Cybersecurity still depends heavily on centralised systems and trusted third parties to address the trust dilemma (“can I trust you?”) and the identity dilemma (“are you who you say you are?”). These central authorities remain necessary in society and technology, yet their design creates systemic weaknesses: they become single points of failure, prime targets for advanced persistent threats, and susceptible to insider abuse through mismanaged privileged access. Traditional “walled garden” network zones can even create a dangerous illusion of safety, while trust delegation (e.g., via certificate authorities) rests on the unverified assumption that the delegate is impartial and uncompromised.
Blockchains introduce a decentralised, distributed, tamper-evident, append-only log whose integrity is maintained by algorithmic consensus and chained hashes, offering mathematical proof where trust was previously implicit. This supports traceability, independently verifiable auditing, improved integrity assurance, and resilience through elimination of single points of control and compromise. However, blockchains are not a universal replacement for centralised trust, nor do they solve human identification and contextual identity challenges; hybrid systems combining centralised and decentralised components are portrayed as the likely path forward.
The text distinguishes decentralised from merely distributed systems, argues blockchains should be understood as an immature platform/protocol family rather than a database or standalone application, and warns against hype-driven adoption. Promising cybersecurity use cases include strengthening DNS and PKI, device integrity and configuration management (especially for IoT/Identity of Things), real-time security intelligence, and tamper-evident logging for internal and cross-organisational audits. Key challenges include access control and privacy in transparent logs, incentive design, consensus performance costs, and new attack classes (e.g., 51% and selfish miner attacks). The overall stance is cautious experimentation: start with low-risk, high-value integrity and auditability use cases while maintaining core security fundamentals.
See All Locations
See All Locations