@Person pretending to be me > Yes. Signatures are not random. Your website proves nothing. Produce a PrivateKey/PublicKey pair, Announce your PublicKey. Announce the crypto algorithm. Sign the posts using your PrivateKey. I'm at the point that I'm ready to write you off as a troll. Perhaps you're used to being the smartest person in the room, but this is a security blog and people here will call you out on your BS. When you hand wave things like "Announce your PublicKey", you show no understanding of how that fundamentally does *not* establish the trust you assert it does. You have yet to answer the epistemological question of identity. You have yet to outline a process that doesn't involve "chasing ghosts". >> How are you going to verify that signature is really me? > > Ding! Ding! Ding! We have a winner! Since you don't answer that question, you don't win anything. If you are indeed arguing in good faith and *not* a troll, please demonstrate it by creating a pseudo-anonymous identity by the process you give at the start of your post (or any other one of your choosing), and then use it for all your future posts so that people here can verify it's you. If it is demonstrably better than my process, I'll adopt it and *then* you can do more than pretend you're a winner. > Spot the problem? No. If you have a point to make, actually spell it out. Just because Bruce's blog allows fake comment attribution only speaks to the topic at hand. If you think your surface fake of me is a problem, then all you do is make everyone question the legitimacy of *every* post here. Since my actual posts are stored on my own server, though, your fake would fail any attempts at validation. It is not at all obvious to me that your precious signature solution is better for this blog. As the old saying goes, put up or shut up. Because right now, all your straw men have done nothing to show that you can pretend to be me in any material way. 27b3200321cb57ba0c3380d521ba10469cde458d7b5db25d4f1ea023a7d5ce10