For a given signature block and any other data, there exists a key whi
ch produces the same signature block. The threat that this poses to sc
hemes which use nested signature blocks as pointers to other tokens is
identified, using a theft-proof capability mechanism as an illustrati
on. A modification to public key certificates is then proposed to elim
inate this threat.