Two things that look the same

Pairs people confuse on Nexus Market, and the one test between them

Home People What a signature actually proves

Nexus market mirrors

nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onion
nexusma2iegzo7atzwbrwxhcdopyri3vare2twibldnlc3txqjdeb5yd.onion
nexusabcdpvtnivv6owtqjkvd22k5x3hlpofkgjqjmgzltlde6mwe2qd.onion

Published as supplied. Nothing here is monitored, so none of this is a claim that any address opens right now.

People / Pair 32 of 41

What a signature actually proves

It arrives as a wall of text with a signature block bolted to the bottom, and that formatting does most of the persuading before you have read a line.

Why both of them look official

A signed messageA

Tied to a key

A block of text with a cryptographic signature over it. If the signature checks out against a particular key, the text has not been altered since that key signed it. That is the entire content of the guarantee, and it is a guarantee about a key.

A claim to be somebodyB

Tied to nothing

Any text asserting an identity. It may be dressed in the same layout, carry the same headers, and include a key of its own. What it lacks is any connection to something you held before it turned up.

A signature ties a message to a key. It does not tie the key to a person, and it never has. The person is a separate matter that has to be settled somewhere else, in advance, by you.

This trips up careful readers rather than careless ones. Careless readers ignore signature blocks. Careful readers check them, watch the check pass, and conclude something the check never said. If the key travelled with the message, or came from a page the message pointed at, then all the passing check tells you is that the sender holds the key they just handed over. Anybody can arrange that in a minute.

The check that does not depend on trusting anybody

Follow the key backwards

Trace your copy of the key, not the message. If the key was already in your possession before this arrived, from somewhere with no connection to it, verification means something. If the key came with the message or from anywhere it directed you, the whole exercise is circular.

  1. Ask where your copy of the key came from, and answer honestly rather than approximately.
  2. If the answer is this message, or a page this message linked to, or a helpful account that supplied it when the subject came up, stop. There is nothing to verify against.
  3. If you held the key beforehand, from a source with no stake in whatever is happening now, check the signature against that copy rather than against anything included with the new message.
  4. A pass means the holder of that key wrote this text. It does not mean the text is true, and it does not mean the holder is who they were when you first filed the key away.

The near miss here is a key you fetched today, from a page you found yourself, at the exact moment you needed one. That feels independent and is not, since whoever wanted you to hold a particular key had every opportunity to put it where a worried buyer would go looking. Age and habit are what give a key its value. A copy you have had for months, from a source you chose when nothing was at stake, is worth more than a fresher copy from a better looking page.

That final line is the part people skip past. Verification establishes authorship and stops there. A key can change hands. A person who once held it can lose it, sell the account it belonged to, or be pushed aside from it. What you gain from a clean check is a much narrower thing than the confidence it produces, which is exactly why it is worth doing and worth not overreading.

Two ways to be wrong, and only one is cheap

If you treat a bare claim as a signed message
You act on instructions from an unknown party who has spent five minutes on formatting. In practice that means sending funds somewhere, changing where something is going, or handing over a detail the market already holds. None of it comes back.
If you treat a genuine signed message as a bare claim
You ignore something real. You wait, you double check through the interface, you look slightly rude and you lose an afternoon. Everything you lose in this direction can be got back by looking again.

Very few pairs on this site are as lopsided as this one. The cautious mistake costs time and the credulous mistake costs the balance, which is a good argument for being the sort of reader who shrugs at signature blocks from strangers. If the message is asking you to move money at all, the pairing to read next is market support or somebody using the name. The tests index lists the separating check for every pair in one place.

What to do in each case

If it is properly signed
Treat it as written by whoever holds that key, and treat the contents as a claim from that party rather than as fact. Anything with money attached still gets confirmed against what the market interface itself shows you.
If it is only a claim
Treat the content as unsourced and go and find the same statement somewhere you reached under your own steam. If it exists there, you never needed the message. If it does not, you have learned something more useful than the message was offering.

The way this shades into reputation is covered at feedback or evidence, since a signed statement is one of the few things in this trade that can act as a record rather than an impression.

Questions readers send about this pair

The message came with its own key. Is that not enough?

No, and this is the common trap. A key included with the message proves the sender signed with the key they supplied. Any sender can do that. The key has to have reached you earlier, by a route with no connection to the message you are examining.

Where should a key have come from?

Somewhere you went to yourself, before you had any pressing reason to want the key, and ideally somewhere you have used since without incident. The value comes from the gap in time and the absence of a link, not from the source looking authoritative.

If the signature verifies, is the message true?

It means the text has not been altered since that key signed it. Truthfulness is a different question and no signature has ever answered it. Someone can sign a false statement perfectly.

Every page here

AddressesGetting inMoneyOrdersPeopleWordsDown for now, or finished for goodOld address, or one built to be misreadSame page at two addresses, and only one is theirsThe redirect and the string it stands in forYour path through Tor, or the far endDid the set move, or did your copy slipLoading proves a server answered, and nothing moreRate limiting against a password that no longer matchesWhen the puzzle is broken and when the reader isA door you shut yourself against a lock somebody changedLogged out by a clock against logged out by a decisionA code that does not match against a clock that does notAn absence against a single character out of placeA wait somebody planned against a wait nobody didA deposit that is slow, or a deposit that is goneThe address expired, or it was never issued to youA rule about release, or a decision about youWho took the difference, the operator or the networkA saving on quantity, or a saving on protectionMoney back, or the end of the argumentStill moving, or already refusedStill settling, or short by a fractionA date with something behind it, and a date withoutOne request moves a clock, the other moves the moneyAsking for a ruling, or handing over informationA word in a database, and an event in a recordNothing new to report is not the same as bad newsA rule that runs by itself, and a date somebody prefersSilence and being ignored look identicalQuiet is not the same as goneFeedback tells you a mood, evidence tells you a factWhat a signature actually provesThe market only speaks in one placeAn empty history and a claimed historyThe result is good. Whose key was it?The same clean result, months apartYou cannot check an image, however clear it isOne of these strings was chosen by somebodyPosted where, and written by whomWho granted it, and what were they promisingTwo lists of addresses, two different guaranteesHow to read a pairEvery pairThe testsThe costsMirrorsQuestions