• bandwidthcrisis@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    20 hours ago

    A digital signature from the label would be created with their private key.

    What would they be signing? Your public key plus the ID of the song? They can’t sign your private key, it’s private.

    What stops you sharing your private key and a song with a friend. Then when either of you need to provide proof, you can both show that you have the private key that matches the signed file?

    • owl@infosec.pub
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      28 minutes ago

      Well they would sign my public key plus ID of the song. I can prove, it is my public key and everyone can verify the song belongs to me.

      You are right, to ensure noone can “share login” so to say, it needs to be tied to you personally. That would deny privacy sadly.

      EDIT: Didn’t notice I wrote the wrong thing, thanks for notifying me.