ketsuban

Who can see what

A reference is a signed note on a public register. Here is who touches it, and what each one sees.

The three parts

  1. Multipassthe register, on chainone record per name per domain; nobody can edit it in place
  2. the registrarthe one key Multipass trustsa record counts only if this key signed it
  3. the namewhat you hand peoplealice.ketsuban.eth reads the record back, in any ENS client

You never write to the register yourself. You ask; the registrar checks; the registrar signs; the chain keeps the signed record. The registrar is the whole game, so where it runs is the question.

Why the registrar sits in a sealed box

To prove an account is yours, the registrar must read your login token. That token lists every account you ever linked, not only the one you chose to show. Whoever holds the registrar could read all of it.

So the registrar runs inside a sealed box — a Chainlink CRE enclave, a TEE. The box reads the token, writes one record naming only the account you chose, signs it, and forgets the rest. Not even the people running this site can look inside. A masked account's view code is sealed to the same box, so nobody else can open it either.

  1. your browseryou sign what you want writteneverything you typed
  2. the enclavechecks your login tokenevery account you linked
  3. the enclavewrites and signs one recordonly the account you chose
  4. the DONcarries the signed recordthe record, nothing else
  5. the chainMultipass keeps itthe record, nothing else

Here, honestly: the green steps are written for the box and tested in its simulator, but this deployment has not been enrolled, so the registrar runs on this site's own server and its operator could read them. Not claimed here until it is.

One key, three places it must match

The chain expects a registrar key. The site signs with a key. View codes are sealed to a key. Same key in all three, or nothing works — and nothing can be faked.

every domain expects0x8583…bbC8
the attester signs as0x8583…bbC8
a view code is sealed to0x8583…bbC8

0x8583AD4a0F59Ba45C7E201318C6F774F31f7bbC8

One key in all three: records are accepted on chain, and a view code opens nowhere else.

Nothing here is mocked: the contracts, on Sepolia

Every address this deployment writes to or reads from, on the public explorer. Open any of them and read the same records this site shows.

