This is about Faketoshi Notamoto, right? click Yup. This guy is a pathological forger and is bad at it. Here's my write-up from when he got caught doing naughty things with ECDSA: https://rya.nc/sartre.html (as noted by another commenter, "pathological" is literal in this case)
Digital forgeries are hard
91–100 of 102 posts
Re: Digital forgeries are hard
#92Re: Digital forgeries are hard
#93Earlier quoted context omitted.
IIRC the fishing link used for the hack pointed to a mainstream URL shortener; and the account that owned that shortened URL used in the fishing op was associated with other URLs dating years back used for fishing campaigns against russian journalists and dissidents. Hence, pretty strong reasons to suspect Russian state involvment.
Are you thinking of this story? https://www.wired.com/2017/05/russian-hackers-using-tainted-... Those phishing emails and links are distinct from the DNC leak
Re: Digital forgeries are hard
#94I wonder why we don't have better (widely trusted and used) timestamping services. It has always been easy to prove that something happened after a certain time: take a photo of today's newspaper, mention stock prices, etc. But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access…
Re: Digital forgeries are hard
#95Earlier quoted context omitted.
You seal the envelope with tape and put the stamp over the tape.
You send the envelope unsealed, then seal & stamp it later.
You put postage on the letter, and the post office stamps the postage (to invalidate the postage). The stamp contains a date. You can't stamp something after having mailed it, that happens as part of the mail submission.
Re: Digital forgeries are hard
#96A more serious case of this took place in Turkey two decades ago, and involved the jailing of a significant fraction of the military leadership. So it amounted to a judicial coup against the military. The son-in-law of one of the generals (Cetin Dogan) analyzed a piece of the evidence, a Word document ostensibly dated 2003, and proved that it contained anachronisms dating it to at least 2007. https://en.wikipedia.org…
Even with homework done I'd never attempt it for the same reasons that Matthew Garrett outlined in his article.
However, assume a hypothetical case where I had to forge a document what would I do? My first thought would be to obtain a pensioned-off PC complete with operating system, user apps such as MS Office/Word and standard default fonts that was last used a little before the date of my intended forgery.
Obtaining such a PC may seem like a tall order but it might not be as difficult as it seems, but it certainly won't be easy. I say that it's possible by just looking at my own situation. In my shed I have a stack of old PCs gathering dust that haven't been switched on in several decades, no doubt there are many similar piles of junk out there in user-land that can be tapped for a suitable PC.
Next, I'd ensure the PC was not switched on until I'd removed the hard disk and forensically mirrored it to a backup on another PC. The mirrored disk image can then be examined to determine the exact date when it was last used, etc., etc.
Without reinstalling the hard disk and before switching it on I'd disconnect the PC's clock battery and or short out the clock operation so the clock was set to the factory default time (I.e. not set). I'd then switch on and set the date in the BIOS slightly ahead of the last date the PC was last switched on (that date I'll have already determined from my forensic analysis of the mirrored image).
After reinstalling the HD I'd switch on and hopefully I'd have functional PC whose date and time would indicate that it was switched on shortly after the actual time it was last used.
At this point and before proceeding further I'd take another mirror image of the HD and compare it with the original for any gotchas. Unless something goes awry I'll use this second mirror for all future installations and any necessary tweaks.
My next step would be to draft out the forged text by hand on paper. I'd study this text with great care to ensure that I've the precise wording and that there are no references to forward dates or events that could not have happened by the date of the forgery. I'll then sit on the text for 24 hours or more to think about it just to make sure that everything I've written is as 'faultless' as is possible.
Assuming all's well and only then will I switch on the PC and use the installed copy of MSO/Word with one of the common already-installed typefaces such as Ariel or Times New Roman to type my text.
Even then, with all that done, I'd still be shitting myself that I'd not fully covered my tracks!
Note: that's the short version, there are many other intermediate checks too detailed to mention here. Some of these steps may require minor tweaks to the second mirror (metadata changes, etc.) before it's mirrored back to the original HD. Any edits to the second mirror should only be done after it's been backed up.
