Attempting (Failed) Verification of the Wright Signature
github.com
github.com
I'm mystified as to how this got past Andresen, though.
I think Randi would be the first to tell us that the skills required to detect a good conman are quite different from skills in technical fields.
http://www.livescience.com/9066-magician-scientists-assume-i...
I bet Andresen simply got tricked, and I think he should not feel to ashamed about it (although he will) -- most of us would have fallen for it.
I think Gavin maybe got a little starry eyed thinking he was talking to the bitcoin god himself and let his guard down. What a shame.
https://www.reddit.com/r/btc/comments/4hfyyo/gavin_can_you_p...
>Craig signed a message that I chose ("Gavin's favorite number is eleven. CSW" if I recall correctly) using the private key from block number 1.
>That signature was copied on to a clean usb stick I brought with me to London, and then validated on a brand-new laptop with a freshly downloaded copy of electrum.
>I was not allowed to keep the message or laptop (fear it would leak before Official Announcement).
It's quite suspect he wouldn't be allowed to keep the message, and that no public message and signature has been produced. But assuming he's not lying, this doesn't really seem like a scenario where he could be easily tricked.
My best guess, based on what I've read so far, is this:
- Gavin supplied his own text for the message.
- Craig faked running "sha256sum" on this message on his own laptop. The real "sha256sum" program could have been overwritten with a fake program that always output the same "hash". This is the "magic trick": the "hash" is attacker-controlled, and doesn't actually correspond to Gavin's message. Rather, the hash corresponds to an old message on the block chain - see, e.g., https://gist.github.com/ryancdotorg/893815f426f181d838c1b44a...
- Then from there, presto. The signature validates (and can be validated on Gavin's clean laptop) - because it's a real Satoshi signature, from the public blockchain years ago. But what it validates against is a "fake" hash - that Gavin thinks corresponds to his own message, but actually doesn't.
Easy to see how that would be a very, very convincing demonstration, after some social engineering. But all sleight of hand.
This is (I believe) why Craig has all this blurb up on https://dankaminsky.com/2016/05/02/validating-satoshi-or-not... - it's to hide the trick, which is that he doesn't give us the file "Spartre". He supplies only a (presumably faked) screenshot of sha256sum against this file. Making you type in the hash by hand is misdirection, so you don't realise that you don't have the original file.
Wright supplied all the inputs. Amazing.
One of the very few things that Bitcoin meaningfully has accomplished as an ecosystem is a world-readable repository of reasonably-well-attested-to-keys.
Yeah no shit.
ecosystem-wise I think it's a bit too harsh :) Bitcoin's p2p network does work (not without hiccups of course) - if I wanted to I could send btc to someone in say Brazil or Malaysia and it WILL work after all. And in some respects it will work smoother than trying to send fiat there.
I would say it is cheaper to send bitcoin, and maybe smoother for two regular users of bitcoin (and who shop online at bitcoin accepting businesses). However, that description applying to any two people is extraordinarily rare.
It is still definitely smoother, but more expensive, to send fiat. The infrastructure is already in place.
Whether the actual experience of that transfer is 'better' than fiat (WU, Swift, etc) is a different story and yes that would depend on the parties involved.
In many places it's easier to sign up for a Bitcoin exchange from your couch than to drive to Western Union. I can personally vouch for the US, Canada, and Thailand, where I've had experience with it.
From one of the reply to Gavinandressen:
https://www.reddit.com/r/btc/comments/4hfyyo/gavin_can_you_p...
I'm inclined to think this whole thing is a con, but I'm unsure if bash variable is a part of it, or just a mistake. But if it is a con, then we can't assume the person perpetrating it has the same level of technical mastery as we do.
All Wright has to do is sign today's headlines with the genesis key and publish the signature, and that's it. No other speculation or "convincing of a core developer" needed.
http://gavinandresen.ninja/satoshi
Probably a bit of confirmation bias there.
You'll have to visually compare this against Wright's screenshots, but it matches. If this sounds fishy to you, well, you're right. Also fishy: making people hand-edit hex values to verify trivial parts of this evidence chain.
To say that this is "fishy" is an understatement. To me it's proof enough that the man is a total fraud.