Digital forgeries are hard
mjg59.dreamwidth.org
mjg59.dreamwidth.org
https://en.wikipedia.org/wiki/Sledgehammer_(alleged_coup_pla...
We had a similar thing in Pakistan. In fact, same font.
https://gulfnews.com/world/asia/pakistan/how-calibri-font-br...
Even with homework done I'd never attempt it for the same reasons that Matthew Garrett outlined in his article.
However, assume a hypothetical case where I had to forge a document what would I do? My first thought would be to obtain a pensioned-off PC complete with operating system, user apps such as MS Office/Word and standard default fonts that was last used a little before the date of my intended forgery.
Obtaining such a PC may seem like a tall order but it might not be as difficult as it seems, but it certainly won't be easy. I say that it's possible by just looking at my own situation. In my shed I have a stack of old PCs gathering dust that haven't been switched on in several decades, no doubt there are many similar piles of junk out there in user-land that can be tapped for a suitable PC.
Next, I'd ensure the PC was not switched on until I'd removed the hard disk and forensically mirrored it to a backup on another PC. The mirrored disk image can then be examined to determine the exact date when it was last used, etc., etc.
Without reinstalling the hard disk and before switching it on I'd disconnect the PC's clock battery and or short out the clock operation so the clock was set to the factory default time (I.e. not set). I'd then switch on and set the date in the BIOS slightly ahead of the last date the PC was last switched on (that date I'll have already determined from my forensic analysis of the mirrored image).
After reinstalling the HD I'd switch on and hopefully I'd have functional PC whose date and time would indicate that it was switched on shortly after the actual time it was last used.
At this point and before proceeding further I'd take another mirror image of the HD and compare it with the original for any gotchas. Unless something goes awry I'll use this second mirror for all future installations and any necessary tweaks.
My next step would be to draft out the forged text by hand on paper. I'd study this text with great care to ensure that I've the precise wording and that there are no references to forward dates or events that could not have happened by the date of the forgery. I'll then sit on the text for 24 hours or more to think about it just to make sure that everything I've written is as 'faultless' as is possible.
Assuming all's well and only then will I switch on the PC and use the installed copy of MSO/Word with one of the common already-installed typefaces such as Ariel or Times New Roman to type my text.
Even then, with all that done, I'd still be shitting myself that I'd not fully covered my tracks!
Note: that's the short version, there are many other intermediate checks too detailed to mention here. Some of these steps may require minor tweaks to the second mirror (metadata changes, etc.) before it's mirrored back to the original HD. Any edits to the second mirror should only be done after it's been backed up.
Doing these checks and ensuring that one's covered one's tracks isn't for the feinthearted. Right, the stakes have to be extraordinarily high to even bother attempting such a job.
_
Edit: if the forgery is to appear in printed form then it should be printed on old stock paper with a printer of the same era, say a HP LaserJet III for instance. Even with expertise, artificially aging such a document is a complicated process and even then it's unlikely to pass muster with a basic forensic analysis.
Another approach is to do the above then photocopy the original then 'lose' it and only use the copy. Recopying the copy on multiple machines of different brands will make tracing the original photocopier more difficult as each machine will have optics with minor distortions that are different to one another. Faxing the document sans headers will further obfuscate where the copy originated as faxes are of low resolution and introduce artifacts noise, but keep in mind that the mechanics and optics of fax machines introduce the same type of distortions as photocopiers.
Again, don't bet your chances, if you use these methods then smart forensics are still likely to nab you.
I'm reminded of that scene in mindhunter where the detectives go to Kemper something like "this theory is unsupported by the data we've collected on serial killers." And kemper calmly responds "Seems to me all of the data you've gathered is from serial killers you're caught."
Kemper believes there are many serial killers undiscovered, and more importantly easily able to avoid detection (as he did) unless they turn themselves in. This is while the fbi is speculating profiles of an active serial killer.
