Jump to content

The problem of authentication.


SleepiB

Recommended Posts

It seems a lot of people get into trouble when they rely on hearsay without bothering to verify authenticity, and sometimes it's not even possible.

Therefore I submit a pgp public key for the verification of signatures, and on request, I will digitally sign any agreement I make and any orders I issue. In the future, when a document is posted on the CN forums by another party on my behalf, it shall have my pgp signature. I suggest anyone else concerned about security take the same measures.

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG/MacGPG2 v2.0.12 (Darwin)

mQINBEsVcKkBEADg9tismxTBJEpehSW1Mtc0PdRr0lWS8aYikDmTEf6Z4HDHC7jP
w2NsYOdkkMJ6rWn08MwCN1ZmMugdVjW9UkNJZ7P9asX57MWiHORdYH3p6gBgKq5b
o6FOnrV8sIi2eyJMeB8ZivU/UoNLUMA2BSj4YQ2NxxUvdsBnTomeLQTge+XjSw7F
z/IMPrlMsmZzXg3egI96LucJBXY4oJCAdorKSjWwMs3o23izSlalqXp6tJxRW28Y
U5HrS1Zm9DzjSpFW1HcGSOqmAEBJaDbGwpd2hFzPiUzvOSWgMyqtlVyDde/2LFTw
UVtwbhmvu21wHVRb8Q0GmXe8OtkLkk02UZ6K7nMUwgTP3yUTw6nzDaRvvIfWcFJj
W+ZPw8RykQphPjsNiAGKjIU/VU+8IBS5/Tgk6PjqvdqaYUZfaKo4lB5CIDL8nRbG
b+j0A+yS+RUukD4CkAnR2SHMZqW+usZmTKiIggPthcBR3PCYZFQNE7yQKt80OjIA
76XqCut7UEB2kjVr2Ly6mkD7gxn5qZ0sAiq/LTLlEaNVnGITI/6Jujvk5M0jTG40
biwin5CoAtKR5M8wqMeqkcTtG9M6a2np/srexWcqUx62TlNixkvDffom758vMK7L
dkaKJ0gMaEKEwiyQZKxGOGc9UHWkdx3EdUilwvhBx0w15tV8UtiHIlW+qQARAQAB
tB9zbGVlcGliIChDTikgPGFkdjExNkB5YWhvby5jb20+iQI2BBMBAgAgBQJLFXCp
AhsDBgsJCAcDAgQVAggDBBYCAwECHgECF4AACgkQBCDSCUgikwEDig//VEdAtNZO
F0/Jrc3DqBC+9ivTWT83Ukk4YYmsSa0Cr800M5bZduxNhg1IVSprYw2W/W3rD+rq
U2sIQWFLlvuq8sDjHG5c/mv0JiggA4flqmpd+juSAeUm4w1lj6MbTBN4xnb9QE1r
DiNyuzFbQoOfS3i2RPM1lVKtoTKDLDbwUY3V6RF29IKqnMXxYVVvJBrAjaFfESPS
XltZbeybHr0VGhjyzRk5NkPD77I+WfXULMpYkAAykLdxT0EXfqNV1sRbe8cQkFX4
NMEAiQ5saa0xCXZIkyqDii/AC1Nh2n3TRx1hxLJBCH3y2/lnCaIAzzuy2ldqsON4
