[HN Gopher] Before passwords - ribbons and seals for document se...
       ___________________________________________________________________
        
       Before passwords - ribbons and seals for document security (2021)
        
       Author : hhs
       Score  : 34 points
       Date   : 2022-02-06 16:32 UTC (6 hours ago)
        
 (HTM) web link (prologue.blogs.archives.gov)
 (TXT) w3m dump (prologue.blogs.archives.gov)
        
       | Pinus wrote:
       | There is a legend in Sweden, that during some power struggle in
       | the 16th century, several high-ranking persons had put their
       | seals on a document which, after a change in political tides, put
       | them at a very real risk of losing their heads in the event now
       | known as "the Stockholm bloodbath". One of them -- the bishop
       | Hans Brask -- then cracked open his seal to reveal a note saying
       | (in 15xx Swedish) "I'm being forced to do this". He got to keep
       | his head, and the word "brasklapp" (literally "Brask note") now
       | means a reservation or caveat.
        
       | crumbits wrote:
       | Anybody who finds this interesting should look into tughras.
        
       | timwis wrote:
       | It strikes me that when we say we're "signing" a file/commit/etc.
       | (using a key), a "seal" is probably a more appropriate analogy,
       | since someone could steal your key just as someone could steal
       | the seal.
        
         | NoSorryCannot wrote:
         | The essential property of seals is that they are fragile and
         | offer tamper evidence. Removing a seal or opening a sealed
         | document is supposed to be destructive to the seal, the
         | document, or both. Seals are still used for this purpose.
         | 
         | Electronic signatures don't have this property.
        
           | timwis wrote:
           | Doh, good point! A stamp of a signature would perhaps be more
           | fitting.
        
             | dredmorbius wrote:
             | Those would be seals (usually _royal_ seals), in European
             | usage.
             | 
             | In Japan, Hanko or Inkan:
             | 
             | https://en.wikipedia.org/wiki/Seal_(East_Asia)#Japanese_usa
             | g...
        
               | thaumasiotes wrote:
               | > Those would be seals (usually royal seals), in European
               | usage.
               | 
               | Well, the European usage is to call them seals in a
               | European or Near Eastern context. For some reason,
               | exactly the same thing in an Asian context is often
               | called a "chop" in European usage.
        
           | upofadown wrote:
           | Tamper evidence is actually the only thing that cryptographic
           | signatures provide. If either the "document" or signature is
           | modified then verification fails.
           | 
           | Cryptographic signatures don't provide evidence that someone
           | looked at the "document" in transit. For that we use a
           | separate sort of thing called encryption. The two things work
           | together to provide the equivalent of a sealed envelope or
           | securely folded paper document.
        
       | 0xbadcafebee wrote:
       | DEFCON has a Tamper Evident Village where you can learn all sorts
       | of ways to defeat tamper-evident seals. There's also some links
       | to papers from Schneier's blog:
       | https://www.schneier.com/blog/archives/2013/02/security_seal...
        
       | dano wrote:
       | You maybe interested in the articles at the Journal of Physical
       | Security https://jps.rbsekurity.com
        
       | bigmattystyles wrote:
       | Should this be `before certificates`? The seal didn't stop you
       | from opening or viewing, just tried to establish authenticity and
       | first viewing. (I realize certs don't guarantee first viewing)
        
       | shimonabi wrote:
       | As a kid, I would find red vax seal sticks in the drawers,
       | because my mom worked for a bank where they sealed the cash into
       | envelopes for some reason.
        
       | brnaftr361 wrote:
       | I really like tally sticks[0]. Obscenely simple, but profoundly
       | secure. You've got the species of wood, the unique grain, exact
       | dimensions, the exact partnership between the two pieces, the
       | human scrawling... This multi-dimesional identifying mechanism
       | and it's little more than a couple of mundane pieces of wood with
       | some contract etched into it.
       | 
       | [0]https://en.wikipedia.org/wiki/Tally_stick
        
         | marvel_boy wrote:
         | Here is also more about split tally sticks in medieval times:
         | https://www.youtube.com/watch?v=2DkyahZplFo
        
         | dredmorbius wrote:
         | Just ... be careful in disposal.
         | 
         | https://en.wikipedia.org/wiki/Burning_of_Parliament
        
