Every public pick, sealed before kick-off
Anyone can post winners after the match. So before every match, each new pick is sealed by an independent timestamp authority, using its clock, not ours. After kick-off the pick and its seal are published, and you can check that the pick existed, unchanged, before the game started. 136 picks sealed since 28 Sept 11:16 UTC.
Sealed 4 min before kick-offby DigiCert, an independent timestamp authority
Presidents Cup
Al Arabi vs Al Thaid
Home win @ 2.05
- Sealed at (the authority’s clock)
- 28 Sept, 14:36 UTC
- Kick-off
- 28 Sept, 14:40 UTC
How it works
01
Hash the pick
Every 5 minutes, new picks (match, market, selection, the price we grade them at, time) are written one per line and turned into a SHA-256 fingerprint. Change one character and the fingerprint changes.02
An authority signs it
Only the fingerprint is sent to DigiCert’s public timestamp authority (FreeTSA as backup). It signs the fingerprint with the time on its own clock (the RFC 3161 standard used for code signing).03
Published after kick-off
Once all its matches have started, the file and the signed seal are published here and on GitHub. A pending pick is never revealed early.
Check it with one command
The browser check above reads the fingerprint and time inside the seal. To also check the authority’s signature, download a batch’s two files and run:
openssl ts -verify -data 123.jsonl -in 123.tsr -CAfile /etc/ssl/cert.pem openssl ts -reply -in 123.tsr -text | grep "Time stamp"
“Verification: OK” plus a time earlier than the pick’s kick-off means the pick existed before the match. On Linux use /etc/ssl/certs/ca-certificates.crt. The same files are in the public GitHub ledger.
What the seal does not prove
- That a pick is good. It proves when we made it, not whether it wins.
- Picks from before 28 Sept 11:16 UTC. Those are timed by our own database, and the ones we posted to Telegram carry Telegram’s post time.
- That we publish every pick we make. That is what the full record and the corrections list are for.