"Trustworthy" PGP Timestamping Service ??

Matthew Richardson matthew at itconsult.co.uk
Sun Jan 21 11:02:30 PST 1996


-----BEGIN PGP SIGNED MESSAGE-----

I have recently setup a free PGP timestamping service which operates 
by email.

The objective of the service is to be able to produce "trustworthy" 
timestamps which cannot be backdated without detection.  It achieves 
this by:-

(a)  giving every signature a unique sequential serial number;

(b)  every day making a ZIP file of that day's detached signatures 
and feeding the ZIP file back for signing (and hence the assignment 
of another serial number);

(c)  making available details of the highest serial number on each 
day as well as the signed ZIP files via email (and shortly WWW);

(d)  weekly publishing details of the DETACHED signatures of the ZIP 
file in alt.security.pgp and to users requesting them on a list 
server.

I would be interested in folks comments on this "trustworthiness", 
including any weaknesses or possible improvements.

Full details of the service can be found at:-
     http://www.itconsult.co.uk/stamper.htm

Thank you in advance.

Best wishes,
Matthew

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2i

iQCVAgUBMQKHtAKwLwcHEv69AQFVLgQAjVyX5w0YM75gskinZ74dkqQ9vDfnOlWt
OD28p/0ot+85q+UP8hreS61Fs1bGDqgH5YL3/2Lviy+xhlIj9x8kVw+Rj1KrZvI+
Jt7pInfqwdx9gYxVGDuP0rIcCH+74vFWQJu1UMpZWORq4gv4t/IS1cBJJRaYSyrM
hhcdHPRU6RE=
=qD+L
-----END PGP SIGNATURE-----







More information about the cypherpunks-legacy mailing list