Signed record

The signed record

Every portfolio item on this site was approved by Gee and signed before it was published. This page says what that record is, what it proves, what it does not, and how to check it.

What it is

A public list of signed entries, in order. Most record one approval: which item it is (for example a case study), a fingerprint of the exact file that was approved, the time, and a digital signature. The others record the keys allowed to sign, and changes to the server code (the Worker), the shared rules and the privacy scanner. Each entry also carries the fingerprint of the entry before it, so an entry cannot be removed or moved without the change showing.

What it proves

  • That each published item is the exact version Gee approved, and when he approved it.
  • That nothing unapproved is published: the site is built only from approved files, and a file that does not match its latest approval stops the build.

What it does not prove

  • That what a case study says is true or complete. The signature shows what he chose to publish.
  • Who a client was: client and employer work is shown without names.
  • That the site has no security problems.
  • Anything checked by someone else: the signing key is his own, not an outside auditor’s.
  • That every part of the site is signed. Page layouts, the site’s own wording, the demos, the pages’ own scripts (the contact form and the assistant widget), the build and its approval gate, and the site’s security headers are not signed item by item.

How to check it

  • The record itself: the signed record file, a list of every entry in order, each exactly as it is kept. Written out one entry per line, the list is the record file the signatures are checked against.
  • The public key its approvals are checked against: the signing key.
  • The signatures are standard SSH signatures, which common tools can check. Changes to the server code (the Worker), the shared rules and the privacy scanner are recorded too, some signed with a build key he authorized for a limited time; that key’s public line is in the record itself.
  • Each case study’s Record panel gives the number of the entry that approved it, so it can be found in the list.
  • One limit: a fingerprint covers the approved source file, which is not published byte for byte, so the chain and the signatures can be checked, but not a page’s fingerprint recomputed from the page.