#merkle-root
Twelve years after launching Universal SSL, Cloudflare is applying to become a certificate authority. By combining an established root, an ACME-first approach, and Merkle Tree Certificates, we are building a post-quantum CA for the open web. https://cfl.re/4rA7ECu #BirthdayWeek
Building a certificate authority for the whole Internet
Today we are announcing the first concrete milestones in that effort: We have applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs, and we have signed a definitive agreement to acquire an established, broadly trusted root from GlobalSign.
blog.cloudflare.com
September 29, 2026 at 1:05 PM
signed merkle tree root hash in the streets, unsigned lthash set-hash digest in the sheets
August 11, 2026 at 4:16 AM
I learned about merkle tree root hash in D.A.R.E.
anybody remember when that one fediverse guy said that atproto repo migrations are computationally expensive because your new server has to re-sign every record with your new signing key even though that was a flat-out lie and you literally only need to sign the merkle tree root hash
September 6, 2024 at 4:25 AM
well it's not much cause you're just re-signing one merkle root
September 11, 2025 at 10:57 PM
a zip of json with a signed merkle root
November 4, 2025 at 3:13 AM
in atproto you can wipe a repo with a single commit that sets an empty merkle root 😎 (also the #tombstone op)
March 2, 2024 at 3:57 PM
merkle root would be a beautiful name for a vegetable
June 25, 2024 at 8:24 PM
Bitcoin Historical Original

3BA3EDFD7A7B12B27AC72C3E67768F617FC81BC3888A51323A9FB8AA4B1E5E4A.btc

The Genesis Block’s Merkle Root in internal little-endian byte order.
September 28, 2026 at 10:47 PM
比特币历史原件

3BA3EDFD7A7B12B27AC72C3E67768F617FC81BC3888A51323A9FB8AA4B1E5E4A.btc

比特币创世区块 Merkle Root 的内部小端序表示,即原始区块头中实际存储的字节序。
它与常规显示的 Merkle Root 是同一个值的不同字节序表示。
September 28, 2026 at 10:47 PM
Right so AFAIK the PDS won't sign an arbitrary message. It will only sign its merkle tree root. You can prove that any entry in the tree is in that merkle tree root (including on-chain).

Entries in the tree also can't be arbitrary data, but you can customize what they are with your own lexicon
May 28, 2025 at 6:53 AM
the repo is a kind of merkle tree w/ a signed root. events on the firehose contain the following:
- the new blocks added to the repo tree
- a description of the write (e.g. "key K changed from value A to B")

the hard part: do these two match and apply cleanly on the prev state of the repo? 3/10
February 24, 2025 at 5:58 PM
anybody remember when that one fediverse guy said that atproto repo migrations are computationally expensive because your new server has to re-sign every record with your new signing key even though that was a flat-out lie and you literally only need to sign the merkle tree root hash
September 6, 2024 at 4:19 AM
we'd still have some sort of commitment over record contents. still nailing down the exact mechanism, but something like: merkle tree root, XOR of record hashes, ECMH hash, rolling hash, etc

then HMACing that which allows for repudiation unlike an asymmetric signature
February 26, 2026 at 6:58 PM
yes, and "Merkle tree is not served from PDS with dangling pointers, if you can't get all the hashes reachable from the root it implies something is wrong" is an actually-important censorship resistance property
February 8, 2026 at 1:45 AM
With deterministic serialisation, combined with the Merkle part of the MST, the entire repo state can be boiled down to a single hash (the MST root), which can easily be cryptographically signed as part of a "commit" object atproto.com/specs/reposi...
Repository - AT Protocol
Self-authenticating storage for public account content
atproto.com
November 9, 2024 at 4:45 PM
Also I think my framing here collapses the two protocols a little bit maybe? Watch in awe as I maintain both a merkle tree root and LtHash digest for the same atproto repository! Behold and despair as I sync spaces over the public atproto firehose!
What is an atproto repository?
One repo, multiple sync methods
iameli.leaflet.pub
July 23, 2026 at 11:19 PM
iirc the commit cid and rkey refer to the signed root of the merkle tree, not the record you're checking the merkle proof of
June 11, 2025 at 4:17 AM
can't believe people still don't get this. it's simple. you just have to synthesize a metaprogrammed firehose client from the lexicon schema, parse the event block CARs and walk the merkle search tree to validate the signature of the root hash, after resolving the DID's pubkey from the PLC directory
mussar.io mussar @mussar.io · Jul 19
just dunk on me for not understanding why the feed generator is set up the way it is
July 19, 2023 at 4:17 PM
we just shipped workflow receipts at Zambo: one verifiable receipt for a whole multi-step run. each step's receipt hash goes into a Merkle tree, one root to recompute. live example: https://zambo.dev/workflow/07e02e55-ab7f-5dbd-a35c-962baaa00c6e free tier, 20 calls/tool/day, no account.
September 25, 2026 at 9:35 AM
*publish the merkle root, not the whole tree.
July 22, 2025 at 7:38 PM
The repository has a Merkle tree root, which is signed. So you can authenticate the root then validate posts against it, without having the full repo (but it's easier to have the full repo for many operations)
October 15, 2024 at 4:50 AM
Seal a file so no one can dispute you didn't touch it | Xiliux Blog

A single hash forces you to reveal the whole set to prove one file. A Merkle tree doesn't.

https://xiliux.com/en/blog/sellar-evidencia-digital-firma-post-cuantica
September 25, 2026 at 3:42 PM
a blockchain is a merkle dag plus a consensus mechanism

each user's pds is a merklization of their account state, and the did signing the merkle root is the consensus mechanism, so you could view it as a forest of blockchains if you wanted
April 28, 2023 at 8:42 PM
we smokin on that hash that made the merkle tree root
September 6, 2024 at 4:22 AM