aai-institute / aai-institute/practical-ai-act

Record-keeping: no operational guidance on showing a log was not altered

Đang mở Phù hợp với người mới
#151 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Python
Star
21
Fork
3
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

The record-keeping page explains the Article 12 obligation clearly, including that logs need to be tamper-evident. What I could not find, here or anywhere else, is the next step: what a team actually builds so that a log can be shown not to have been altered, and by whom.

The distinction that seems to be missing everywhere is **altered by whom**. A hash chain detects an outsider's edit and proves nothing against the party that wrote the record, which is the party a deployer's own auditor is asking about. Most guidance treats those as the same property.

I have written that up:

https://machinetestimony.org/tamper-evidence/

It compares append-only storage, hashes, hash chains, signatures, RFC 3161 timestamps and transparency logs, and says what each proves and against whom. It gives runnable commands, including the verification failure and what that failure does not tell you, and it is explicit that none of it establishes that a record is true, complete, or the only one produced.

It is not about any particular format and works with whatever a reader already logs.

If it is useful, a link from the record-keeping page might save somebody the search. If it duplicates something you already have, or you would rather not link out, no reply needed and no offence taken.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Find the record-keeping page in the repository, likely in the docs or content directory. The task is to add a link to the external article https://machinetestimony.org/tamper-evidence/ in the appropriate section. Verify the link works and the context fits, then propose the change.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Lĩnh vực
documentation
Loại issue
Tài liệu
Độ khó
1/5
Thời gian dự kiến
Dưới một giờ
Mức độ hoạt động
Sôi nổi
Độ rõ ràng
Đặc tả rõ ràng
Mức phù hợp với người mới
85/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.