My best guess is that Gavin has been duped by a sleight of hand (like a magician would use) by Craig.
My best guess, based on what I've read so far, is this:
- Gavin supplied his own text for the message.
- Craig faked running "sha256sum" on this message on his own laptop. The real "sha256sum" program could have been overwritten with a fake program that always output the same "hash". This is the "magic trick": the "hash" is attacker-controlled, and doesn't actually correspond to Gavin's message. Rather, the hash corresponds to an old message on the block chain - see, e.g., https://gist.github.com/ryancdotorg/893815f426f181d838c1b44a...
- Then from there, presto. The signature validates (and can be validated on Gavin's clean laptop) - because it's a real Satoshi signature, from the public blockchain years ago. But what it validates against is a "fake" hash - that Gavin thinks corresponds to his own message, but actually doesn't.
Easy to see how that would be a very, very convincing demonstration, after some social engineering. But all sleight of hand.
This is (I believe) why Craig has all this blurb up on https://dankaminsky.com/2016/05/02/validating-satoshi-or-not... - it's to hide the trick, which is that he doesn't give us the file "Spartre". He supplies only a (presumably faked) screenshot of sha256sum against this file. Making you type in the hash by hand is misdirection, so you don't realise that you don't have the original file.