Post
Topic
Board Meta
Re: My trust :( im not alt Candystripes accounts!
by
Quickseller
on 19/02/2015, 13:26:33 UTC
aren't they time stamped based on the time of my computer though? If I were to change the date/time on my computer then it would show as being signed at a different time. Plus some may not be savvy enough to check the time of the signature.

It is based on the time on your computer, but most PGP clients will change the timezone to UTC to prevent your timezone from being disclosed. Yep this can be faked, but so can the time you put in the message (you could be lying). You can however configure your PGP client to use a trusted timestamp server, though there aren't many of these as this functionality is really old and not used much. This will prove that the message was signed on or after the time specified, it wouldn't be possible for the message to be signed before the time specified unless the timestamp server was acting malicious.

Most (all) PGP clients will display the date and time the message was signed and you are supposed to check it.
I assume that using a time stamp authority is done by the person signing the message, and that in order to use one then the computer that holds the private key must be connected to the Internet.