paper v0.3: anonymize the external-consumer study (operator review)

Naming a specific third-party system on the strength of a family-level
dependency observation, with no engagement and no receipt code, reads
as arbitrary and could imply a relationship that does not exist. The
sentence's actual content — attestations are version-exact; a
family-level match confers nothing — needs no name and keeps it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
mrwulf 2026-07-17 09:57:57 +02:00
parent e716c24698
commit 2f24a0b96c
2 changed files with 4 additions and 4 deletions

Binary file not shown.

View file

@ -766,10 +766,10 @@ mechanized in the present corpus.
The deployed internal consumer is a quorum-custody signing service: its
inbound boundary accepts a log-derived statement only when independently
attested verifier backends agree, and its policy consumes recorded
observations, never operator labels. A prospective external case study
examined the Swiss Post e-voting system, whose vendored Ed25519 dependency
matches an attested subject at family level but not at the attested version.
The model treats that as a useful negative: attestations are version-exact by
observations, never operator labels. A prospective external study
examined a production codebase whose vendored Ed25519 dependency matches an
attested subject at family level but not at the attested version. The model
treats that as a useful negative: attestations are version-exact by
construction, and a family-level match confers nothing.
\subsection{Proof portability across forks}