I'm one of Wright's defendants and have spent the last several years of my life trapped in this involuntary puzzle hunt.
Often people read the conclusions on the documents and say "man this guy Wright is a total idiot"-- and while I don't disagree with the sentiment, it's the wrong conclusion to draw from the documents.
These debunks seem simple once they've been pointed out to you. But the problem that a forger has is that they must get EVERYTHING exactly right. The anti-forger, on the other hand, need only identify one solid flaw.
Wright's stupidity wasn't so much in any particular error (okay, well a couple were kinda dumb: like backdating documents by robotically replacing all past tense with future tense, turning him into nostradumbass.)-- but the scale meant that it was inevitable the he would make errors.
Unfortunately he's been learning and for the most part his later forgeries had a lot less metadata to go on. If he gets too many more tries he may be able to start producing unfalsifiable forgeries. I'm really homing the judgement is forceful enough to meaningfully shut him down.
I think in particular the Lynch (one of Wright's expert) report on the LaTeX files is interesting because it took a different approach than Rosendahl -- so it wasn't as duplicative: Rosendahl tried using legacy tools against the files, Lynch used current tools the combination was particularly fatal to Wright because if only one approach had been used Wright would have claimed that the other approach would have produced results that supported his case.
(Rosendahls' report itself is a great work in its own right, in spite of being a LaTeX user for >20 years I learned quite a few things from it).
I wish we'd gotten access to Wright's 22 million lines of chatgpt traffic since September, that might have been particularly interesting! -- the abuse of LLM's in the case is itself something of public interest that sadly wasn't adequately ventilated in the trial because we weren't able to get the relevant records. But there were pretty good indications that Wright used ChatGPT directly to create forgeries, aid in the construction of other forgeries, and to pad out his witness statements in a bit of a volumetric attack.
The Bitcoin legal defense fund has tried to get out most of what it could lawfully put out, -- skipping a few things with privacy issues-- but once the trial started the priority shifted to managing the case.
The default openness of the US courts may well have been the real hero in all this: documents and statements made public in the kleiman case boxed wright in from every angle. Its important that materials from this case are made public because it may not, unfortunately, be the last we hear from wright. Even where the US case didn't make some things public, it make their existence public which in some cases enabled us to obtain them: e.g. we were able to get all of Gavin's communications with Satoshi which had previously been provided to Wright and whose existence Wright tried desperately and ultimately unsuccessfully to deny.
The UK court openness is less by default, but the parties have a substantial ability to publish things-- allowing the parties to get things much closer to US practices.
I very much did not enjoy having to read a large amount of handwritten nonsense on a short fuse during the trial... and in some sense he was successful with them in that he wasted an enormous amount of time that could have been spent on something else, an they likely won't weigh against him substantially if at all since they didn't get used.
click
Yup.
This guy is a pathological forger and is bad at it.
Here's my write-up from when he got caught doing naughty things with ECDSA:
(as noted by another commenter, "pathological" is literal in this case)
"pathological"
I think it's literally a compulsion for him.
But proving that an event happened before a certain time, like in the article, is a lot harder. You can send someone an email through a trusted gateway, but people can only check by having access to that mailbox, or trusting the person who has access. And I know about PKI timestamping, but I've never seen them used for legal cases, maybe because the complexity erodes trust.
Are there any good solutions that would convince a non-technical judge?
Edit: I remember Twitter[1] being used for this purpose, but I don't know if today I'd trust a hash dropped there, given how much it's evolving and/or struggling.
That was hard to find. My first google searches turn up this post. Here it is, in case anyone is interested: https://www.itconsult.co.uk/stamper/stampinf.htm
In the end both are just digital signatures, and so are "entirely possible with regular old public key cryptography" as you say. You can achieve a similar effect by sending a gmail message to yourself with an sha256 of the document in the subject. The subject and date are included in the gmail DKIM signature. The cryptographic primitives used by Stamper, gmail DKIM and bitcoin are equally secure as a first approximation.