Multipass, the register0x418F82fd0014a4CA402F145978bfaF0555a9cA06
the registrar key0x8583AD4a0F59Ba45C7E201318C6F774F31f7bbC8
the attestation bridge0xC7283bD9Aad1B08947C841536946Ce4dA9c99929
the permissioned resolver0x4E2d9783cEFF2ed72CD77C14206b29fe246b24F7
the .eth registry0xBDC85dD5b15D7ecb354cd7cb6f2c50b4f2c4F0E2
ketsuban.eth registry0x254D9c7601BD8fa6b6FA7f5A42c860d184E053A7
ketsuban.eth resolver0x6acc74E4931436c18E00302465f70A27599125FD
kju-is.ketsuban.eth registry0xA976CB21597c555F92e7A5de2dAAF06A3c0D63F7
kju-is.ketsuban.eth resolver0x24d0F1dc28D9d05342C2c2ceA459C3f0Dffb18D8
alice.ketsuban.eth registry0x88AAC0f69f279264FA2B6B127CB40Ec02524941A
alice.ketsuban.eth resolver0xae66c62AcAE72098BdAc57d8E8AED53EF000b2Ba
x.ketsuban.eth registry0xef364C83e090Cc0c108688A52a1fb9D8370C9E83
x.ketsuban.eth resolver0xab077B49c61D5AB686D982F501BE06Eb21DF98Cf
telegram.ketsuban.eth registry0xa8832cD715C7AF8f7A7Ea83e3783E497b8490fdA
telegram.ketsuban.eth resolver0xae66c62AcAE72098BdAc57d8E8AED53EF000b2Ba
discord.ketsuban.eth registry0x7d36AFBea41f2a6d9D3eceb956D37e7E5AE47e0D
discord.ketsuban.eth resolver0xe11972d6CD3E98e134166bbFF44dCEbb2c2BbBDC
github.ketsuban.eth registry0x5cBa4C1e56931eF47e42656E466419d46f2A5Ec3
github.ketsuban.eth resolver0xA7EA6E7A323cD25637E63F4DcA93295b64eA5739
google.ketsuban.eth registry0xCf2276f7905b5466D7A0c2b47B418A0f82e81B2c
google.ketsuban.eth resolver0xae66c62AcAE72098BdAc57d8E8AED53EF000b2Ba
linkedin.ketsuban.eth registry0x441ea32D909906f98821141eC1e0c03258836959
linkedin.ketsuban.eth resolver0xd3012973d54C4a96741a84928C5F28a61C8f390D
email.ketsuban.eth registry0x74251190aB2cE7852D2f358f197c146ac64675da
email.ketsuban.eth resolver0xd584cC5dc1477C8f06ec0d9E4B441EE700DCbf6B
peersky.ketsuban.eth registry0x4Cf95D629D00F47E296F5271f8C245B01ec78270
peersky.ketsuban.eth resolver0x6332ED23aF379ba5d2587B3603E87aCD63989134
test-account-123456.ketsuban.eth registry0xA8ADD2CEa6c0Ba08284272a2F2423f71f3862440
test-account-123456.ketsuban.eth resolver0xC001Fb3Ff8fcA7554F477E111f080280bB66a4DA
tims-friend-test.ketsuban.eth registry0xC5c9e3A06953D080570A6395CF6382184fa4Eb77
tims-friend-test.ketsuban.eth resolver0x4E2d9783cEFF2ed72CD77C14206b29fe246b24F7
kju-is.ketsuban.eth registry0xac5534C6bAA24742BDccDe125C8477B8ca1aa876
kju-is.ketsuban.eth resolver0x1732f2022641bf9c39B2332476219786e5135A86
com.x.www.ketsuban.eth registry0x5FD37107CAe5C4981420F505b2Ce57ED8D4209Dc
com.x.www.ketsuban.eth resolver0xae66c62AcAE72098BdAc57d8E8AED53EF000b2Ba
com.github.www.ketsuban.eth registry0x38060F7B35486C4F7C8de1758d2C91f84843d5Ac
com.github.www.ketsuban.eth resolver0xae66c62AcAE72098BdAc57d8E8AED53EF000b2Ba
com.google.www.ketsuban.eth registry0xacbBc3393fA854977C30B42E1D0D276Ad492FBBE
com.google.www.ketsuban.eth resolver0xae66c62AcAE72098BdAc57d8E8AED53EF000b2Ba
com.discord.www.ketsuban.eth registry0xFd6436692Dc52ed44B35Ceae8d432604c915B096
com.discord.www.ketsuban.eth resolver0xae66c62AcAE72098BdAc57d8E8AED53EF000b2Ba
com.linkedin.www.ketsuban.eth registry0x4a1E40e86DD2f501522B4454abC1Cdd7bCd34d7B
com.linkedin.www.ketsuban.eth resolver0xae66c62AcAE72098BdAc57d8E8AED53EF000b2Ba
me.t.www.ketsuban.eth registry0x959aDF834D2C1FdD876743b40c058EC96B4DeFE5
me.t.www.ketsuban.eth resolver0x3Ac88937535374f72fCc242b2dEFE787C9D9638f
com.gmail.@.ketsuban.eth registry0x3541201C4FA762Aa5026cF002407501FA9DBBeC3
com.gmail.@.ketsuban.eth resolver0xae66c62AcAE72098BdAc57d8E8AED53EF000b2Ba
xyz.peeramid.@.ketsuban.eth registry0xb3ABB4135dE16E78Fe53fC5827Bfd9058EdE1fD6
xyz.peeramid.@.ketsuban.eth resolver0xae66c62AcAE72098BdAc57d8E8AED53EF000b2Ba
the name, in the ENS appketsuban.eth
the name, in the ENS appkju-is.ketsuban.eth

It has done it for real

a public account0x71b7edd5…
one kept private0x6af38a23…

The private one stores no handle at all: scrambled bytes and a lock only a view code opens. Nodes simulated, forwarder Chainlink's MockKeystoneForwarder; handler, signature, bridge and record real.

How SybilScore is counted

Fake accounts can vouch for each other all day. What they cannot do is be a real person.

  1. edgesevery live reference is a line, writer → subjectsigned records, nothing guessed
  2. seedspeople who passed a Selfie Checkthe one thing you cannot hold twice
  3. walktrust flows from seeds along the linesteams fill up; rings of fakes barely do
  4. ranktrust divided by connectionscollecting connections earns nothing
  5. SybilScore0–100: a real person is 20, each reference adds up to 15 of its writer's scorea newcomer starts at 0; a ring nobody proved stays at 0

A signal beside the count and the shape, never a verdict.

How a reference is read

  1. the words31 bytes somebody signedalways shown as written
  2. the councilthree AI models read them, oncethe words are data, never instructions
  3. polaritycritical … supportive, and one sentence whysame words, same reading
  4. provisionaluntil real peers have judgedno council configured → shown unread

It reads sentences, not people.

Outside the box, on purpose

  • Your World ID proof — has no secret of yours in it; World says whether it holds.
  • Reference letters — kept on this site; only their fingerprint is on chain, forever.
  • Who may read a masked account — kept on this site; opens only inside the box.

What this deployment says is wrong with it

  • the Multipass owner is the relayer key (0xF0121f93b1a1bAd73AdDC316B57684bD93D3254e): the key that signs transactions can also delete any record, so one compromise removes references this deployment calls permanent. It owns Multipass because provisioning a vouch domain is an owner call; the fix is a separate owner signer for that call, then transfer ownership to a key that signs nothing else