Doing these checks and ensuring that one's covered one's tracks isn't for the feinthearted. Right, the stakes have to be extraordinarily high to even bother attempting such a job.
_
Edit: if the forgery is to appear in printed form then it should be printed on old stock paper with a printer of the same era, say a HP LaserJet III for instance. Even with expertise, artificially aging such a document is a complicated process and even then it's unlikely to pass muster with a basic forensic analysis.
Another approach is to do the above then photocopy the original then 'lose' it and only use the copy. Recopying the copy on multiple machines of different brands will make tracing the original photocopier more difficult as each machine will have optics with minor distortions that are different to one another. Faxing the document sans headers will further obfuscate where the copy originated as faxes are of low resolution and introduce artifacts noise, but keep in mind that the mechanics and optics of fax machines introduce the same type of distortions as photocopiers.
Again, don't bet your chances, if you use these methods then smart forensics are still likely to nab you.
Re: Digital forgeries are hard
#97I wonder why we don't have better (widely trusted and used) timestamping services. It has always been easy to prove that something happened after a certain time: take a photo of today's newspaper, mention stock prices, etc. But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access…
Re: Digital forgeries are hard
#98(Assuming this is the same case; I haven't been following Craig Wright closely) It looks like the case was very swiftly decided against Wright. Here's reporting from The Guardian about it today: https://www.theguardian.com/technology/2024/mar/14/australia...
I always wonder about people like Wright... how does such a brain work? Why would one invest so much of his life and reputation on brazen lies and forgeries? He's been caught so many times, surely nobody can take him seriously anymore, it's over, time to move on - but here he is, forging emails and logs, digging deeper and deeper, turning his life more and more into a farce. Why?
Ha, wouldn't it be funny if Wright actually had the last laugh and that his claim that he's Satoshi Nakamoto was meant to have holes so that he would be discredited.
The whole saga of Satoshi Nakamoto and Bitcoin is so odd and unbelievable and fraught with so many open-ended questions one has to wonder what's true and what's not. The only thing for certain is that Bitcoin is real and that someone actually invented it.
Why would Satoshi Nakamoto bother obfuscate facts and hide himself, what would be his motive and what would he achieve by so acting? Even if unlikely it's completely plausible that Wright is Satoshi Nakamoto and that his seemingly shoddy claims about being him is actually part two of some strange hoax that he's cooked up.
Unlikely for sure, but if he is Satoshi Nakamoto then his place in history will be assured for certain, he'll be remembered for a double whammy that'll never be forgotten: the genius of Bitcoin and block chain cryptocurrency, and the biggest king-sized hoax/con job of all time.
Clearly Wright is smart but he could be smarter than we give him credit for. Wright's ego may be such that he wants an assured high place in history, if so then what better way to achieve that than to act as he has done?
Eventually the true identity of Satoshi Nakamoto will be revealed and someone will have that last laugh.
Re: Digital forgeries are hard
#99A more serious case of this took place in Turkey two decades ago, and involved the jailing of a significant fraction of the military leadership. So it amounted to a judicial coup against the military. The son-in-law of one of the generals (Cetin Dogan) analyzed a piece of the evidence, a Word document ostensibly dated 2003, and proved that it contained anachronisms dating it to at least 2007. https://en.wikipedia.org…
You'd think by now that everyone—especially those who'd intend forging documents—would be aware of the 'mismatched' font problem but it appears not because it's happened in significant numbers of high profile cases in the past. Simply, these forgers haven't done their necessary homework. Even with homework done I'd never attempt it for the same reasons that Matthew Garrett outlined in his article. However, assume a h…
I'm reminded of that scene in mindhunter where the detectives go to Kemper something like "this theory is unsupported by the data we've collected on serial killers." And kemper calmly responds "Seems to me all of the data you've gathered is from serial killers you're caught."
Kemper believes there are many serial killers undiscovered, and more importantly easily able to avoid detection (as he did) unless they turn themselves in. This is while the fbi is speculating profiles of an active serial killer.