That means the security ultimately rests on the security of the key used to sign it. So do you trust Matthew Richardson to keep is gpg key secure, or Google to keep their DKIM secure, or the difficulty imposed by a proof of work where the amount of work is equal to a nation states electricity supply? I know which I'd choose out of those three, and that's the key differentiator of bitcoin. It is not the cryptographic primitives used.
That is presumably one of the reasons that hasn't happened in the roughly 30 years the service has been ticking along.
I feel like the best you can do is either to publish a cryptographically secure hash or to publish something encrypted and share the key/password when you want to reveal the secret.
- Publicly accessible.
- Timestamped.
- Immutable (or at least with edits marked as such).
- Widely trusted (or too big to be bribed in small cases, e.g., Google).
- And keep those features for many years.
Twitter was surprisingly good at that in the past, but no more. Blockchains, as mentioned in other comments, give excellent immutability; but the field is such a minefield that I'd struggle to find a trustworthy blockchain explorer.
I didn't know. Thanks for the heads up.
Judges can be aided by expert reports.
And not all judges are non-technical.
The fact that you can defend your documents with timestamps is often enough: the other side won't challenge them knowing that they are likely to lose the challenge.
There isn't any way to do this without one or more trusted third parties. Traditionally that would involve someone like a public notary or a lawyer.
I was amused to find that there is a service that cryptographically timestamps things over email via PGP that has been running since 1995:
Note that you need to send First Class to get a postmark in the US - not standard Priority Mail.
You put postage on the letter, and the post office stamps the postage (to invalidate the postage). The stamp contains a date. You can't stamp something after having mailed it, that happens as part of the mail submission.
What confused me was how you would achieve post office stamping over a seal that's on the wrong side of the envelope, where the flap is.
If you know you're going to have to prove it, there are loads of options. Absolutely loads.
The issue is simply that this guy's a fraud so he's gotta come up with a story about why he didn't use any of them.
The judge in this case is actually very technical so that's not a problem.
Regardless, the easiest and most direct way to timestamp something is to use the standard RFC 3161 timestamping servers. There are many, located in different countries and run by different people, and the format is straightforward and standardized. Support is built in to products like Acrobat. You can attach multiple timestamps from different sources to a single file. They are free. It can be explained to non-technical people in a not extreme amount of time, and courts / law firms in any country can easily find expert witnesses who can verify such timestamps and testify to the court as to their veracity.
For emails there's also DKIM, which signs email including the date header. Again, plenty of people who can verify those signatures, so emailing something to someone else and then getting a copy of the raw email will do it (don't email to yourself, that skips the signing process).
Disclosure: I took part in this trial as a witness and testified against Wright.
[1] https://en.wikipedia.org/wiki/DomainKeys_Identified_Mail#Con...
Of course for verification it's important that the timestamp countersignature comes from a reputable CA and not some random server you set up.
Stuff on the block chain has a problem asserting anything that's not on the block chain, which is what a lot of people want to use it for. In this case, it's a bitcoin solution to a bitcoin problem. It's all in-universe so to speak.
It looks like the case was very swiftly decided against Wright. Here's reporting from The Guardian about it today: https://www.theguardian.com/technology/2024/mar/14/australia...
It's true that most people consider Wright a silly clown these days, but the chilling effect against Bitcoin development is hard to quantify and, I think, wholly real. This is why his latest loss makes today a good day.
However, if I try to assume a good intent, here's what I come up with:
CW knows he is not Satoshi and his case is laughable. However, by chance he happens to be in a unique position (relative to everyone else) where as long as he pushes his case, he keeps attention on the mystery of Satoshi . Maybe that is his goal all along, and his calculations show that he increases the odds of the true creator being revealed by pushing his false claims.
