Prototype docs is built

The pages are written in Markdown and built into these pages and an index of 154 sections. The assistant answers from the index, and every answer names the sections it was taken from.