Hi Pilou,
as example: For my Bubo and Bugi bunnies, where i provided the models
for free download (for-non-commercial usage) i digitally signed the model
file with a detached signature (a separate signature file) with GnuPG and
then i time stamped the signature file. So when someone downloads my
model file he/she can use it freely, for non-comercial use, but he/she can
easily verify that *i* signed* the model file and with verifying the time stamp
(he/she can use the time stamp service and upload the time stamp
file and the signature file) they know that i signed this model file at a certain
time. Should someone remove those files and distributes the model file later
i can easily proof that my original .zip archive (with the model file
and the time stamp and signature file) was distributed without all the
other files included.
*the GnuPG signature can't be faked or cracked. My public GnuPG key
is also certified by a German Certification Authority and the procedure
used to certify my GnuPG key can not be faked either, unless of course
someone is capable to crack and copy the new German ID Card and
steal the passphrase of my GnuPG secret key.
The time stamp file is also registered in the Bitcoin blockchain and this
data can't be removed from the blockchain or been manipulated later
in the blockchain.
Regards
Stefan
|