I mean, the anonymity of Satoshi is puzzling. BitCoin is the only major modern invention with an anonymous creator, AFAIK. I guess the most bothering aspect of the whole thing is not that I don't know who Satoshi is, it's that I know there are people out there who do know (maybe in the dozens, hundreds, or low thousands). It's annoying that there are state secrets like that. So if that is CW's intent behind all his puzzling immature actions, then there's an interesting argument to consider that his actions might have a positive ends.
Ha, wouldn't it be funny if Wright actually had the last laugh and that his claim that he's Satoshi Nakamoto was meant to have holes so that he would be discredited.
The whole saga of Satoshi Nakamoto and Bitcoin is so odd and unbelievable and fraught with so many open-ended questions one has to wonder what's true and what's not. The only thing for certain is that Bitcoin is real and that someone actually invented it.
Why would Satoshi Nakamoto bother obfuscate facts and hide himself, what would be his motive and what would he achieve by so acting? Even if unlikely it's completely plausible that Wright is Satoshi Nakamoto and that his seemingly shoddy claims about being him is actually part two of some strange hoax that he's cooked up.
Unlikely for sure, but if he is Satoshi Nakamoto then his place in history will be assured for certain, he'll be remembered for a double whammy that'll never be forgotten: the genius of Bitcoin and block chain cryptocurrency, and the biggest king-sized hoax/con job of all time.
Clearly Wright is smart but he could be smarter than we give him credit for. Wright's ego may be such that he wants an assured high place in history, if so then what better way to achieve that than to act as he has done?
Eventually the true identity of Satoshi Nakamoto will be revealed and someone will have that last laugh.
One example: https://gulfnews.com/world/asia/pakistan/calibri-controversy...
They could've easily used Times New Roman like their teachers probably instructed them. /hj
This is essentially "digital forgery" at the protocol level. I wonder if the thesis could be shown to be generalizable to most digital forgery, or even forgery in general.
Even if it’s hard to prove exactly that he did it, there’s a strong motive and means and a lot of pretty shocking evidence of forgery here.
Maybe that won't be treated as seriously as it should be because people don't realize that it very much could have worked!
You do make a good general point, though! Good forgeries are by their nature not known to be forgeries.
Craig Wright is definitely not Satoshi, the guy has some issues and so keeps claiming that he is.
The flip side of this is how difficult it is to avoid tracking and hidden metadata.
Over the eight years he's been at this, he has built up a cult following of people who worship the ground he walks on and will defend him ferociously at every opportunity.
Yes, he's a bad liar, but very few people can do what he does.
He is an expert at statements that brim with sound and fury but which signify nothing, and so although they covey some impression their content leaves nothing to falsify.
He immediately deceives many people. Some of his approach is polarizing, particularly the technobabbling-- people either fall hard for him or see right through him-- but generally a conman only needs to fool some people, not everyone.
The technobabbling even sometimes works on technical people, particularly when they go in pre-awed by him, they assume that misunderstandings are errors on their part.
Like if you met Knuth and asked him a question and he replied with a bunch of jargon you've barely heard about but it doesn't really sound right... you're not going to suddenly start thinking he's a big fake, right? you're going to assume you're the clueless one.
One thing I've realized during the case is that the kind of scrutiny people apply when they get handed a document as "proof" is not the same as the scrutiny they'd apply if handed a document they know is fake and they simply need to find proof.
In the former case people just tend to confirmation bias themselves, they check a few things and say "yep checks out". While in the latter case, they'll much more quickly say "well if it's authentic, then all the version numbers should check out, lemme go check those".
The former kind of check is almost completely ineffective against an intentional forgery unless it was made by someone dramatically less competent that you. Validation for "proof" sake must use the second process of assuming it false and looking for the evidence of it.
There is nothing fundamentally wrong with accepting a document on its face, but you shouldn't deceive yourself that you've validated something. If someone is giving you a document to prove something then you have to accept a serious possibility that it was fake, otherwise why bother looking at the document at all?
Hence, pretty strong reasons to suspect Russian state involvment.
Those phishing emails and links are distinct from the DNC leak