VWIpKVesVKDHXiYrQIKjPCtTGwwulVrT+3HGUQp/eti+mErh3xsn9vflOag7GD3z
P0Xhq2R+Ly+6jN7wu/ENAgTmoyGJT8vCabMOfjHI3GwgprUtx/V6B3AyceDbmsQ2
q51J7ZHSAjTI9t2WayukmPBRJPrSsadaYXkg70+n6kIaVaqzM7fKwVMYXwaKgHsp
34idytIH/sdoO4QaFFYjkuyGPfqU1YJxCRGJBvldhVAX7nCfr0TXCLbGfJonos4m
zasXqovIfInqrS3bpCntsHI+4eAdRAvPYZdHbrY1hWOuO9aROAh7T4TacXIbyzK3
2X+2rWxqvSP9hh/OS8AksRUyj6zL64u0mG25Ag0ESxVwqQEQALxwEfPZv3UGQb3o
1aRSfNzxj//+/aAFI5PKXkeqQ3CwlKvctXrxHxBxNj7BG97eR7OgHUoWptMcU+FC
Ld171dW4DkkgZOJoGBX6LbB/CuYrox5WlN8+jA06Wo0cr0sxxES7gNTz8y9k4AY8
fUaHa4B4SVjX4h7OswFkVV46LFwyKofzk4nWbwrh/cligpQF+iqriX3zxqNg08q1
8vZ8oA2ZzmXZeU/KViJq0wR2sLKRtyFRc6ZVMFwNRcIilKaN/uNFe34IZJiJMIDw
n8wCor/4iHIVFz5tuV4n+lqm++WGXpgMX4AbIwRIXK3Xb+OrCxyUeKqqZcfccosk
lQtravTEb6ZQIQnGfskRaKyuE6CTzCEpnXOkuCPsddwTzcDvkL0B2k8hyImnzA5r
SZR07vlP0Vdx8vWZ3MnTxHEqlXbIqZw1aLIepvpd7wszoOuYV6gI4ilrGIoPZk/n
wm9WROyW9U1rc+Wt7OTHw+w0RknNSbB7zgX1nY+qfsmfpBFtOaiJ9ZH6c80MhWob
ZTlLwETaZYBWJABdt1cjgR+0ObR8hxU1tMJgWmQZ8Uqh6eP8Si47jW/8gpbhGyvP
YorIh4EsjtzkEYUQ+vlOMq0OnOozn0ikCc4hDb0CzLTq3yq+U2PDtGoBSRJ1iCVb
yqgH99rhZt6mhQwQb515qdE+XXE7ABEBAAGJAh8EGAECAAkFAksVcKkCGwwACgkQ
BCDSCUgikwHKpw//ZTp4b4yShP1m+lRLKZs6ewM1JVscDDhKKSeWDtkGs/vENQeX
CmtoHX/KZj6LCTY/4Vs/30o1pRtB0QjLYIrLsDlFhJkWIe+3UfXPNrxYAoiExmP1
lbGWkW6IA6ls07euaa8YgI9PbRj8wsJ0Sj9puafxwLYFucWYqeVWo+fhpHGnwCn1
WykcjSucCQR9KqyDFB9iWTfCEC+ZFaEnL/MsVwSb9zEPRQ84kFOFp8aP8MKEai3C
nHdoB91FkBL9suuW7kqIkWhuXg/drnHqrzblLN+R9CIc1lthFo0hmt661o+8m2mu
68oQfy4lfTvyIeULc6ROxEzq7SV4YXNvGjPLlZy13N5gFUlfcyvlLtMYzSPjvx2/
7cNLAKHKdcFfQ9Xeke+RvuJFoKs5tJ/X1ezWk1nVVbeY42ldg6ABIkLri4TloSmJ
Ou4It1lVYRRzA59+CSXqAzvQJsGmPtL0FqDkjBWPp9dGCwCjaRr8Nyyrnlj12V5Z
eLiDUfQmOfkAVbCjYqF2hVmp1z0Xl54ZPvi/pqqQ/hjPz7CVFgOGbf0zLExyTk+H
xULqsDZ2/tkQB3lEvOpOpjMP0L85+aoAm3o7EgHvzfEUPLFtVdQ9VILpUpiN9nDT
5aiuiFLVzGmZm9Ic0tDZ+GHHq7uUqJWpejv6vmduXY2rR8OBFu9bRTKc2+U=
=JQji
-----END PGP PUBLIC KEY BLOCK-----

public key mirrored here.

