Rewrite audit-ready briefing: software is not a certificate.
Some checks are pending
ci / markdown (push) Waiting to run
Some checks are pending
ci / markdown (push) Waiting to run
Open with an executive summary that HIPAA, SOC 2, and ISO 27001 are organizational programs. Verae DataCubes supply store, communicate, timestamp, verify, and audit tools for the technical portion only. Chapters cover transit (HPKE, visible routing), rest (IPFS/Peergos hash-verified restore), receipts, EU Peergos evaluations (Cure53 2019, ROS 2024), cross-blockchain timestamping, and write-once Iceberg archive. PDF is branded with the Verae logo top-left and Verae Inc contact in the footer; last chapters are sourced bios for Garfinkel (FINRA CRD 5052743), Haber, and Lambert.
This commit is contained in:
parent
da60402e88
commit
4fcbb9ac95
53 changed files with 6323 additions and 814 deletions
110
source/bio-stuart-haber.rst
Normal file
110
source/bio-stuart-haber.rst
Normal file
|
|
@ -0,0 +1,110 @@
|
|||
Stuart Haber
|
||||
============
|
||||
|
||||
Role at Verae
|
||||
-------------
|
||||
|
||||
**Stuart Haber** is a **co-founder of Verae**. The company's
|
||||
public site introduces him as one of the creators of
|
||||
blockchain and as the inventor, in 1991, of cryptographic
|
||||
timestamping --- "the science that lets you prove a record
|
||||
hasn't been altered, and the foundation under every
|
||||
blockchain since." The site quotes him:
|
||||
|
||||
"I co-founded Verae to make blockchain accessible to
|
||||
enterprises without having to deal with the complexity of
|
||||
blockchain."
|
||||
|
||||
--- Stuart Haber, Co-Founder of Verae; co-inventor of
|
||||
blockchain timestamping, 1991
|
||||
|
||||
Verae's product claim is that this is the proof Haber has
|
||||
been building toward: simple enough for a compliance team,
|
||||
precise enough for an SEC exam, with the customer's records
|
||||
remaining in the customer's storage and only a fingerprint
|
||||
being sealed.
|
||||
|
||||
The scientific work
|
||||
-------------------
|
||||
|
||||
Haber is a cryptographer. He worked at **Bellcore** (Bell
|
||||
Communications Research) in Morristown, New Jersey, in the
|
||||
late 1980s and 1990s, in the research culture descended from
|
||||
Bell Labs. With physicist **W. Scott Stornetta** he posed a
|
||||
problem that looks obvious only after it is solved: digital
|
||||
documents live on media that can be altered without a mark;
|
||||
how do you certify **when the bits existed**, without
|
||||
trusting the disk, and without handing the document to the
|
||||
timestamping service?
|
||||
|
||||
**1991.** Stuart Haber and W. Scott Stornetta, "How to
|
||||
Time-Stamp a Digital Document," *Journal of Cryptology*,
|
||||
volume 3, number 2, pages 99--111. This is the paper that
|
||||
introduces computationally practical digital timestamping
|
||||
so that a user cannot back-date or forward-date a document
|
||||
even with the collusion of a timestamping service, while
|
||||
keeping the document itself private. Bitcoin's white paper
|
||||
cites it as reference **[3]**.
|
||||
|
||||
**1993.** Dave Bayer, Stuart Haber, and W. Scott Stornetta,
|
||||
"Improving the Efficiency and Reliability of Digital
|
||||
Time-Stamping," in *Sequences II: Methods in Communication,
|
||||
Security and Computer Science*, pages 329--334. Merkle
|
||||
trees, efficient certificates, publication of a compact
|
||||
root. Bitcoin's white paper cites it as reference **[4]**.
|
||||
|
||||
**1997.** Stuart Haber and W. Scott Stornetta, "Secure names
|
||||
for bit-strings," *Proceedings of the 4th ACM Conference on
|
||||
Computer and Communications Security*, pages 28--35. Bitcoin's
|
||||
white paper cites it as reference **[5]**.
|
||||
|
||||
Those three papers are **three of the eight** citations in
|
||||
Satoshi Nakamoto, "Bitcoin: A Peer-to-Peer Electronic Cash
|
||||
System" (2008). Haber has remarked that this is a .375
|
||||
batting average, and that Bitcoin is an application built on
|
||||
top of the early blockchain rather than the invention of the
|
||||
data structure itself. That is a historical statement, not a
|
||||
claim that Verae is Bitcoin.
|
||||
|
||||
Surety, 1994: first commercial blockchain
|
||||
-----------------------------------------
|
||||
|
||||
Haber and Stornetta took the research into production as
|
||||
**Surety**. Surety hashed customer documents, linked those
|
||||
hashes in a chain of certificates, and published a weekly
|
||||
summary hash in the classified section of the Sunday *New
|
||||
York Times*. That analog publication is widely described as
|
||||
the oldest surviving public blockchain: a commitment that
|
||||
does not depend on Surety's servers remaining honest or
|
||||
online, because the *Times* is independently archived. The
|
||||
design idea --- **commit a compact fingerprint to a widely
|
||||
witnessed record, without revealing the documents** --- is
|
||||
the same idea Verae productizes for enterprise compliance.
|
||||
|
||||
Other cryptographic publications
|
||||
--------------------------------
|
||||
|
||||
Haber's research record is broader than timestamping. It
|
||||
includes work on minimum-knowledge interactive proofs,
|
||||
symmetric public-key encryption, and secure multi-party
|
||||
protocols (including "Cryptographic Computation: Secure
|
||||
Fault-Tolerant Protocols and the Public-Key Model"). A
|
||||
reader who wants the academic trail should start with the
|
||||
three Bitcoin-cited papers and the 1991 *Journal of
|
||||
Cryptology* article, then the ACM CCS 1997 paper.
|
||||
|
||||
Why this biography is in the briefing
|
||||
-------------------------------------
|
||||
|
||||
Timestamping in this document is not a metaphor. It is a
|
||||
specific scientific object --- hash, time, sequence, privacy
|
||||
of the document from the notary --- that Haber defined in
|
||||
print in 1991, commercialized in 1994, and is now building
|
||||
into Verae so that a CCO can produce a receipt instead of a
|
||||
vendor letter. The biography is here as **provenance of the
|
||||
receipt**, not as a substitute for the organization's
|
||||
controls.
|
||||
|
||||
The same honesty that applies to Peergos applies here:
|
||||
Haber co-invented the timestamping chain; he did not issue
|
||||
the customer's SOC 2.
|
||||
Loading…
Add table
Add a link
Reference in a new issue