@SpaceLifeForm > A hash is not a signature. I never said it was one. When you start off with a straw man like that, you completely undermine your position. Your comments are in many ways *worse* than the fake comments that can be generated by algorithms. > But why should I chase ghosts on another site? Are you even following the topic at hand? The aim is to validate comments that people make. A challenge-response process that I use is one such way. The question you should be asking is: why should I trust that the comments I read here are real? It's *this* site that is full of ghosts; my site contains my *real* comments. The fact that you must "chase" them down is an unfortunate artifact of how web sites evolved to be silos that attempt to control their visitors. Any site *could* allow distributed commenting, but that would involve acknowledging that they don't actually own their users speech. > Can you guarantee that? To the extent that a cryptographically secure hash can guarantee anything, yes; if that's not enough for you, you'll find that you have zero security *anywhere* on the Internet, so you shouldn't even be here if your safety is important to you. Even MD5 functions as a usable hash for comments and other structured content, because forcing a collision is likely to result in something that contains a lot of nonsense that makes it clear it was the result of an attack. > From your perspective. No, from a mathematical perspective. You keep showing that you don't really understand how these things work. > Your hash proves nothing to the outside public. It is not a signature. Wait, are you seriously saying that me standing behind the comments on my server is *less* believable than random comments on some random site with some random signature? You trot out signatures as a straw man, yet they seem to be just another thing you don't understand. How are you going to verify that signature is really *me*? Explain it without having to "chase ghosts", which you so bemoan. > No one said that. You're the one that said: "That is exactly what troll farms do.", so if that's anyone's straw man to own, it's another one of yours. If you actually understand what a web of trust is, please explain further how troll farms would use it to trick Bruce (or anyone else) into necessarily posting garbage comments. To those in the know, a web of trust allows exactly the *opposite*, helping you to identify the associates of bad commenters and preventing them from overrunning a site. > But a SHA-256 hash is not a signature. It’s just not. Do not deceive yourself. Again, never said it was. That you believe otherwise is a self deception. It's sadly a popular way to view the world these days. Just the same, I encourage you to stop doing it. c2e384cdff6be5d08c9be561ff4d871b74764fce17a04433c455b14e9116dbd4