Rewrite audit-ready briefing: software is not a certificate.
Some checks are pending
ci / markdown (push) Waiting to run
Some checks are pending
ci / markdown (push) Waiting to run
Open with an executive summary that HIPAA, SOC 2, and ISO 27001 are organizational programs. Verae DataCubes supply store, communicate, timestamp, verify, and audit tools for the technical portion only. Chapters cover transit (HPKE, visible routing), rest (IPFS/Peergos hash-verified restore), receipts, EU Peergos evaluations (Cure53 2019, ROS 2024), cross-blockchain timestamping, and write-once Iceberg archive. PDF is branded with the Verae logo top-left and Verae Inc contact in the footer; last chapters are sourced bios for Garfinkel (FINRA CRD 5052743), Haber, and Lambert.
This commit is contained in:
parent
da60402e88
commit
4fcbb9ac95
53 changed files with 6323 additions and 814 deletions
240
build/html/bio-stuart-haber.html
Normal file
240
build/html/bio-stuart-haber.html
Normal file
|
|
@ -0,0 +1,240 @@
|
|||
<!DOCTYPE html>
|
||||
|
||||
<html lang="en" data-content_root="./">
|
||||
<head>
|
||||
<meta charset="utf-8" />
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
|
||||
|
||||
<title>15. Stuart Haber — Making yourself audit-ready with Verae DataCubes</title>
|
||||
<link rel="stylesheet" type="text/css" href="_static/pygments.css?v=5ecbeea2" />
|
||||
<link rel="stylesheet" type="text/css" href="_static/basic.css?v=b08954a9" />
|
||||
<link rel="stylesheet" type="text/css" href="_static/alabaster.css?v=2a97f0c7" />
|
||||
<link rel="stylesheet" type="text/css" href="_static/verae.css?v=050b9d5b" />
|
||||
<script src="_static/documentation_options.js?v=250a654d"></script>
|
||||
<script src="_static/doctools.js?v=fd6eb6e6"></script>
|
||||
<script src="_static/sphinx_highlight.js?v=6ffebe34"></script>
|
||||
<link rel="icon" href="_static/VeraeFullLogo.png"/>
|
||||
<link rel="index" title="Index" href="genindex.html" />
|
||||
<link rel="search" title="Search" href="search.html" />
|
||||
<link rel="next" title="16. George Lambert" href="bio-george-lambert.html" />
|
||||
<link rel="prev" title="14. James H. Garfinkel" href="bio-james-garfinkel.html" />
|
||||
|
||||
<link rel="stylesheet" href="_static/custom.css" type="text/css" />
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
</head><body>
|
||||
<div class="document">
|
||||
|
||||
<div class="sphinxsidebar" role="navigation" aria-label="Main">
|
||||
<div class="sphinxsidebarwrapper">
|
||||
<p class="logo"><a href="index.html">
|
||||
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo of Making yourself audit-ready with Verae DataCubes"/>
|
||||
</a></p>
|
||||
<p class="logo">
|
||||
<a href="index.html">
|
||||
<img class="logo" src="_static/VeraeFullLogo.png" alt="Logo" />
|
||||
|
||||
</a>
|
||||
</p>
|
||||
|
||||
|
||||
|
||||
<p class="blurb">Tools for storage, communications, timestamping, verification, and audit — not a certificate.</p>
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
<search id="searchbox" style="display: none" role="search">
|
||||
<div class="searchformwrapper">
|
||||
<form class="search" action="search.html" method="get">
|
||||
<input type="text" name="q" aria-labelledby="searchlabel" autocomplete="off" autocorrect="off" autocapitalize="off" spellcheck="false" placeholder="Search"/>
|
||||
<input type="submit" value="Go" />
|
||||
</form>
|
||||
</div>
|
||||
</search>
|
||||
<script>document.getElementById('searchbox').style.display = "block"</script><h3>Navigation</h3>
|
||||
<p class="caption" role="heading"><span class="caption-text">Contents</span></p>
|
||||
<ul class="current">
|
||||
<li class="toctree-l1"><a class="reference internal" href="executive.html">1. Executive summary</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="what-verae-provides.html">2. What Verae provides — and what it does not</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="datacube-server.html">3. The Verae DataCube Server Solution</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="data-in-transit.html">4. Secure communications — data in transit</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="data-at-rest.html">5. Encryption at rest — IPFS blocks and Peergos</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="timestamped-receipts.html">6. Global timestamped receipts</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="peergos-eu-evaluations.html">7. Peergos security evaluations in Europe</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="global-timestamping.html">8. Verae global timestamping — a cross-blockchain receipt</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="iceberg-archive.html">9. Write-once Iceberg archive</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="architecture.html">10. Architecture for an audit interview</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="baa-dpa.html">11. BAAs, DPAs, and ciphertext without host keys</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="checklist.html">12. Audit-ready checklist</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="howto.html">13. How to use this briefing</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="bio-james-garfinkel.html">14. James H. Garfinkel</a></li>