       | dredmorbius wrote:
       | Some years ago I had the opportunity to visit a switch control
       | tower at a rail yard.
       | 
       | As with much else in the technological built landscape, what I'd
       | not realised before that time was how much of the structure was
       | devoted to, and determined by _mechanism_. Moving a switch
       | control in the tower itself activated a relay which moved a lever
       | arm, which _through mechanical coupling_ moved the actual rail
       | points.
       | 
       | (This is no longer always the case, but for older infrastructure,
       | and this dated to at least the 1930s, it's quite common.)
       | 
       | The operater interfaces were themselves secured and sealed. The
       | operator rather delightedly showed how the seals could be readily
       | removed without any apparent sign of having done so....
       | 
       | Times, locations, and personnel left intentionally vague, though
       | few of those involved are likely still alive.
        
       | sowbug wrote:
       | Tangentially related: digital currencies like Bitcoin and
       | Ethereum have spawned a burgeoning physical-document-security
       | industry. If you don't want your private key to leave the
       | airgapped computer that created it, but you do want a backup,
       | then you might manually etch, engrave, or stamp your key onto
       | metal rectangles. Some companies are now providing kits to
       | facilitate this tedious process. It's a little steampunk.
       | 
       | Even more tangentially related: if you've seen the _Rick and
       | Morty_ episode  "Morty's Mind Blowers," do you know the name of
       | the red container that Summer snapped open to reveal emergency
       | recovery instructions? You also see them in old Atomic Age
       | movies. I don't know if they've had any practical application in
       | the last 20-30 years, but they are pretty cool and maybe useful
       | for protecting the secrets mentioned above.
        
       | Terry_Roll wrote:
       | Something not mentioned is the additional security built into the
       | obvious wax seal.
       | 
       | So in order to test couriers credibility and trustworthyness to
       | deliver wax sealed parchments, a courier would be required to
       | collect and deliver said parchment in a controlled experiment. So
       | the route would be lined with spies in on the test who could
       | report back anything untoward. The wax seal would be laced with
       | Atropa Belladonna[1] which when inhaled from melted wax would
       | cause the pupils to dilate and the delivery point would be dark.
       | So when the courier handed over the parchment a lantern would be
       | held up to the couriers face to see if the pupils constricted in
       | the light. If the courier had melted the wax laced with
       | belladonna, their pupils would look like saucers and the
       | recipient would know the wax seal had been melted & vapours
       | inhaled. It was a measure to protect against counterfeiting wax
       | seals.
       | 
       | I dont think this knowledge made it to the US, but it was very
       | common in Europe.
       | 
       | Loyalty & trustworthy tests still go on today, but they have
       | evolved somewhat with the times, but you may not even realise you
       | have been tested!
       | 
       | [1] https://www.historyandwomen.com/2012/07/fatal-
       | beauty.html#:~....
        
       | daenz wrote:
       | Impressive but honestly I am more impressed by the quality of
       | handwriting at that time. The penmanship appears flawless and
       | beautiful. I'm not seeing any typos or corrections. The authors
       | must have had incredible focus and a crystal clear vision about
       | what exactly they were going to communicate (certainly from many
       | previous drafts). It makes me think that we lost something
       | valuable when our published words became so "cheap" by
       | comparison.
        
         | NoSorryCannot wrote:
         | If it helps, these documents were not written down by the
         | authors but by a professional scribe whose job it was to write
         | a beautiful page, or to keep trying until it was just so.
         | 
         | The handwriting in historical letters, while still often
         | beautiful, was not perfect and had errors.
        
         | hhs wrote:
         | If interested, there was a post on Timothy Matlack's great
         | penmanship with writing the Declaration of Independence:
         | https://prologue.blogs.archives.gov/2021/07/01/the-power-of-...
        
           | lelandfe wrote:
           | > The formality and skill of the engrossed copy strengthened
           | the persuasiveness of the Declaration by distancing its
           | arguments from any individual. The document [also] helped
           | protect the identities of the signers -- the names were kept
           | secret until 1777
           | 
           | This is a fascinating aside that I'd never considered before
           | (and I did not know that the signatories were kept secret for
           | some time). Thanks for the link.
           | 
           | I wonder if keeping the signatories secret was done to
           | temporarily give the appearance of unanimity, since some
           | congressmen refused to sign.
        
       ___________________________________________________________________
       (page generated 2022-02-06 23:01 UTC)