Live data from Hacker News

Digital forgeries are hard

mjg59.dreamwidth.org

81–90 of 102 posts

Re: Digital forgeries are hard

#81

Earlier quoted context omitted.

Don’t know how convincing it’d be in court, but Open Timestamps[1], a free service that operates by publishing Merkle tree hashes to the Bitcoin ledger and can give you independently-verifiable proofs after a while, still exists even if it doesn’t seem to be under active development. (I think Keybase tried something like that some time ago as well, they already had most of the parts in place, but then they decided to…

A good example of using bitcoin for something that was entirely possible with regular old public key cryptography. Matthew Richardson's Stamper has been running since 1995.

> Matthew Richardson's Stamper

That was hard to find. My first google searches turn up this post. Here it is, in case anyone is interested: https://www.itconsult.co.uk/stamper/stampinf.htm

In the end both are just digital signatures, and so are "entirely possible with regular old public key cryptography" as you say. You can achieve a similar effect by sending a gmail message to yourself with an sha256 of the document in the subject. The subject and date are included in the gmail DKIM signature. The cryptographic primitives used by Stamper, gmail DKIM and bitcoin are equally secure as a first approximation.

That means the security ultimately rests on the security of the key used to sign it. So do you trust Matthew Richardson to keep is gpg key secure, or Google to keep their DKIM secure, or the difficulty imposed by a proof of work where the amount of work is equal to a nation states electricity supply? I know which I'd choose out of those three, and that's the key differentiator of bitcoin. It is not the cryptographic primitives used.

Re: Digital forgeries are hard

#82
post #20
post #12

Earlier quoted context omitted.

> Are there any good solutions that would convince a non-technical judge? I feel like the best you can do is either to publish a cryptographically secure hash or to publish something encrypted and share the key/password when you want to reveal the secret.

But publish it where, though? It has to be: - Publicly accessible. - Timestamped. - Immutable (or at least with edits marked as such). - Widely trusted (or too big to be bribed in small cases, e.g., Google). - And keep those features for many years. Twitter was surprisingly good at that in the past, but no more. Blockchains, as mentioned in other comments, give excellent immutability; but the field is such a minefiel…

I'm repeating what I said above, but just send yourself an gmail with the hash in the Subject. Gmail will kindly timestamp it and provide a DKIM signature. Publish the mail headers gmail includes in the signature (which includes the timestamp and subject, but not the contents), the signature itself, and a link to hashed the document and you're done.

Re: Digital forgeries are hard

#83
post #20

Earlier quoted context omitted.

But publish it where, though? It has to be: - Publicly accessible. - Timestamped. - Immutable (or at least with edits marked as such). - Widely trusted (or too big to be bribed in small cases, e.g., Google). - And keep those features for many years. Twitter was surprisingly good at that in the past, but no more. Blockchains, as mentioned in other comments, give excellent immutability; but the field is such a minefiel…

I'm repeating what I said above, but just send yourself an gmail with the hash in the Subject. Gmail will kindly timestamp it and provide a DKIM signature. Publish the mail headers gmail includes in the signature (which includes the timestamp and subject, but not the contents), the signature itself, and a link to hashed the document and you're done.

This is only true if Google never release old private keys for DKIM signatures, which various people have been campaigning for them to do in order to provide long-term deniability around DKIM-signed mails.

Re: Digital forgeries are hard

#84
post #6

I wonder why we don't have better (widely trusted and used) timestamping services. It has always been easy to prove that something happened after a certain time: take a photo of today's newspaper, mention stock prices, etc. But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access…

Post your SHA256 hash as a comment on a Hacker News story just before the 14 day edit window expires!

The edit window is actually less than that, around 2 hours.

Re: Digital forgeries are hard

#85
post #59

Earlier quoted context omitted.

Wouldn't it be trivially easy to prove that oneself is Satoshi Nakamoto? Just signing arbitrary messages with one of the many wallet addresses from the first Bitcoins mined? Assuming of course, that those early keys didn't end up like so many: on a hard drive, in a land fill.

He claims he destroyed the keys while medicated after being released from hospital https://twitter.com/bitnorbert/status/1757745072974475270

It's unfortunate that this is annoying to read with having to expand each entry and then the content popping back up to the top. Annoying enough that I lost interest in reading it. YMMV.

Re: Digital forgeries are hard

#86
Surprised that noone mentioned Barely Sociable video on Satoshi Nakamoto[1] (last of a 3-part series). Pretty strong arguments as to why Adam Back is Satoshi, the amount of coincidences is just way too many IMO.

Craig Wright is definitely not Satoshi, the guy has some issues and so keeps claiming that he is.

[1] https://www.youtube.com/watch?v=XfcvX0P1b5g

Re: Digital forgeries are hard

#87

Earlier quoted context omitted.

He claims he destroyed the keys while medicated after being released from hospital https://twitter.com/bitnorbert/status/1757745072974475270

It's unfortunate that this is annoying to read with having to expand each entry and then the content popping back up to the top. Annoying enough that I lost interest in reading it. YMMV.

Here's the whole thread from that court day as a webpage: https://threadreaderapp.com/thread/1757676051591749813.html

Re: Digital forgeries are hard

#88

Earlier quoted context omitted.

A good example of using bitcoin for something that was entirely possible with regular old public key cryptography. Matthew Richardson's Stamper has been running since 1995.

> Matthew Richardson's Stamper That was hard to find. My first google searches turn up this post. Here it is, in case anyone is interested: https://www.itconsult.co.uk/stamper/stampinf.htm In the end both are just digital signatures, and so are "entirely possible with regular old public key cryptography" as you say. You can achieve a similar effect by sending a gmail message to yourself with an sha256 of the document…

Stamper signs and automatically publishes hashes of its history. It is a "block chain" in that sense: If Richardson decided to use the keys to backdate something to two years ago, he would have to fake two years of history, and risk being exposed if even one person came forward with a hash he'd signed contradicting his new fake history.

That is presumably one of the reasons that hasn't happened in the roughly 30 years the service has been ticking along.

Re: Digital forgeries are hard

#89
post #14

Earlier quoted context omitted.

I always wonder about people like Wright... how does such a brain work? Why would one invest so much of his life and reputation on brazen lies and forgeries? He's been caught so many times, surely nobody can take him seriously anymore, it's over, time to move on - but here he is, forging emails and logs, digging deeper and deeper, turning his life more and more into a farce. Why?

There's pretty broad consensus that Craig Wright is a pathological liar. And I'm not using that as an idiom for "dishonest person", I mean it in the psychiatric term of art sense [0]: he probably has an actual compulsion to lie stemming from some kind of psychological damage, which doesn't stop even when he's caught red-handed (he just invents new even more outrageous lies, even when that's nakedly against his own se…

I've known a pathological liar. The thing is because people tend to default to trusting, especially because pathological liars will lie about things most reasonable people would not expect anyone to lie about, they will get away with it for a good amount of time (varying by how good they are at it). But their credibility in a given group quickly crumbles once one or two lies are exposed. Often they will then move on somewhere else where they repeat the progress.

Re: Digital forgeries are hard

#90
post #6

I wonder why we don't have better (widely trusted and used) timestamping services. It has always been easy to prove that something happened after a certain time: take a photo of today's newspaper, mention stock prices, etc. But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access…

If only there was some sort of globally distributed, cryptographically verified database of some sort that could be used for this purpose …

The CT logs are a nifty place for this sort of thing!
Post reply on HN