Link to comment
Share on other sites

  • Replies 51
  • Created
  • Last Reply

Top Posters In This Topic

fine, I'll sign the content of the OP, but you can verify the key on your own:

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

It seems a lot of people get into trouble when they rely on hearsay without bothering to verify authenticity, and sometimes it's not even possible.

Therefore I submit a pgp public key for the verification of signatures, and on request, I will digitally sign any agreement I make and any orders I issue. In the future, when a document is posted on the CN forums by another party on my behalf, it shall have my pgp signature. I suggest anyone else concerned about security take the same measures.

-----BEGIN PGP SIGNATURE-----

Version: GnuPG/MacGPG2 v2.0.12 (Darwin)

iQIcBAEBAgAGBQJLFZJxAAoJEAQg0glIIpMBFZsQAKi+3C9M71kDqDnQbDAIjiGx

sreSyQ541r0PsLFvix1Ft8PHp+JycOKFa73aqRDQS6kLzr9kjav+d2kx0dxMCGUT

lPgG+2w87F415H+kpS27QzumZyOUy7hzsq8y9Kihbkq0OcAFDU6l8jEqwpWK70WQ

3e5ikN8fHxpErB8AeD3Ht+vYf6c0AuS49X/cOpTkVFQIH/Eies+/VckSTO5QcGFP

+76te8M8ZXk2qvBJlVnhCPyLzKlfQ2VZKI5/5yGOLuovFJykjuh5fZforQRN6qeS

himKiGWhycWLxbGMFZ6vJQIkIaKC/kZORHcUiyIEZq7YngXHqS/Byb5qddebOJ0Y

lFzQwYB0OU83Lo0V3menzykzM905YQqnf4AGFH0mNTYtGLF2NdIQKw7K7ll1ze27

xVO+R4Uu/7gBUKQkUhV3m0WpSUazcnimID2yU9xfaVdrMXDLq6oKSncfkrZZ/Q4S

xCuWHvFe7pYL0Z3KzGIQCvENXpCSSJYbKtXM4Me3TK+87Rr76jOEnivJ7Mvz+VAb

yKXipEOy/3QtlYiyBIj0ViFiX9mDDc+U08u7dq1eYcFhu1tSO+iO2QMAVh5M7PlX

U48OUxlQB7F0yxYyg5r4wTQXe2VPc7l1tpdayFcLEecuHAUZfh2ZMow0sHt34DPT

WczxnG52BvsUAyRimBfY

=qJT0

-----END PGP SIGNATURE-----

Edited by SleepiB
Link to comment
Share on other sites

Um, what's going on here? Authentication codes for CN documents? Really?

Oh boy.

HEY NOW, this is srs bsns!

"There is no 'overkill'. There is only 'open fire' and 'I need to reload.'" -The Seven Habits of Highly Effective Pirates, Rule 37

I wonder if I'll get warned if i hide the signature in a spoiler tag.

Link to comment
Share on other sites

My official signature and proof of authentication is

Lord Bilrow, New Pacific Order Member, Hero of the Order, Past Imperial Advisory Council, Retired High Command, Retired Intelligence Director, Past Holy Triumvirate and Chief Protector of the Realm of the Grand Global Alliance, Past Elder Statesman of the Grand Global Alliance, Babi the Code Monkey, The Purger of the Greenlands, Stealer of Win, Toad of the Highest Order, King of Cowards, Sultan of Sycophants, Most Loathed Player of 2009, Warning: Gnawing Inevitable, Squisher of Bugs, Executor of Morality on CN, Cowtipper Extraordinaire, Polar Traitor, He Who Must Not be Named, Stalked by NAH, Gittered by Hannah, Slave of DarkMistress, Do You Want a Monkey Claw?, Stealer of all things Christmas, and Head On - Apply Directly to the Forehead, Head On - Apply Directly to the Forehead

