Skip to main content

blind_data

Function blind_data 

Source
pub fn blind_data(data: &Value, blind: Blind) -> Result<Value, BlindError>
Expand description

data with a Blind under BLIND_KEY — what a writer signs and stores for every redactable entry.

An entry’s data_hash is public and permanent: the chain cannot verify without it. After a redaction everything in data except the removed values is public too, so without a blind anyone could test a guess at a removed value — a name, a handle — by putting it back and hashing. The blind is 256 bits of the preimage that redact_data replaces along with the values, so the old hash can no longer be reproduced by anyone who did not already hold the unredacted entry. It is not a secret while the entry is whole, and it is not part of the envelope: verifiers hash data as they always did.

Entries written before blinding existed have none. Their first redaction is only as safe as the removed values are hard to guess (redact the enclosing value when in doubt); it leaves a blind behind, so later ones are protected.