Live data from Hacker News

Sign Everything

avc.com

31–40 of 90 posts

Re: Sign Everything

#31
I do believe this "sign everything" issue can be dealt with later on. For new data/knowledge/posts.

There's a much more pressing issue.

I just asked ChatGPT to explain it, here's what it spouted:

"We need to securely record the knowledge created by humans up to this date using cryptographic hashes and a Merkle tree. This includes text, pictures, videos, and sound. This is vital for training future AIs and will ensure that the well is not poisoned. We can use SHA-3, SHA-256, Blake3, or any other cryptographic hash. We should store this in a large database, as well as sites and forums that will provide a "proof of existence" before a certain date."

It got a bit confused at the end. What I was suggesting was that there'd eventually be sites/forums/tools where every data you can access could check it's "proof of existence".

You'll then know for sure if the file was created before a certain date or not.

For example imagine I were to download a file, a tool could tell me (disclaimer for sensitive users, I'll mention the 'B' word):

"File xyz, with SHA-256 4f82d8dd...eb80fd7b, was first recorded on the Bitcoin blockchain in block 601382, in april 2023. We verified that using the Merkle tree XYZ3497 whose root hash was in that block."

It's not perfect but before we begin signing every new content we create, I think the most pressing matter is to "sign" as much of the past human knowledge as we can.

For what an AI will be able to do is to create and sign new content and use fake identities.

But what an AI will not be able to do is modify proof-of-existence of old documents. So we need, now, to establish proof-of-existence for as much old data as we can.

Re: Sign Everything

#32

Great example of the danger of talking about a solution before you’ve truly defined the problem. What problem is Fred trying to solve? The example he gives of writing he would sign is a blog post. The blog post is already authenticated because it’s on avc.com. Fred Wilson has the tokens, social authority etc to ensure what shows up there under his name is from him. Technically speaking, it was already signed via TLS…

> What problem is Fred trying to solve?

> The blog post is already authenticated because it’s on avc.com. Fred Wilson has the tokens, social authority etc to ensure what shows up there under his name is from him.

Haven't you answered your question? Most people don't own a domain, that's the problem signing solves.

If I see signed messages from John Doe which look like human generated messages and I start following him and then I start seeing AI-generated spam from John Doe, I can tag the signing key John Doe used as "bot confidently generating non-sense".

I cannot do that if John Doe doesn't have its own website.

Re: Sign Everything

#33
Hmm, perhaps robots.txt semantics needs to be extended to signify “OK to crawl for a search database but not as a training set”.

Re: Sign Everything

#34

Great example of the danger of talking about a solution before you’ve truly defined the problem. What problem is Fred trying to solve? The example he gives of writing he would sign is a blog post. The blog post is already authenticated because it’s on avc.com. Fred Wilson has the tokens, social authority etc to ensure what shows up there under his name is from him. Technically speaking, it was already signed via TLS…

Signing everything is not terrible advice. But here the problem Fred is trying to solve is very simple. He is an investor in mirror.xyz and needs to make his money back. This is the only reason someone interested in signing something would also ask you to go through the hassle of using a blockchain.

There is absolutely 0 need to use a blockchain to sign something :facepalm:

Re: Sign Everything

#35

Web3! Does AVC have anything riding on that? Meanwhile, from 2004, on Web1: On the other hand, say you’ve already established something of an online identity, perhaps through your own web site, or as a frequent commenter at this or some other blog(s). What prevents someone else from coming along and posting a comment here, leaving your name and your website’s URL to identify himself? Put another way, how can readers…

USV were one of the biggest backers of coinbase

Re: Sign Everything

#36
post #6
post #2

I believe that cryptographic signing of content will become an important step in confirming legitimacy of content, however I believe it is up for debate that "web3" is the way to go about doing that. With the rise of AI generated content, deepfakes, etc, being able to track media back to its source in a cryptographically sound way will be key. How exactly we go about doing that remains to be seen.

Simply S/MIME. We could have a Let's Encrypt for S/MIME allowing people to sign the content they produce.

Yep. There is even an RFC for SMIME ACME, but I don’t think such CAs have CT at the moment. A email@domain system using something like SXG and the existing server PKI is probably a more tangible idea atm.

Re: Sign Everything

#37

Great example of the danger of talking about a solution before you’ve truly defined the problem. What problem is Fred trying to solve? The example he gives of writing he would sign is a blog post. The blog post is already authenticated because it’s on avc.com. Fred Wilson has the tokens, social authority etc to ensure what shows up there under his name is from him. Technically speaking, it was already signed via TLS…

I think it's funny that if everyone signed their blog posts, ChatGPT would try to "sign" its blog posts as well, and fail.

Fail if someone checks the signature, but chatGPT would definitely pass the xkcd test: https://m.xkcd.com/1181/

Re: Sign Everything

#38

Great example of the danger of talking about a solution before you’ve truly defined the problem. What problem is Fred trying to solve? The example he gives of writing he would sign is a blog post. The blog post is already authenticated because it’s on avc.com. Fred Wilson has the tokens, social authority etc to ensure what shows up there under his name is from him. Technically speaking, it was already signed via TLS…

The blockchain proves that the post was made when he says it was.

Being on avc.com doesn't prove that; he could back-date posts.

Re: Sign Everything

#39
What what? So I sign everything so that people know that it was me copy pasting GPT3 content into my own blog? Or are we betting that signing can't be automated?

What am I not getting here?

Re: Sign Everything

#40

Great example of the danger of talking about a solution before you’ve truly defined the problem. What problem is Fred trying to solve? The example he gives of writing he would sign is a blog post. The blog post is already authenticated because it’s on avc.com. Fred Wilson has the tokens, social authority etc to ensure what shows up there under his name is from him. Technically speaking, it was already signed via TLS…

I'm no Web3 proponent, but hard disagree here -- I think Fred is onto something clear.

- Current experience is that most folks do not own their own domain or do not have audiences that will consume the content on their own domain, they instead depend on content being copied and distributed on other platforms.

- Threat is that modern AI makes it much easier to convincingly impersonate you on other platforms -- including robust profiles and statements that match your style or even tweak real content.

- Web3 potentially offers a platform-neutral, globally accessible place to claim ownership of content itself, so that people know if they are viewing a primary source or something edited.

There is a TON of productization to be done and a network effect problem to solve (there must be a simple, widely used protocol for verification that can either be used by everyone or built into trusted tools). But the value prop for a public signature ledger is not some fantasy IMO.

Post reply on HN