Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Misbehaviour

Signed contradictions can become portable evidence. Glimpr defines checks for an operator or witness attesting to incompatible versions of the same history position.

Conflicting heads

A host that rewrites history must publish a chain that disagrees with one it already attested. Because heads are signed, and witnesses retain what they co-signed, the result is two signed statements about the same position that cannot both be true.

A conviction is that pair: two heads for the same stream at the same position, with different chain hashes, both signatures verifying under the same signer.

Checking it requires trusting neither the party that produced it nor the party presenting it. Both signatures verify or they do not.

Conflicting roots

The same shape applies to the namespace: two directory roots at the same sequence number, committing to different namespace states, both signatures verifying under the same signer.

A directory that shows one answer to one party and a different answer to another has signed exactly that pair.

Both forms convict operators and witnesses alike. A witness that co-signs two conflicting heads has equivocated exactly as an operator would have, and the same evidence establishes it.

Detection requires plurality

Producing a conviction requires that two views actually get compared. That is what witnessing across parties is for, and why witnesses sharing an operator provide so little — a party consulting only itself will always find itself consistent.

Witnesses retain what they signed, so a conviction remains assemblable after the fact rather than only at the moment of divergence.

Bounded ambition

A conflicting-head proof establishes a specific act: one signer attested to different hashes for the same creator history at the same position. A conflicting-root proof establishes the analogous act for the directory.

These proofs do not establish every kind of misconduct. Going offline, refusing a request or withholding a file does not necessarily produce two contradictory signed statements. An isolated client may also see only one branch of a fork until views are compared.

The value is precision. Where the contradictory statements are available, another party can check them without access to the operator’s database or trust in the person reporting the conflict.

Removing a misbehaving host

The creator can use the ordinary host-switch procedure to close the outgoing host’s authority and authorise a replacement. Witness-held evidence supports the close, while available history and content support the transfer.

Clients with acceptable current evidence reject writes outside the closed delegation. A successful move still depends on the recovery materials being available; the proof of misconduct does not supply them.

What conviction does not do

It produces a checkable fact, not a penalty. The proof check does not itself recover funds, delete data or administer a penalty. Rejecting a key from future delegations or witness policy requires that the evidence reach the parties enforcing those decisions.

What the evidence supports is a decision made by people — members declining to trust a host, creators declining to hire it, operators declining to work with it. The contribution is that the decision can rest on something checkable rather than on an accusation.

The honest boundary

All of the above assumes the parties holding the evidence are independent of the party the evidence concerns.

Where witnesses share an operator with the host, or where the anchor a client pins comes from the party being checked, the mechanism is present and the guarantee is not. That gap belongs to a deployment, not to a design, and no amount of correct design closes it. See Limits.