Live data from Hacker News

Digital forgeries are hard

mjg59.dreamwidth.org

21–30 of 102 posts

Re: Digital forgeries are hard

#21
post #13
post #6

I wonder why we don't have better (widely trusted and used) timestamping services. It has always been easy to prove that something happened after a certain time: take a photo of today's newspaper, mention stock prices, etc. But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access…

This is/could be a legitimate use of blockchain, e.g. see https://gwern.net/timestamping

Oh, there's a Gwern page about that. That's perfect, thanks for the link.

Re: Digital forgeries are hard

#23
post #10

Holy smokes isn’t forging evidence a crime? Even if it’s hard to prove exactly that he did it, there’s a strong motive and means and a lot of pretty shocking evidence of forgery here.

He left court on a Friday, did the email forgery in the article over the weekend, and was back in court on Monday. Forging evidence is always bad, but doing it during the trial in response to something he was cross-examined on? That has to be particularly bad.

Re: Digital forgeries are hard

#24
This reminds me of a paper[0] whose thesis is "We enumerate the requirements that a censorship-resistant system must satisfy to successfully mimic another protocol and conclude that “unobservability by imitation” is a fundamentally flawed approach." It relates to censorship-resistant communication systems such as SkypeMorph, StegoTorus, and CensorSpoofer which aim to evade censors’ observations by imitating common protocols like Skype and HTTP.

This is essentially "digital forgery" at the protocol level. I wonder if the thesis could be shown to be generalizable to most digital forgery, or even forgery in general.

0: https://people.cs.umass.edu/~amir/papers/parrot.pdf

Re: Digital forgeries are hard

#25
post #6

I wonder why we don't have better (widely trusted and used) timestamping services. It has always been easy to prove that something happened after a certain time: take a photo of today's newspaper, mention stock prices, etc. But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access…

For most purposes, mailing something to yourself for the postmark and keeping the envelope sealed would probably be adequate. It's possible to forge, but tricky enough.

Re: Digital forgeries are hard

#26
post #20
post #12

Earlier quoted context omitted.

> Are there any good solutions that would convince a non-technical judge? I feel like the best you can do is either to publish a cryptographically secure hash or to publish something encrypted and share the key/password when you want to reveal the secret.

But publish it where, though? It has to be: - Publicly accessible. - Timestamped. - Immutable (or at least with edits marked as such). - Widely trusted (or too big to be bribed in small cases, e.g., Google). - And keep those features for many years. Twitter was surprisingly good at that in the past, but no more. Blockchains, as mentioned in other comments, give excellent immutability; but the field is such a minefiel…

Take out a personal ad in a newspaper.

Re: Digital forgeries are hard

#27
post #20
post #12

Earlier quoted context omitted.

> Are there any good solutions that would convince a non-technical judge? I feel like the best you can do is either to publish a cryptographically secure hash or to publish something encrypted and share the key/password when you want to reveal the secret.

But publish it where, though? It has to be: - Publicly accessible. - Timestamped. - Immutable (or at least with edits marked as such). - Widely trusted (or too big to be bribed in small cases, e.g., Google). - And keep those features for many years. Twitter was surprisingly good at that in the past, but no more. Blockchains, as mentioned in other comments, give excellent immutability; but the field is such a minefiel…

It's funny given the context of this case that this would be one of the rare times when using a blockchain would have actually been useful

Re: Digital forgeries are hard

#28
post #20
post #12

Earlier quoted context omitted.

> Are there any good solutions that would convince a non-technical judge? I feel like the best you can do is either to publish a cryptographically secure hash or to publish something encrypted and share the key/password when you want to reveal the secret.

But publish it where, though? It has to be: - Publicly accessible. - Timestamped. - Immutable (or at least with edits marked as such). - Widely trusted (or too big to be bribed in small cases, e.g., Google). - And keep those features for many years. Twitter was surprisingly good at that in the past, but no more. Blockchains, as mentioned in other comments, give excellent immutability; but the field is such a minefiel…

Publish a document hash in the newspaper classifieds. Media should still be getting permanently archived by National Archive or Internet Archive.

Re: Digital forgeries are hard

#29
post #6

I wonder why we don't have better (widely trusted and used) timestamping services. It has always been easy to prove that something happened after a certain time: take a photo of today's newspaper, mention stock prices, etc. But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access…

There used to be a service that published your hashes in the New York Times. Satoshi must have known about it because it is mentioned in the Bitcoin paper.

Re: Digital forgeries are hard

#30
This is a great point that hasn't been aired enough. I'm thrilled to see outsiders reading the expert reports-- which are themselves fascinating reading.

I'm one of Wright's defendants and have spent the last several years of my life trapped in this involuntary puzzle hunt.

Often people read the conclusions on the documents and say "man this guy Wright is a total idiot"-- and while I don't disagree with the sentiment, it's the wrong conclusion to draw from the documents.

These debunks seem simple once they've been pointed out to you. But the problem that a forger has is that they must get EVERYTHING exactly right. The anti-forger, on the other hand, need only identify one solid flaw.

Wright's stupidity wasn't so much in any particular error (okay, well a couple were kinda dumb: like backdating documents by robotically replacing all past tense with future tense, turning him into nostradumbass.)-- but the scale meant that it was inevitable the he would make errors.

Unfortunately he's been learning and for the most part his later forgeries had a lot less metadata to go on. If he gets too many more tries he may be able to start producing unfalsifiable forgeries. I'm really homing the judgement is forceful enough to meaningfully shut him down.

Post reply on HN