A TLS certificate is usually the quietest part of any connection. I never read mine. Some authority nobody questions vouches for it, the padlock turns green, and that's that.

@OpenGradient Chat's certificate doesn't get to be that boring. Its public key gets hashed and sealed into the enclave's own attestation, in a field called user_data.

Not a chain of signatures going back to some authority. A number, baked straight into proof that the right code was running when the connection happened.

I pulled the certificate from OpenGradient's on-chain registry once and checked the hash against the attestation myself. They either match or they don't. No authority to call, nothing to take on faith. Just arithmetic.

Except the arithmetic only checks one thing. It confirms the certificate matches what's sitting in OpenGradient's registry right now. It says nothing about the afternoon somebody actually wrote that record — whether the hash going in was even the right one. Whether anything got mixed up before the chain started checking itself.

A certificate authority can be questioned years later; the signing records are out there somewhere. The registration I looked at left nothing like that behind.

Whatever happened the day that hash got written either happened correctly. It didn't, and there's no second copy anywhere to check it against.
#OPG $OPG