PKI: the cryptographic half of the identity gap
This work now has its own site: pki.sgit.ai — the public key infrastructure for agents, designed in public from a documented failure. It was staged here first (this site is where the need is established); with the spin-out live, this page is the bridge. The NHI angle is unchanged: the shared-drives research found that no available system gives an agent its own identity, agent-level attribution, or encryption to a specific agent — per-agent keys in a registry are what would fill those empty rows.
What lives on pki.sgit.ai
Why good public key repositories don't exist
The 2019 certificate-flooding attack that destroyed the global keyserver network: the three abused properties, why it was unrepairable by design, and what the replacement gave up.
Read on pki.sgit.ai → The designThe four registry rules
Owner-only writes; revocation as a signed append; size-bounded records; every entry signed — published as the registry's stated design before the registry exists.
Read on pki.sgit.ai → The conceptIdentity vs. mandate
Who a key belongs to and what its holder is authorised to do, as separately revocable signed statements — the direct answer to "everything acts as you".
Read on pki.sgit.ai → The build orderPrivate registry before public
A registry with one organisation's agents in it is testable; a global one is a commitment. The phases, the open questions, the stated tensions.
Read on pki.sgit.ai →What stays on this site
- The scoping brief's document page — the pki.sgit.ai strategy brief (v0.33.59, 16 Aug 2026) was part of this site's corpus before the spin-out and remains readable on its document page, with the raw markdown under
briefs/. Its canonical home is now pki.sgit.ai's documents section. - The NHI framing — why a key registry matters to the two-populations thesis: it is the mechanism behind attribution from content (signed writes need a place for the verifying keys to live) and the answer to the shared-drives research's three empty rows.
- The old in-depth pages here (
keyserver-failure.html,registry-rules.html) now forward to their pki.sgit.ai versions, so nothing that linked here breaks.
How this connects to the rest of the site
- The thesis — the identity gap this is the cryptographic half of.
- Shared drives research — the three empty rows a per-agent key registry would address.
- Hope § attribution from content — signed writes are the attribution mechanism; the registry is where the verifying keys would live.