transparencylog/tl

Self hosting

Opened this issue · 2 comments

Hello,

I imagine it's a little ironic to be asking for self-hosting for a project that brands itself with "transparency" and "public" keywords but I was wondering if opensourcing the server was planned?
I would love to run this in an air gapped environment for example.

What are the obstacles to using the hosted service for you? Would a proxy be sufficient? #11

A good deal of the value of a transparency log is having lots of people using the same log to both:

  1. Add URL digests as soon as possible to them being published (ideally by the publisher themselves: https://www.transparencylog.com/software-release-process-integration/)

  2. Having users with a single shared view of digests across the internet finding mismatches in case of an attack

we plan to use it in the following way.

1,000 of self hosted "servers". Mobiles, desktops, anything

global revere proxy for them. Ngrok on steroids.

the transparency log is saved on each users computer but the Proxy just allows everyone to find each other and compare the logs. The public keys of each user in on the Proxy, The private keys on their devices that they sign data with.

Would be awesome to hear any feedback on that design.