Welcome to Incremental Social! Learn more about this project here!
Check out lemmyverse to find more communities to join from here!

go_go_gadget , (edited )

That's fine?

Signatures aren't meant to prove authenticity. They're proving the source which you can use to weigh the authenticity.

I think the confusion comes from the fact that cryptographic signatures are mostly used in situations where proving the source is equivalent to proving authenticity. Proving a text message is from me proves the authenticity as there's no such thing as doctoring my own text message. There's more nuance when you're using signatures to prove a source which may or may not be providing trustworthy data. But there is value in at least knowing who provided the data.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • technology@lemmy.world
  • random
  • incremental_games
  • meta
  • All magazines