this.me / Tests / Security

Derived from Secret

A value derived from a secret becomes public only through someone who can open that secret. Without the key the secret is absent, so a formula over it has nothing to compute from. Declaring a public formula over your own secret is a disclosure you choose, and it keeps publishing on every recompute. What the kernel does not try to stop: people inferring things from data they are entitled to, or copying a value after it was opened to them.

Every value below is computed right now, in this page, by the .me kernel. Nothing is pasted in. The cases are the ones in Typescript/tests/Security/derived-from-secret.test.ts, which runs with npm test (via npm run test:security).

Holds from this.me 4.0.2 on npm. 4.0.1 and earlier fail this test.

RUNNINGLoading kernel…

Setup

Secret A lives at vault.balance under a _ scope. fx.rate is public. Four parties end up holding the data but not the key.

Show setup code

Who can derive what

Each party declares the same four formulas over the secret. Cells show what the kernel returned. Without the key, the formula stays unevaluated text. The owner, holding the key, gets numbers.

not derivedderived by the key holder (a disclosure they chose)derived without the key (would be a leak)

Recompute after the key is gone

The owner declared report.mixed = vault.balance * fx.rate while holding the key. Then the key goes away and fx.rate changes.

By design

What the owner chose to disclose, and where that disclosure ends.

Baseline