People / Pair 32 of 41
What a signature actually proves
It arrives as a wall of text with a signature block bolted to the bottom, and that formatting does most of the persuading before you have read a line.
Why both of them look official
Tied to a key
A block of text with a cryptographic signature over it. If the signature checks out against a particular key, the text has not been altered since that key signed it. That is the entire content of the guarantee, and it is a guarantee about a key.
Tied to nothing
Any text asserting an identity. It may be dressed in the same layout, carry the same headers, and include a key of its own. What it lacks is any connection to something you held before it turned up.
A signature ties a message to a key. It does not tie the key to a person, and it never has. The person is a separate matter that has to be settled somewhere else, in advance, by you.
This trips up careful readers rather than careless ones. Careless readers ignore signature blocks. Careful readers check them, watch the check pass, and conclude something the check never said. If the key travelled with the message, or came from a page the message pointed at, then all the passing check tells you is that the sender holds the key they just handed over. Anybody can arrange that in a minute.
The check that does not depend on trusting anybody
Follow the key backwards
Trace your copy of the key, not the message. If the key was already in your possession before this arrived, from somewhere with no connection to it, verification means something. If the key came with the message or from anywhere it directed you, the whole exercise is circular.
- Ask where your copy of the key came from, and answer honestly rather than approximately.
- If the answer is this message, or a page this message linked to, or a helpful account that supplied it when the subject came up, stop. There is nothing to verify against.
- If you held the key beforehand, from a source with no stake in whatever is happening now, check the signature against that copy rather than against anything included with the new message.
- A pass means the holder of that key wrote this text. It does not mean the text is true, and it does not mean the holder is who they were when you first filed the key away.
The near miss here is a key you fetched today, from a page you found yourself, at the exact moment you needed one. That feels independent and is not, since whoever wanted you to hold a particular key had every opportunity to put it where a worried buyer would go looking. Age and habit are what give a key its value. A copy you have had for months, from a source you chose when nothing was at stake, is worth more than a fresher copy from a better looking page.
That final line is the part people skip past. Verification establishes authorship and stops there. A key can change hands. A person who once held it can lose it, sell the account it belonged to, or be pushed aside from it. What you gain from a clean check is a much narrower thing than the confidence it produces, which is exactly why it is worth doing and worth not overreading.
Two ways to be wrong, and only one is cheap
- If you treat a bare claim as a signed message
- You act on instructions from an unknown party who has spent five minutes on formatting. In practice that means sending funds somewhere, changing where something is going, or handing over a detail the market already holds. None of it comes back.
- If you treat a genuine signed message as a bare claim
- You ignore something real. You wait, you double check through the interface, you look slightly rude and you lose an afternoon. Everything you lose in this direction can be got back by looking again.
Very few pairs on this site are as lopsided as this one. The cautious mistake costs time and the credulous mistake costs the balance, which is a good argument for being the sort of reader who shrugs at signature blocks from strangers. If the message is asking you to move money at all, the pairing to read next is market support or somebody using the name. The tests index lists the separating check for every pair in one place.
What to do in each case
- If it is properly signed
- Treat it as written by whoever holds that key, and treat the contents as a claim from that party rather than as fact. Anything with money attached still gets confirmed against what the market interface itself shows you.
- If it is only a claim
- Treat the content as unsourced and go and find the same statement somewhere you reached under your own steam. If it exists there, you never needed the message. If it does not, you have learned something more useful than the message was offering.
The way this shades into reputation is covered at feedback or evidence, since a signed statement is one of the few things in this trade that can act as a record rather than an impression.
Questions readers send about this pair
The message came with its own key. Is that not enough?
No, and this is the common trap. A key included with the message proves the sender signed with the key they supplied. Any sender can do that. The key has to have reached you earlier, by a route with no connection to the message you are examining.
Where should a key have come from?
Somewhere you went to yourself, before you had any pressing reason to want the key, and ideally somewhere you have used since without incident. The value comes from the gap in time and the absence of a link, not from the source looking authoritative.
If the signature verifies, is the message true?
It means the text has not been altered since that key signed it. Truthfulness is a different question and no signature has ever answered it. Someone can sign a false statement perfectly.