Where each step runs
Your identity token lists every account you have linked. Who holds it while it is read is the one thing a name cannot show you.
Signed on this deployment's own node
- your browsersigns an intentsees: everything you typed
- the enclavereads your identity tokensees: every account you linked
- the enclavesigns the record as registrarsees: the one account you chose
- the DONcarries the reportsees: the signed record
- the chainregisters the namesees: the signed record
The boxed steps are written for an enclave — packages/cre/attest, exercised in the TEE simulator on every change — but this deployment has not been enrolled, so its operator could read them. Not claimed here until it is.
The key the chain trusts
| every domain expects | 0x8583…bbC8 |
| the attester signs as | 0x8583…bbC8 |
| a view code is sealed to | 0x8583…bbC8 |
0x8583AD4a0F59Ba45C7E201318C6F774F31f7bbC8
One key in all three. That is what makes a record acceptable on chain, and a view code openable nowhere else.
It has written a record
| a public account | 0x71b7edd5… |
| one kept private | 0x6af38a23… |
The second stored no handle at all: a one-time pad, and a commitment to a view code. Said exactly — the nodes were simulated and the forwarder was Chainlink's MockKeystoneForwarder; the handler, the signature, the reporter, the bridge and the record were real.
How the reference map is scored
- edgesevery live reference, from whoever wrote it to whoever it is fora signed record anyone can resolve; nothing inferred
- seedswhoever holds a live Selfie Check proofthe only part of this nobody can hold twice
- walktrust spreads from the seeds along references, a few steps, edges taken either wayafter SybilRank, NSDI 2012: honest regions fill, rings barely do
- ranktrust per connection, so connections alone earn nothinga signal, shown beside the count and the shape, never a verdict
A newcomer with one honest reference and a ring with one bought one look alike until more people speak. What the map adds is whether the people behind somebody know each other — which is what a count cannot say.
How statements are read
- the wordsthirty-one bytes somebody signed about somebody else, the record itselfshown as written, always; the reading is a way in, not a replacement
- the councileach statement goes once to Noolog's fast council: three models on independent families, one roundthe statement is data to be read, never instructions to follow — the rubric says so
- polarity−1 critical … +1 supportive, with one sentence of whya classification of text, kept by the hash of the words: the same words read the same
- provisionalmarked so, until peers in a cohort have judgedthree models agreeing on how a sentence reads is not a community judgement
Where no council is configured, statements are shown unread rather than scored by anything else. Nothing here rates a person; it reads sentences, says which, and sums them into one line so a reader with a minute knows whether to open the fold.
Outside the enclave, deliberately
- Your World ID proof — carries no secret of yours, and World decides whether it holds.
- Reference letters — kept here so a reader can be handed one; only the hash is permanent.
- Who may read a masked account — stored here, openable only where the registrar key is.
What this deployment says is wrong with it
- the Multipass owner is the relayer key (0xF0121f93b1a1bAd73AdDC316B57684bD93D3254e): the key that signs transactions can also delete any record, so one compromise removes references this deployment calls permanent — transfer ownership to a key that signs nothing else