I wonder why we don't have better (widely trusted and used) timestamping services. It has always been easy to prove that something happened after a certain time: take a photo of today's newspaper, mention stock prices, etc. But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access…
Digital forgeries are hard
31–40 of 102 posts
Re: Digital forgeries are hard
#32I wonder why we don't have better (widely trusted and used) timestamping services. It has always been easy to prove that something happened after a certain time: take a photo of today's newspaper, mention stock prices, etc. But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access…
If you know you're going to have to prove it, there are loads of options. Absolutely loads.
The issue is simply that this guy's a fraud so he's gotta come up with a story about why he didn't use any of them.
Re: Digital forgeries are hard
#33I wonder why we don't have better (widely trusted and used) timestamping services. It has always been easy to prove that something happened after a certain time: take a photo of today's newspaper, mention stock prices, etc. But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access…
> Are there any good solutions that would convince a non-technical judge? I feel like the best you can do is either to publish a cryptographically secure hash or to publish something encrypted and share the key/password when you want to reveal the secret.
Judges can be aided by expert reports.
And not all judges are non-technical.
The fact that you can defend your documents with timestamps is often enough: the other side won't challenge them knowing that they are likely to lose the challenge.
Re: Digital forgeries are hard
#34There's also been a few cases over the years of forged documents being spotted by changing MS Word font defaults: One example: https://gulfnews.com/world/asia/pakistan/calibri-controversy...
They could've easily used Times New Roman like their teachers probably instructed them. /hj
Re: Digital forgeries are hard
#35Holy smokes isn’t forging evidence a crime? Even if it’s hard to prove exactly that he did it, there’s a strong motive and means and a lot of pretty shocking evidence of forgery here.
He left court on a Friday, did the email forgery in the article over the weekend, and was back in court on Monday. Forging evidence is always bad, but doing it during the trial in response to something he was cross-examined on? That has to be particularly bad.
Maybe that won't be treated as seriously as it should be because people don't realize that it very much could have worked!
Re: Digital forgeries are hard
#36Reality: Casual forgery is pretty easy. Forgery that will stand up to expert examination is very hard. And impossible if you're a bungling incompetent, as this guy seems to be.
One thing I've realized during the case is that the kind of scrutiny people apply when they get handed a document as "proof" is not the same as the scrutiny they'd apply if handed a document they know is fake and they simply need to find proof.
In the former case people just tend to confirmation bias themselves, they check a few things and say "yep checks out". While in the latter case, they'll much more quickly say "well if it's authentic, then all the version numbers should check out, lemme go check those".
The former kind of check is almost completely ineffective against an intentional forgery unless it was made by someone dramatically less competent that you. Validation for "proof" sake must use the second process of assuming it false and looking for the evidence of it.
There is nothing fundamentally wrong with accepting a document on its face, but you shouldn't deceive yourself that you've validated something. If someone is giving you a document to prove something then you have to accept a serious possibility that it was fake, otherwise why bother looking at the document at all?
Re: Digital forgeries are hard
#37I wonder why we don't have better (widely trusted and used) timestamping services. It has always been easy to prove that something happened after a certain time: take a photo of today's newspaper, mention stock prices, etc. But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access…
For most purposes, mailing something to yourself for the postmark and keeping the envelope sealed would probably be adequate. It's possible to forge, but tricky enough.
Note that you need to send First Class to get a postmark in the US - not standard Priority Mail.
Re: Digital forgeries are hard
#38I wonder why we don't have better (widely trusted and used) timestamping services. It has always been easy to prove that something happened after a certain time: take a photo of today's newspaper, mention stock prices, etc. But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access…
The judge in this case is actually very technical so that's not a problem.
Regardless, the easiest and most direct way to timestamp something is to use the standard RFC 3161 timestamping servers. There are many, located in different countries and run by different people, and the format is straightforward and standardized. Support is built in to products like Acrobat. You can attach multiple timestamps from different sources to a single file. They are free. It can be explained to non-technical people in a not extreme amount of time, and courts / law firms in any country can easily find expert witnesses who can verify such timestamps and testify to the court as to their veracity.
For emails there's also DKIM, which signs email including the date header. Again, plenty of people who can verify those signatures, so emailing something to someone else and then getting a copy of the raw email will do it (don't email to yourself, that skips the signing process).
Disclosure: I took part in this trial as a witness and testified against Wright.
Re: Digital forgeries are hard
#39Wow this guy is a prolific forger! Not knowing the details of the case, doesn't he risk getting a book thrown at him for introducing forged evidence?
Re: Digital forgeries are hard
#40Earlier quoted context omitted.
I always wonder about people like Wright... how does such a brain work? Why would one invest so much of his life and reputation on brazen lies and forgeries? He's been caught so many times, surely nobody can take him seriously anymore, it's over, time to move on - but here he is, forging emails and logs, digging deeper and deeper, turning his life more and more into a farce. Why?
There's pretty broad consensus that Craig Wright is a pathological liar. And I'm not using that as an idiom for "dishonest person", I mean it in the psychiatric term of art sense [0]: he probably has an actual compulsion to lie stemming from some kind of psychological damage, which doesn't stop even when he's caught red-handed (he just invents new even more outrageous lies, even when that's nakedly against his own se…
It's true that most people consider Wright a silly clown these days, but the chilling effect against Bitcoin development is hard to quantify and, I think, wholly real. This is why his latest loss makes today a good day.