Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.project > #11979

Re: Keysigning in times of COVID-19

From Olek Wojnar <olek@debian.org>
Newsgroups linux.debian.project
Subject Re: Keysigning in times of COVID-19
Date 2020-08-08 22:50 +0200
Message-ID <ABDWW-eO-1@gated-at.bofh.it> (permalink)
References <AB64W-52C-5@gated-at.bofh.it> <AB6xZ-5rN-17@gated-at.bofh.it> <ABgnD-2QP-3@gated-at.bofh.it> <ABmjn-6lb-3@gated-at.bofh.it> <ABzTj-6jx-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Hi Sam,

On Sat, Aug 8, 2020, 11:46 Sam Hartman <hartmans@debian.org> wrote:

>
> TL;DR: While there may be improvements to be found in a completely
> different approach to identity, let us not let the scope of the
> discussion broaden that far, so we can make progress today.
>

I respectful disagree on this point. This conversation started with a
question about how to verify identity without in-person interaction. The
reason a number of people have seemingly broadened the scope (from my
perspective, I clearly don't know people's actual motivations) is because
that is the deeper question behind the original query.

>>>>> "Olek" == Olek Wojnar <olek@debian.org> writes:
>
>     Olek> Thanks to some great tools, it's fairly easy to
>     Olek> verify that they do indeed control the email addresses tied to
>     Olek> their key. That's what I care about at that point in time.
>
> For me, that's not nearly enough.
> If all you want to do is verify that a particular point in time, an
> email address belongs to a key, set up a service to do that.
>

I was referring to the caff package.

When I sign a key I am signing a certification that I believe
> 1) the key and
> 2) the real world identity
>
> correspond to the digital identity in the FLOSS community represented by
> the claimed email address.
>

That is how I have always done it as well but this conversation is making
me rethink the *why* of that process.

I don't want to throw out what we have without a viable suggestion that
> the project can get behind.
>

Agreed.

So, let's focus this thread on key signing and how to adapt that because
> it's what we have today and because we're looking for some short-term
> answers.
> If you want to start a different thread proposing to revamp how we think
> about identity, go for it.
>

Again, I disagree that these are distinct topics. I think they are
intrinsically linked.

There have been some good points so far about the value of having a
real-world identity connected to your Debian identity for reasons of
accountability and liability. There have also been good points about
personal privacy. (Dissident Test, anyone?)

I was just recently speaking with a prospective first-time contributor who
was very excited about being involved in the project but was not
comfortable sharing their real life identity. Do we turn people like that
away or welcome their contributions into the project once we have validated
their reliability and trustworthiness *in the scope of the Debian Project*?
Do we absolutely *have* to have a real life identity connected to someone
to sign their key? Or to accept a patch? Or a packaging job? Or permissions
as a DM?

I'm not advocating a position since I'm not 100% sure what the answer
should be. But I think that these are important questions to ask ourselves
and an important conversation to have. Perhaps this will eventually lead to
a GR, or perhaps we'll develop a consensus here. But we absolutely need to
be having this conversation and considering all points of view and
repercussions.

-Olek

>

Back to linux.debian.project | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: Keysigning in times of COVID-19 Gerardo Ballabio <gerardo.ballabio@gmail.com> - 2020-08-07 10:40 +0200
  Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-07 11:10 +0200
    Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-07 21:40 +0200
      Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-07 22:50 +0200
        Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-08 00:00 +0200
          Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-08 04:00 +0200
      Re: Keysigning in times of COVID-19 Cindy Sue Causey <butterflybytes@gmail.com> - 2020-08-07 23:30 +0200
      Re: Keysigning in times of COVID-19 Olek Wojnar <olek@debian.org> - 2020-08-08 04:00 +0200
        Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-08 18:30 +0200
          Re: Keysigning in times of COVID-19 Olek Wojnar <olek@debian.org> - 2020-08-08 22:50 +0200
            Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-09 01:10 +0200
              Re: Keysigning in times of COVID-19 Olek Wojnar <olek@debian.org> - 2020-08-09 03:40 +0200
                Re: Keysigning in times of COVID-19 Felix Lechner <felix.lechner@lease-up.com> - 2020-08-09 07:40 +0200
                Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-09 15:10 +0200
                Re: Keysigning in times of COVID-19 Holger Levsen <holger@layer-acht.org> - 2020-08-10 12:00 +0200
                How to Value a Community Sam Hartman <hartmans@debian.org> - 2020-08-10 14:20 +0200
              Re: Keysigning in times of COVID-19 Eldon Koyle <ekoyle@gmail.com> - 2020-08-09 06:20 +0200

csiph-web