pub fn blind_data(data: &Value, blind: Blind) -> Result<Value, BlindError>Expand description
data with a Blind under BLIND_KEY — what a writer signs and
stores for every redactable entry.
An entry’s data_hash is public and permanent: the chain cannot verify
without it. After a redaction everything in data except the removed
values is public too, so without a blind anyone could test a guess at a
removed value — a name, a handle — by putting it back and hashing. The
blind is 256 bits of the preimage that redact_data replaces along
with the values, so the old hash can no longer be reproduced by anyone
who did not already hold the unredacted entry. It is not a secret while
the entry is whole, and it is not part of the envelope: verifiers hash
data as they always did.
Entries written before blinding existed have none. Their first redaction is only as safe as the removed values are hard to guess (redact the enclosing value when in doubt); it leaves a blind behind, so later ones are protected.