Link to comment
Share on other sites

My official signature and proof of authentication is

Lord Bilrow, New Pacific Order Member, Hero of the Order, Past Imperial Advisory Council, Retired High Command, Retired Intelligence Director, Past Holy Triumvirate and Chief Protector of the Realm of the Grand Global Alliance, Past Elder Statesman of the Grand Global Alliance, Babi the Code Monkey, The Purger of the Greenlands, Stealer of Win, Toad of the Highest Order, King of Cowards, Sultan of Sycophants, Most Loathed Player of 2009, Warning: Gnawing Inevitable, Squisher of Bugs, Executor of Morality on CN, Cowtipper Extraordinaire, Polar Traitor, He Who Must Not be Named, Stalked by NAH, Gittered by Hannah, Slave of DarkMistress, Do You Want a Monkey Claw?, Stealer of all things Christmas, and Head On - Apply Directly to the Forehead, Head On - Apply Directly to the Forehead

Since when did you become a "Hero of the Order"? I thought only Aflsav had that title.

Link to comment
Share on other sites

My official signature and proof of authentication is

Lord Bilrow, New Pacific Order Member, Hero of the Order, Past Imperial Advisory Council, Retired High Command, Retired Intelligence Director, Past Holy Triumvirate and Chief Protector of the Realm of the Grand Global Alliance, Past Elder Statesman of the Grand Global Alliance, Babi the Code Monkey, The Purger of the Greenlands, Stealer of Win, Toad of the Highest Order, King of Cowards, Sultan of Sycophants, Most Loathed Player of 2009, Warning: Gnawing Inevitable, Squisher of Bugs, Executor of Morality on CN, Cowtipper Extraordinaire, Polar Traitor, He Who Must Not be Named, Stalked by NAH, Gittered by Hannah, Slave of DarkMistress, Do You Want a Monkey Claw?, Stealer of all things Christmas, and Head On - Apply Directly to the Forehead, Head On - Apply Directly to the Forehead

Actually NAH has moved on to stalking Bill N Ted. Nice try though ;)

Link to comment
Share on other sites

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

Hi guys, my name is Sleepib and I just wanted to let everyone know I like caek, and totally pointless and easily bypassed security measures. So yeah, I'm totally Sleepib. Don't believe me? Take a look at my signature, see I told you I'm Sleepib....;)

-----BEGIN PGP SIGNATURE-----

Version: GnuPG/MacGPG2 v2.0.12 (Darwin)

iQIcBAEBAgAGBQJLFZJxAAoJEAQg0glIIpMBFZsQAKi+3C9M71kDqDnQbDAIjiGx

sreSyQ541r0PsLFvix1Ft8PHp+JycOKFa73aqRDQS6kLzr9kjav+d2kx0dxMCGUT

lPgG+2w87F415H+kpS27QzumZyOUy7hzsq8y9Kihbkq0OcAFDU6l8jEqwpWK70WQ

3e5ikN8fHxpErB8AeD3Ht+vYf6c0AuS49X/cOpTkVFQIH/Eies+/VckSTO5QcGFP

+76te8M8ZXk2qvBJlVnhCPyLzKlfQ2VZKI5/5yGOLuovFJykjuh5fZforQRN6qeS

himKiGWhycWLxbGMFZ6vJQIkIaKC/kZORHcUiyIEZq7YngXHqS/Byb5qddebOJ0Y

lFzQwYB0OU83Lo0V3menzykzM905YQqnf4AGFH0mNTYtGLF2NdIQKw7K7ll1ze27

xVO+R4Uu/7gBUKQkUhV3m0WpSUazcnimID2yU9xfaVdrMXDLq6oKSncfkrZZ/Q4S

xCuWHvFe7pYL0Z3KzGIQCvENXpCSSJYbKtXM4Me3TK+87Rr76jOEnivJ7Mvz+VAb

yKXipEOy/3QtlYiyBIj0ViFiX9mDDc+U08u7dq1eYcFhu1tSO+iO2QMAVh5M7PlX

U48OUxlQB7F0yxYyg5r4wTQXe2VPc7l1tpdayFcLEecuHAUZfh2ZMow0sHt34DPT

WczxnG52BvsUAyRimBfY

=qJT0

-----END PGP SIGNATURE-----

This can be SO easily defeated by copy paste, why bother?

