A signature with an old date
Everything checks out. Right key, valid signature, unaltered text. And the announcement you are reading was true in March, which is a different thing from being true now.
- What it is
- A genuine signed statement being presented as current
- Where you meet it
- Copies of market pages, directories, forum posts
- What it settles
- That the text is authentic and unaltered
- Cannot tell you
- That it still applies, which is usually what you wanted
The specimen
gpg: using RSA key 4A2F 91C7 … A8E3 04FB
gpg: Good signature from "Torzon Market <…>"
Torzon address set, published 2026-03-07
today is months later, and the page presenting this says nothing about that
A real signature, reused. Salmon marks the two dates, one from the tool and one from inside the signed text. They agree, which is normal. What matters is the gap between them and today, and no software will point that out for you.
Why replay works
A signature has no expiry. It says this text came from this key, and that stays true forever. There is nothing built into the format to say the statement is still the current one, because the format was never trying to answer that question.
So an old announcement that was completely genuine when published can be lifted whole and put on a page today. Nothing has been forged. Nothing fails. The only wrong part is the framing around it, and the framing is not signed.
Where to look for the date
| Where | How much it is worth |
|---|---|
| Inside the signed text | The one that counts. It is covered by the signature |
| In the tool output | Also covered. Fine to use |
| On the page around the block | Nothing. Not signed, so it can say anything |
| A last updated line on the site | Nothing, for the same reason |
What counts as recent
There is no fixed number, and anybody giving you one is inventing it. What is reasonable is a rule of thumb: a set of addresses published within the last few weeks is ordinary, one from several months ago is worth a second source before you rely on it, and one from a year ago is a historical document. Also check the obvious thing, which is whether the addresses in it appear anywhere current at all.
The whole habit in one line
Read which key signed, then read when. Two questions, both answered by output you are already looking at, and between them they close the two ways a verification can succeed while telling you nothing useful.
The cheapest cross check
Take one address out of the signed set and see whether it appears in any current list from somewhere unrelated. If a set is months old and none of it turns up anywhere else today, you are reading a historical document. This takes about a minute and it catches the case where everything about the signature is genuine and the framing around it is not.