The Soji Library — signing key

Published here so it does not travel with the archive it verifies.

The key

ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIH069xDSHbVc7Pz/M0J3pLSAsPUWgzs8MmnyuzTY+wYO soji-archive-signing
fingerprint  SHA256:aw6V5X1oRx19BCPc6/qiRB78USDEIkI+hvgPi6zBhBo
type         ED25519
signer       michaelarthurtremblay@gmail.com

Why this page exists

Every sealed copy of the archive carries a signature, and a file naming the key that made it. Checking the signature using only files found inside the archive proves nothing: anyone able to alter the archive can also replace that file with a key of their own and re-sign everything. It would all match.

So the key is written down somewhere the archive cannot reach. This is one of those places.

How to use it

Compare the fingerprint above against allowed_signers inside the archive.

They match — the signature check inside the archive means what it says.
They differ — stop. The archive has been re-signed by someone else. This page is the copy to trust, not the archive's.

Nothing here is secret. This key can only check signatures, never make them. Publishing it is the intended use.

Other copies of this same statement

On paper with the vault backup; captured by the Internet Archive so this page cannot be quietly edited later; and stamped into the Bitcoin blockchain via OpenTimestamps, which depends on no company continuing to exist. Four copies, four different ways to fail — and any one survivor exposes a forgery of the rest.