Live data from Hacker News

Digital forgeries are hard

mjg59.dreamwidth.org

61–70 of 102 posts

Re: Digital forgeries are hard

#61
post #59
post #15

This is about Faketoshi Notamoto, right? click Yup. This guy is a pathological forger and is bad at it. Here's my write-up from when he got caught doing naughty things with ECDSA: https://rya.nc/sartre.html (as noted by another commenter, "pathological" is literal in this case)

Wouldn't it be trivially easy to prove that oneself is Satoshi Nakamoto? Just signing arbitrary messages with one of the many wallet addresses from the first Bitcoins mined? Assuming of course, that those early keys didn't end up like so many: on a hard drive, in a land fill.

He claims he destroyed the keys while medicated after being released from hospital https://twitter.com/bitnorbert/status/1757745072974475270

Re: Digital forgeries are hard

#62
post #6

I wonder why we don't have better (widely trusted and used) timestamping services. It has always been easy to prove that something happened after a certain time: take a photo of today's newspaper, mention stock prices, etc. But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access…

> Are there any good solutions that would convince a non-technical judge? The judge in this case is actually very technical so that's not a problem. Regardless, the easiest and most direct way to timestamp something is to use the standard RFC 3161 timestamping servers. There are many, located in different countries and run by different people, and the format is straightforward and standardized. Support is built in to…

Note that DKIM does not necessarily sign the message contents. [1] DKIM is only really (in a general sense) intended to provide cryptographic proof that the originating server is permitted to send it. If you need a non-reputable, dated message, you really should use time stamping servers.

[1] https://en.wikipedia.org/wiki/DomainKeys_Identified_Mail#Con...

Re: Digital forgeries are hard

#63
post #8

Wow this guy is a prolific forger! Not knowing the details of the case, doesn't he risk getting a book thrown at him for introducing forged evidence?

Yes. He is at grave risk of the Crown Prosecution Service making an example of him, which could result in jail time.

No doubt he expects to be able to talk his way out of that.

Re: Digital forgeries are hard

#65
post #6

I wonder why we don't have better (widely trusted and used) timestamping services. It has always been easy to prove that something happened after a certain time: take a photo of today's newspaper, mention stock prices, etc. But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access…

Don’t know how convincing it’d be in court, but Open Timestamps[1], a free service that operates by publishing Merkle tree hashes to the Bitcoin ledger and can give you independently-verifiable proofs after a while, still exists even if it doesn’t seem to be under active development. (I think Keybase tried something like that some time ago as well, they already had most of the parts in place, but then they decided to…

A good example of using bitcoin for something that was entirely possible with regular old public key cryptography. Matthew Richardson's Stamper has been running since 1995.

Re: Digital forgeries are hard

#66
post #6

I wonder why we don't have better (widely trusted and used) timestamping services. It has always been easy to prove that something happened after a certain time: take a photo of today's newspaper, mention stock prices, etc. But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access…

> Are there any good solutions that would convince a non-technical judge? The judge in this case is actually very technical so that's not a problem. Regardless, the easiest and most direct way to timestamp something is to use the standard RFC 3161 timestamping servers. There are many, located in different countries and run by different people, and the format is straightforward and standardized. Support is built in to…

Yeah it's odd to see a bunch of people proposing ideas for cryptographic timestamps (on the blockchain!) when anyone who has worked with digital signatures should know about RFC3161.

Of course for verification it's important that the timestamp countersignature comes from a reputable CA and not some random server you set up.

Re: Digital forgeries are hard

#67
post #46

A more serious case of this took place in Turkey two decades ago, and involved the jailing of a significant fraction of the military leadership. So it amounted to a judicial coup against the military. The son-in-law of one of the generals (Cetin Dogan) analyzed a piece of the evidence, a Word document ostensibly dated 2003, and proved that it contained anachronisms dating it to at least 2007. https://en.wikipedia.org…

Turkish Rathergate?

Re: Digital forgeries are hard

#68
post #52

Earlier quoted context omitted.

For most purposes, mailing something to yourself for the postmark and keeping the envelope sealed would probably be adequate. It's possible to forge, but tricky enough.

you realise it is possible to mail unsealed, open envelopes, right? doesn't seem that tricky...

You seal the envelope with tape and put the stamp over the tape.

Re: Digital forgeries are hard

#69
post #59
post #15

This is about Faketoshi Notamoto, right? click Yup. This guy is a pathological forger and is bad at it. Here's my write-up from when he got caught doing naughty things with ECDSA: https://rya.nc/sartre.html (as noted by another commenter, "pathological" is literal in this case)

Wouldn't it be trivially easy to prove that oneself is Satoshi Nakamoto? Just signing arbitrary messages with one of the many wallet addresses from the first Bitcoins mined? Assuming of course, that those early keys didn't end up like so many: on a hard drive, in a land fill.

Indeed. Which makes all his subsequent contortions all the more absurd.

Re: Digital forgeries are hard

#70

Earlier quoted context omitted.

There's pretty broad consensus that Craig Wright is a pathological liar. And I'm not using that as an idiom for "dishonest person", I mean it in the psychiatric term of art sense [0]: he probably has an actual compulsion to lie stemming from some kind of psychological damage, which doesn't stop even when he's caught red-handed (he just invents new even more outrageous lies, even when that's nakedly against his own se…

From watching the trial, it does seem to be an innate behavior for him, effortlessly spinning "plausible" stories to account for everything he's challenged on, that would sound convincing to somebody without the technical knowledge to understand what he's talking about.

I haven't watched it but surely, hopefully pathological lying in court can get someone in real trouble regarding perjury instead of just the case being lost
Post reply on HN