Currently, the `trust.BasicVerifier` discards all signatures as invalid if the timestamp is in the future. We should make the verifier configurable to allow small time diffs in the future to allow for clock drift.