|
||||
<li class="toctree-l1 current"><a class="current reference internal" href="#">15. Stuart Haber</a><ul>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#role-at-verae">15.1. Role at Verae</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#the-scientific-work">15.2. The scientific work</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#surety-1994-first-commercial-blockchain">15.3. Surety, 1994: first commercial blockchain</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#other-cryptographic-publications">15.4. Other cryptographic publications</a></li>
|
||||
<li class="toctree-l2"><a class="reference internal" href="#why-this-biography-is-in-the-briefing">15.5. Why this biography is in the briefing</a></li>
|
||||
</ul>
|
||||
</li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="bio-george-lambert.html">16. George Lambert</a></li>
|
||||
<li class="toctree-l1"><a class="reference internal" href="contact.html">17. Verae Inc — contact</a></li>
|
||||
</ul>
|
||||
|
||||
<div class="relations">
|
||||
<h3>Related Topics</h3>
|
||||
<ul>
|
||||
<li><a href="index.html">Documentation overview</a><ul>
|
||||
<li>Previous: <a href="bio-james-garfinkel.html" title="previous chapter"><span class="section-number">14. </span>James H. Garfinkel</a></li>
|
||||
<li>Next: <a href="bio-george-lambert.html" title="next chapter"><span class="section-number">16. </span>George Lambert</a></li>
|
||||
</ul></li>
|
||||
</ul>
|
||||
</div>
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
</div>
|
||||
</div>
|
||||
<div class="documentwrapper">
|
||||
<div class="bodywrapper">
|
||||
|
||||
|
||||
<div class="body" role="main">
|
||||
|
||||
<section id="stuart-haber">
|
||||
<h1><span class="section-number">15. </span>Stuart Haber<a class="headerlink" href="#stuart-haber" title="Link to this heading">¶</a></h1>
|
||||
<section id="role-at-verae">
|
||||
<h2><span class="section-number">15.1. </span>Role at Verae<a class="headerlink" href="#role-at-verae" title="Link to this heading">¶</a></h2>
|
||||
<p><strong>Stuart Haber</strong> is a <strong>co-founder of Verae</strong>. The company’s
|
||||
public site introduces him as one of the creators of
|
||||
blockchain and as the inventor, in 1991, of cryptographic
|
||||
timestamping — “the science that lets you prove a record
|
||||
hasn’t been altered, and the foundation under every
|
||||
blockchain since.” The site quotes him:</p>
|
||||
<blockquote>
|
||||
<div><p>“I co-founded Verae to make blockchain accessible to
|
||||
enterprises without having to deal with the complexity of
|
||||
blockchain.”</p>
|
||||
<p class="attribution">—Stuart Haber, Co-Founder of Verae; co-inventor of
|
||||
blockchain timestamping, 1991</p>
|
||||
</div></blockquote>
|
||||
<p>Verae’s product claim is that this is the proof Haber has
|
||||
been building toward: simple enough for a compliance team,
|
||||
precise enough for an SEC exam, with the customer’s records
|
||||
remaining in the customer’s storage and only a fingerprint
|
||||
being sealed.</p>
|
||||
</section>
|
||||
<section id="the-scientific-work">
|
||||
<h2><span class="section-number">15.2. </span>The scientific work<a class="headerlink" href="#the-scientific-work" title="Link to this heading">¶</a></h2>
|
||||
<p>Haber is a cryptographer. He worked at <strong>Bellcore</strong> (Bell
|
||||
Communications Research) in Morristown, New Jersey, in the
|
||||
late 1980s and 1990s, in the research culture descended from
|
||||
Bell Labs. With physicist <strong>W. Scott Stornetta</strong> he posed a
|
||||
problem that looks obvious only after it is solved: digital
|
||||
documents live on media that can be altered without a mark;
|
||||
how do you certify <strong>when the bits existed</strong>, without
|
||||
trusting the disk, and without handing the document to the
|
||||
timestamping service?</p>
|
||||
<p><strong>1991.</strong> Stuart Haber and W. Scott Stornetta, “How to
|
||||
Time-Stamp a Digital Document,” <em>Journal of Cryptology</em>,
|
||||
volume 3, number 2, pages 99–111. This is the paper that
|
||||
introduces computationally practical digital timestamping
|
||||
so that a user cannot back-date or forward-date a document
|
||||
