Hash-chained audit logs require external verification to prove tampering
A hash-chained audit log within a single database cannot detect a complete rewrite by someone with write access to that database. The cryptographic chain only proves internal consistency, allowing a forger to recompute the entire chain after altering any record. To detect tampering, the log's final hash must be stored outside the attacker's control. This external 'head' value creates a fixed point to verify the log's history against.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in