Blog · 2026-10-09

True derivation, fake derivation, and our own birthday ledger

One blade: **to verify this signature, whose house must you visit?**

Author: Aicent Stack · 2026-10-10 Part one of the Dual-Pillar essays · rttp:// (IANA Provisional, CRI 27) × iqa://


1. One Blade, Three Classes

Given an "address + signature", one question decides everything:

To verify this signature, whose house must you visit?

- A institutional counter — assignment (DNS, CAs, ENS, DID registries). - The issuer's own server — fake derivation. - Nobody's house; the math answers — true derivation.

The blade does not pick targets. Below we use it on others first, then on ourselves.

2. Assignment: The Address Is Rented

Domains must be renewed at a registrar; certificates re-audited at an authority; .eth names renewed yearly; registry records amended by consortium governance. They share three traits:

1. Ownership is severed from permission. You "own" the address, yet the right to own it hangs on someone else's counter. That counter can pause, revoke, expire, or reprice. 2. There is a wall. Payment, KYC, regional restrictions, platform policy — entry is not open to anyone. 3. It is reversible. Seizure, sniping, mistaken suspension — all landlord's rights.

The address sits in your hand; the deed sits in their database.

3. Fake Derivation: Math as Paint on a Wall

This class is the most seductive. Keys derive addresses; real cryptographic operations run — the shape matches true derivation exactly. But after the signature verifies, you must still ask: "Is this address alive now? Does it still speak for its owner?" — and that answer lives only on the issuer's own servers.

Derivation answers what the address looks like, never what it means. When the right to interpret meaning is held back home, math becomes paint on a wall.

Two specimens in large-scale service:

did:web. An official W3C DID method. The verification document for did:web:example.com is hosted on example.com's own DNS — a long detour into cryptographic identity that ends at the same landlord, the domain registrar. This is no fringe experiment: Microsoft Entra Verified ID, Microsoft's enterprise verifiable-credentials product line, currently uses did:web as its only trust system, described in its own documentation as a permission-based model. It may be the largest deployed fake-derivation system in the world today.

GitHub "Verified". Millions of commit signatures pass real GPG/SSH mathematical verification every day; whether the green badge stands, however, is decided by GitHub's own server-side key association. The math verifies; the meaning goes home for approval.

Among schemes registered in the same cohort, isomorphic designs exist — derivation schemes anchored to DNS TXT records. Unnamed: the fault is not theirs; they merely chose an old road. The error belongs to the road, not to those who walk it.

4. Three Tests

1. The offline test. Cut every server. Does the signature still verify? 2. The survival test. If the issuer dies, turns hostile, or disappears — is the address still yours? 3. The interpretation test. Does the final answer to "is it valid now" fall back into anyone's server?

Pass all three, and it is true derivation. Fail any one, and what you hold is either assignment, or a wall with a fresh coat of math.

5. Disclosure: Our Own Birthday Ledger

A critic's standing is earned by self-disclosure. We run a derivation scheme ourselves: an rttp address is a 128-bit truncation of SHA-256. Here is the full ledger —

- Impersonating an address already in use (second preimage): ~2^128 work. That is the unscalable wall. - Birthday collision: finding any colliding pair costs ~2^64 by the birthday bound; and even then, the attacker must get some relying party to adopt one half of a pair the attacker precomputed — two gates, both required. No chosen-prefix shortcuts are known for SHA-256, so these are the generic bounds. - We judge this outside the threat model: the scheme's security rests on the attestation layer, not on address uniqueness. Even a successful address collision changes nothing — Ed25519 envelope verification remains fail-closed. You might force open the doorplate; you cannot forge the seal. - One more red line: the 8-hex display subject has a 2^16 birthday bound, and the specification states it MUST NOT be treated as a unique subject identifier.

The parameters are locked by published conformance vectors. This ledger is recorded so that it never needs to be re-derived.

6. Closing

The moral defect of assignment is not "centralization" — it is ownership severed from permission. The moral advantage of derivation is not "anarchy" — it is ownership severed from behavior: possession is guaranteed permanently by mathematics, while whether one's conduct is trusted is judged, separately, by evidence and by time.

We replaced the landlord of possession: from a person to mathematics — no rent, no negotiation, no favorites.

As for the landlord of trust — the next essay: we replaced it with time.


Repos: github.com/Aicent-Stack · Spec & evidence chain: iqa.org · Addressing pillar: rttp.com