Live data from Hacker News

Hash escrow

pdf23ds.net

11–16 of 16 posts

Re: Hash escrow

#11
post #6
post #5

Isn't this whole timestamping thing overcomplicated? Just set up a twitter account and post the hash codes. The code in itself is useless, so it does not have to be kept secret, and you will have a way to proof that you had the document generating it at that time.

This would work if you could search all of your tweets. I don't think that is currently possible, is it? It also assumes that twitter is going to be around when you finally need the timestamped hashes, and that you can prove that twitter (or any other service for that matter) can't have back-dated hashes inserted. Posting to a usenet group, like alt.test, where independent systems store and timestamp the message woul…

Why not just use multiple webmail services?

Re: Hash escrow

#12
post #11
post #6

Earlier quoted context omitted.

This would work if you could search all of your tweets. I don't think that is currently possible, is it? It also assumes that twitter is going to be around when you finally need the timestamped hashes, and that you can prove that twitter (or any other service for that matter) can't have back-dated hashes inserted. Posting to a usenet group, like alt.test, where independent systems store and timestamp the message woul…

Why not just use multiple webmail services?

Email timestamps are laughably easy to fake.

Re: Hash escrow

#13

These guys did exactly what's being proposed in the article. http://www.win.tue.nl/hashclash/Nostradamus/ In November 2007, they posted the MD5 hash of a PDF file containing the name of the winner of the 2008 election. That of course doesn't prove that they knew who would win the election, because they prepared 12 different PDFs with 12 different names in it, all of which were crafted to generate the same MD5 hash. I…

The article mentions hashing the same data with multiple hashing algorithms; I would think this would be effective at preventing collisions (presumably different hashing algorithms are not vulnerable to the same collision attacks).

Re: Hash escrow

#14
post #11

Earlier quoted context omitted.

Why not just use multiple webmail services?

Email timestamps are laughably easy to fake.

Surely Google et al, record the actual arrival time of the email in the headers do they not?

If not, then I'm sure they do in their logs.

Re: Hash escrow

#15
post #14

Earlier quoted context omitted.

Email timestamps are laughably easy to fake.

Surely Google et al, record the actual arrival time of the email in the headers do they not? If not, then I'm sure they do in their logs.

What stops you copying in a crafted email via IMAP, though?

Re: Hash escrow

#16

Is there anything wrong with the idea in the first blog comment? I would think sending the hashes to one or more webmail accounts in your own name would accomplish the feat of proof, and it would not require you to rely on other people to safeguard the data or give testimony.

How do you prove the e-mail wasn't changed? At least gmail allows you to upload pretty much anything (which is useful when migrating mail), and may not be able/willing to turn over (old) logs.

If they were simply unwilling, a subpoena would fix that.
Post reply on HN