Live data from Hacker News

Digital forgeries are hard

mjg59.dreamwidth.org

101–102 of 102 posts

Re: Digital forgeries are hard

#101
post #83

Earlier quoted context omitted.

I'm repeating what I said above, but just send yourself an gmail with the hash in the Subject. Gmail will kindly timestamp it and provide a DKIM signature. Publish the mail headers gmail includes in the signature (which includes the timestamp and subject, but not the contents), the signature itself, and a link to hashed the document and you're done.

This is only true if Google never release old private keys for DKIM signatures, which various people have been campaigning for them to do in order to provide long-term deniability around DKIM-signed mails.

> This is only true if Google never release old private keys for DKIM signatures, which various people have been campaigning for them to do in order to provide long-term deniability around DKIM-signed mails.

I didn't know. Thanks for the heads up.

Re: Digital forgeries are hard

#102

Earlier quoted context omitted.

You send the envelope unsealed, then seal & stamp it later.

The word "stamp" is confusing here. You put postage on the letter, and the post office stamps the postage (to invalidate the postage). The stamp contains a date. You can't stamp something after having mailed it, that happens as part of the mail submission.

OK, I suppose this could be arranged. The seal has to be over the whole of the "back side" of the envelope, where the flap is. Then put the address and the postage over that, and the post office stamps it.

What confused me was how you would achieve post office stamping over a seal that's on the wrong side of the envelope, where the flap is.

Post reply on HN