On Sat, 10 May 2008 10:17:06 +0100, "\(not quite so\) Fat Sam"
wrote:
>> All it proves of course is that you had the document in your
>> possession at some time. It does not prove that you are the author of
>> the document. Anyone could take the document, remove your digital
>> signature, append their own and republish it.
>But surely that's the whole point of checksum verification that the OP was
>asking about.
>If someone did change a part of the document - even a digital signature -
>that would instantly indicate alteration or tampering as the acompanying
>code would be different. It wouldn't indicate what exactly had been changed,
>but it would show that a change had been made.
You can easily remove a digital signature and append a different one.
The only way around that would be to add a digital *watermark*, which
I is not really possible with any text based document.
--
Cynic
|