DEV Community

Andrew Cluev for Ecode

Posted on

How to timestamp your code without sharing the source

When you need to document a particular version of your software, keeping the exact files matters. A timestamp associated with a file's digital fingerprint can add a separate record of when that fingerprint existed.

Here is how this works, and what you should keep.

A fingerprint instead of your source code

A SHA-256 hash is a digital fingerprint calculated from a file's contents. Even a small change will generally produce a different fingerprint.

A timestamp can be associated with that fingerprint without publishing the file itself. Later, you can calculate the fingerprint of your saved file again and compare it with the recorded value.

Preserve the original file. A certificate cannot recover lost source code.

How Ecode uses this approach

Ecode is a free code registration service. Your source code stays on your device, while its SHA-256 fingerprint is registered.

The service combines three records:

  • Database. A registration entry.
  • Timestamp. A timestamp using the RFC 3161 standard.
  • Blockchain. A record on Polygon.

You receive a certificate with verification information.

What to keep with your registration

Keep the exact file you registered, the certificate, and any associated verification files. Back them up separately from your working copy.

If you change the code, register the new version separately. Give each saved version a clear name so you can match it to the correct certificate.

What the record establishes

A timestamp helps document the existence of a particular fingerprint at a particular time. It does not, by itself, identify who wrote the code.

Keep supporting materials such as development history, drafts, contracts, and relevant correspondence.

Try it and share your feedback

You can register a code file with Ecode for free.

We would welcome feedback on the registration process and certificate verification.

Which step needs a clearer explanation?

Top comments (0)