even with the collusion of a timestamping service, while
|
||||
keeping the document itself private. Bitcoin’s white paper
|
||||
cites it as reference <strong>[3]</strong>.</p>
|
||||
<p><strong>1993.</strong> Dave Bayer, Stuart Haber, and W. Scott Stornetta,
|
||||
“Improving the Efficiency and Reliability of Digital
|
||||
Time-Stamping,” in <em>Sequences II: Methods in Communication,
|
||||
Security and Computer Science</em>, pages 329–334. Merkle
|
||||
trees, efficient certificates, publication of a compact
|
||||
root. Bitcoin’s white paper cites it as reference <strong>[4]</strong>.</p>
|
||||
<p><strong>1997.</strong> Stuart Haber and W. Scott Stornetta, “Secure names
|
||||
for bit-strings,” <em>Proceedings of the 4th ACM Conference on
|
||||
Computer and Communications Security</em>, pages 28–35. Bitcoin’s
|
||||
white paper cites it as reference <strong>[5]</strong>.</p>
|
||||
<p>Those three papers are <strong>three of the eight</strong> citations in
|
||||
Satoshi Nakamoto, “Bitcoin: A Peer-to-Peer Electronic Cash
|
||||
System” (2008). Haber has remarked that this is a .375
|
||||
batting average, and that Bitcoin is an application built on
|
||||
top of the early blockchain rather than the invention of the
|
||||
data structure itself. That is a historical statement, not a
|
||||
claim that Verae is Bitcoin.</p>
|
||||
</section>
|
||||
<section id="surety-1994-first-commercial-blockchain">
|
||||
<h2><span class="section-number">15.3. </span>Surety, 1994: first commercial blockchain<a class="headerlink" href="#surety-1994-first-commercial-blockchain" title="Link to this heading">¶</a></h2>
|
||||
<p>Haber and Stornetta took the research into production as
|
||||
<strong>Surety</strong>. Surety hashed customer documents, linked those
|
||||
hashes in a chain of certificates, and published a weekly
|
||||
summary hash in the classified section of the Sunday <em>New
|
||||
York Times</em>. That analog publication is widely described as
|
||||
the oldest surviving public blockchain: a commitment that
|
||||
does not depend on Surety’s servers remaining honest or
|
||||
online, because the <em>Times</em> is independently archived. The
|
||||
design idea — <strong>commit a compact fingerprint to a widely
|
||||
witnessed record, without revealing the documents</strong> — is
|
||||
the same idea Verae productizes for enterprise compliance.</p>
|
||||
</section>
|
||||
<section id="other-cryptographic-publications">
|
||||
<h2><span class="section-number">15.4. </span>Other cryptographic publications<a class="headerlink" href="#other-cryptographic-publications" title="Link to this heading">¶</a></h2>
|
||||
<p>Haber’s research record is broader than timestamping. It
|
||||
includes work on minimum-knowledge interactive proofs,
|
||||
symmetric public-key encryption, and secure multi-party
|
||||
protocols (including “Cryptographic Computation: Secure
|
||||
Fault-Tolerant Protocols and the Public-Key Model”). A
|
||||
reader who wants the academic trail should start with the
|
||||
three Bitcoin-cited papers and the 1991 <em>Journal of
|
||||
Cryptology</em> article, then the ACM CCS 1997 paper.</p>
|
||||
</section>
|
||||
<section id="why-this-biography-is-in-the-briefing">
|
||||
<h2><span class="section-number">15.5. </span>Why this biography is in the briefing<a class="headerlink" href="#why-this-biography-is-in-the-briefing" title="Link to this heading">¶</a></h2>
|
||||
<p>Timestamping in this document is not a metaphor. It is a
|
||||
specific scientific object — hash, time, sequence, privacy
|
||||
of the document from the notary — that Haber defined in
|
||||
print in 1991, commercialized in 1994, and is now building
|
||||
into Verae so that a CCO can produce a receipt instead of a
|
||||
vendor letter. The biography is here as <strong>provenance of the
|
||||
receipt</strong>, not as a substitute for the organization’s
|
||||
controls.</p>
|
||||
<p>The same honesty that applies to Peergos applies here:
|
||||
Haber co-invented the timestamping chain; he did not issue
|
||||
the customer’s SOC 2.</p>
|
||||
</section>
|
||||
</section>
|
||||
|
||||
|
||||
</div>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
<div class="clearer"></div>
|
||||
</div>
|
||||
<div class="verae-page-footer">
|
||||
<strong>Verae Inc</strong>
|
||||
· <a href="https://www.verae.com">https://www.verae.com</a>
|
||||
· Book a call at <a href="https://www.verae.com">verae.com</a>
|
||||
· <a href="https://app.verae.com">app.verae.com</a>
|
||||
</div>
|
||||
|
||||
<div class="footer">
|
||||
©2026, Verae Inc.
|
||||
|
||||
</div>
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
</body>
|
||||
</html>
|
||||
Loading…
Add table
Add a link
Reference in a new issue