paper v0.3: anonymize the external-consumer study (operator review)

Naming a specific third-party system on the strength of a family-level
dependency observation, with no engagement and no receipt code, reads
as arbitrary and could imply a relationship that does not exist. The
sentence's actual content — attestations are version-exact; a
family-level match confers nothing — needs no name and keeps it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
mrwulf 2026-07-17 09:57:57 +02:00
parent e716c24698
commit 2f24a0b96c
2 changed files with 4 additions and 4 deletions

Binary file not shown.

View file

@ -766,10 +766,10 @@ mechanized in the present corpus.
The deployed internal consumer is a quorum-custody signing service: its The deployed internal consumer is a quorum-custody signing service: its
inbound boundary accepts a log-derived statement only when independently inbound boundary accepts a log-derived statement only when independently
attested verifier backends agree, and its policy consumes recorded attested verifier backends agree, and its policy consumes recorded
observations, never operator labels. A prospective external case study observations, never operator labels. A prospective external study
examined the Swiss Post e-voting system, whose vendored Ed25519 dependency examined a production codebase whose vendored Ed25519 dependency matches an
matches an attested subject at family level but not at the attested version. attested subject at family level but not at the attested version. The model
The model treats that as a useful negative: attestations are version-exact by treats that as a useful negative: attestations are version-exact by
construction, and a family-level match confers nothing. construction, and a family-level match confers nothing.
\subsection{Proof portability across forks} \subsection{Proof portability across forks}