Link to comment
Share on other sites

This can be SO easily defeated by copy paste, why bother?

Each message has a unique signature, and it's easy to prove the signature doesn't match the message it supposedly signs. Even if there are only a couple people in each alliance that know how to read a pgp signature, they can verify or refute for everyone.

it works like this:

a pair of keys is generated, public and private, owned by a specific person.

private key and document are run through an algorithm to generate a signature.

public key, signature, and document can be run through a verification algorithm to determine if the document is authentic, which is the entire point. (You can use gnupg, or some other pgp implementation of your choice.)

Edited by SleepiB
Link to comment
Share on other sites

your faked message would return this on verification:

$ gpg --verify ~/Desktop/nc.asc

gpg: Signature made Tue Dec 1 16:02:25 2009 CST using RSA key ID 48229301

gpg: BAD signature from "sleepib (CN) <adv116@yahoo.com>"

The original would return this:

$ gpg --verify ~/Desktop/op.asc

gpg: Signature made Tue Dec 1 16:02:25 2009 CST using RSA key ID 48229301

gpg: Good signature from "sleepib (CN) <adv116@yahoo.com>"

Edited by SleepiB
Link to comment
Share on other sites

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

Hi guys, my name is Sleepib and I just wanted to let everyone know I like caek, and totally pointless and easily bypassed security measures. So yeah, I'm totally Sleepib. Don't believe me? Take a look at my signature, see I told you I'm Sleepib....;)

-----BEGIN PGP SIGNATURE-----

Version: GnuPG/MacGPG2 v2.0.12 (Darwin)

iQIcBAEBAgAGBQJLFZJxAAoJEAQg0glIIpMBFZsQAKi+3C9M71kDqDnQbDAIjiGx

sreSyQ541r0PsLFvix1Ft8PHp+JycOKFa73aqRDQS6kLzr9kjav+d2kx0dxMCGUT

lPgG+2w87F415H+kpS27QzumZyOUy7hzsq8y9Kihbkq0OcAFDU6l8jEqwpWK70WQ

3e5ikN8fHxpErB8AeD3Ht+vYf6c0AuS49X/cOpTkVFQIH/Eies+/VckSTO5QcGFP

+76te8M8ZXk2qvBJlVnhCPyLzKlfQ2VZKI5/5yGOLuovFJykjuh5fZforQRN6qeS

himKiGWhycWLxbGMFZ6vJQIkIaKC/kZORHcUiyIEZq7YngXHqS/Byb5qddebOJ0Y

lFzQwYB0OU83Lo0V3menzykzM905YQqnf4AGFH0mNTYtGLF2NdIQKw7K7ll1ze27

xVO+R4Uu/7gBUKQkUhV3m0WpSUazcnimID2yU9xfaVdrMXDLq6oKSncfkrZZ/Q4S

xCuWHvFe7pYL0Z3KzGIQCvENXpCSSJYbKtXM4Me3TK+87Rr76jOEnivJ7Mvz+VAb

yKXipEOy/3QtlYiyBIj0ViFiX9mDDc+U08u7dq1eYcFhu1tSO+iO2QMAVh5M7PlX

U48OUxlQB7F0yxYyg5r4wTQXe2VPc7l1tpdayFcLEecuHAUZfh2ZMow0sHt34DPT

WczxnG52BvsUAyRimBfY

=qJT0

-----END PGP SIGNATURE-----

This can be SO easily defeated by copy paste, why bother?

you might wanna go study up on public key encryption, how and why it works before you start running your mouth.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...