Security threat model
Evidence Threats
Cryptographic integrity does not eliminate bad evidence. ENTITY's evidence layer must defend against both byte tampering and semantic misrepresentation.
Threats
- Substituted source artifact with a valid signature over the wrong thing.
- Attester with no authority for the claim.
- External anchor substitution or stale anchor interpretation.
- Selective omission of contrary evidence.
- Reusing evidence for a broader claim than it supports.
- Confusing provenance with ownership/truth.
- Changing profile semantics after issuance.
Controls
Content-address evidence, record scope/source, verify attester authority, pin external references where possible, retain contrary/superseding evidence, preserve versioned interpretation rules and state conclusions narrowly.
Economic threat
Do not convert an evidence link into a monetary contribution weight without an explicit attribution method or term. Unknown value should remain unknown/zero rather than fabricated.