Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.project > #11979

Re: Keysigning in times of COVID-19

Path csiph.com!aioe.org!bofh.it!news.nic.it!robomod
From Olek Wojnar <olek@debian.org>
Newsgroups linux.debian.project
Subject Re: Keysigning in times of COVID-19
Date Sat, 08 Aug 2020 22:50:02 +0200
Message-ID <ABDWW-eO-1@gated-at.bofh.it> (permalink)
References <AB64W-52C-5@gated-at.bofh.it> <AB6xZ-5rN-17@gated-at.bofh.it> <ABgnD-2QP-3@gated-at.bofh.it> <ABmjn-6lb-3@gated-at.bofh.it> <ABzTj-6jx-1@gated-at.bofh.it>
X-Mailbox-Line From debian-project-request@lists.debian.org Sat Aug 8 20:42:24 2020
Old-Return-Path <olekw.dev@gmail.com>
X-Amavis-Spam-Status No, score=-1.0 required=4.0 tests=FREEMAIL_FORGED_FROMDOMAIN, FREEMAIL_FROM,HEADER_FROM_DIFFERENT_DOMAINS,HTML_MESSAGE,LDO_WHITELIST, MURPHY_DRUGS_REL8,ONEWORDBODY,RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H2 autolearn=no autolearn_force=no version=3.4.2
X-Amavis-Spam-Status No, score=-2.978 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, FREEMAIL_FORGED_FROMDOMAIN=0.001, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.001, HTML_MESSAGE=2, LDO_WHITELIST=-5, MURPHY_DRUGS_REL8=0.02, ONEWORDBODY=2, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001] autolearn=no autolearn_force=no
X-Policyd-Weight NOT_IN_SBL_XBL_SPAMHAUS=-1.5 CL_IP_EQ_HELO_IP=-2 (check from: .gmail. - helo: .mail-qt1-f171.google. - helo-domain: .google.) FROM/MX_MATCHES_HELO(DOMAIN)=-2; rate: -5.5
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=0bDxVtjRy3QrfuOqVGx40JaGlxuvTa4hMs0edXxyzgk=; b=H0mySsIpd2QPSo0t/ni4IMrshPIEGY4ATaSdc/1TIVk/qgosUKWVgGDCs3x8yWQdeC xCtSSbRuOB94ap9LUYmYg5/45SGKHEPpCFfhXq9mAEr34RNbkTD1H33GL2KXHEz89j9n ll40U1bdqEzujuAZhJaGJL1nRqxnV6W5FJJ/oCW6N41adeqEdCdCZwbqSI8BnVTEaNub oI/L70WCZtSB/Sv6MrTUy5QoeJ5ZkzOwyIhL9F3cRtHuJnm3Ucq7K+6g9XjO7mxyOdB4 LeqdsYKAqJtRF8NUoKiRJpjP9OEjbHdasECQa7WzWtMesc+TqvD5B3FFQIGkFY5jCe0O 7PsA==
X-Gm-Message-State AOAM531f01ICjNZ2Y3s3+fSYriR1q1S7G7OMQFAcFUklnyTQKnbOgefE u0dWW20UfXbKKihYE+1hhRZIHAwq
X-Google-SMTP-Source ABdhPJx4J56HS54XKK8eXhjOAF5h/o+OKONZcherXwR//Ec0y8ksdDYzyZZeptMCmTpyVKKv0WeKEg==
X-Received by 2002:ac8:1349:: with SMTP id f9mr20694092qtj.24.1596918466336; Sat, 08 Aug 2020 13:27:46 -0700 (PDT)
X-Received by 2002:a0c:9b96:: with SMTP id o22mr21603891qve.213.1596918465853; Sat, 08 Aug 2020 13:27:45 -0700 (PDT)
MIME-Version 1.0
X-Gmail-Original-Message-ID <CAJj0crQA=Ey_auOEk82F+nY5VMVn0kai4RXb431ufsZcdUgqkQ@mail.gmail.com>
Content-Type multipart/alternative; boundary="000000000000e47c8905ac638d08"
Moderated yes
X-Mailing-List <debian-project@lists.debian.org> archive/latest/29841
List-ID <debian-project.lists.debian.org>
List-URL <https://lists.debian.org/debian-project/>
List-Archive https://lists.debian.org/msgid-search/CAJj0crQA=Ey_auOEk82F+nY5VMVn0kai4RXb431ufsZcdUgqkQ@mail.gmail.com
Approved robomod@news.nic.it
Lines 171
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Sat, 8 Aug 2020 16:27:33 -0400
X-Original-Message-ID <CAJj0crQA=Ey_auOEk82F+nY5VMVn0kai4RXb431ufsZcdUgqkQ@mail.gmail.com>
X-Original-References <CA+f80t5DzcbuiDdq_4Jt4wZudNf7gUUrK7tbAeRnO7qVxc9VWQ@mail.gmail.com> <159679002214.3529538.17079933599967930183@auryn.jones.dk> <tslk0yal14t.fsf@suchdamage.org> <CAJj0crQUJg-S7e2QHfPpeTwU75s6uQ6Srz_rf7pTWJF=9_JY7w@mail.gmail.com> <tsl8sepkuon.fsf@suchdamage.org>
Xref csiph.com linux.debian.project:11979

Show key headers only | View raw


[Multipart message — attachments visible in raw view] - view raw

Hi Sam,

On Sat, Aug 8, 2020, 11:46 Sam Hartman <hartmans@debian.org> wrote:

>
> TL;DR: While there may be improvements to be found in a completely
> different approach to identity, let us not let the scope of the
> discussion broaden that far, so we can make progress today.
>

I respectful disagree on this point. This conversation started with a
question about how to verify identity without in-person interaction. The
reason a number of people have seemingly broadened the scope (from my
perspective, I clearly don't know people's actual motivations) is because
that is the deeper question behind the original query.

>>>>> "Olek" == Olek Wojnar <olek@debian.org> writes:
>
>     Olek> Thanks to some great tools, it's fairly easy to
>     Olek> verify that they do indeed control the email addresses tied to
>     Olek> their key. That's what I care about at that point in time.
>
> For me, that's not nearly enough.
> If all you want to do is verify that a particular point in time, an
> email address belongs to a key, set up a service to do that.
>

I was referring to the caff package.

When I sign a key I am signing a certification that I believe
> 1) the key and
> 2) the real world identity
>
> correspond to the digital identity in the FLOSS community represented by
> the claimed email address.
>

That is how I have always done it as well but this conversation is making
me rethink the *why* of that process.

I don't want to throw out what we have without a viable suggestion that
> the project can get behind.
>

Agreed.

So, let's focus this thread on key signing and how to adapt that because
> it's what we have today and because we're looking for some short-term
> answers.
> If you want to start a different thread proposing to revamp how we think
> about identity, go for it.
>

Again, I disagree that these are distinct topics. I think they are
intrinsically linked.

There have been some good points so far about the value of having a
real-world identity connected to your Debian identity for reasons of
accountability and liability. There have also been good points about
personal privacy. (Dissident Test, anyone?)

I was just recently speaking with a prospective first-time contributor who
was very excited about being involved in the project but was not
comfortable sharing their real life identity. Do we turn people like that
away or welcome their contributions into the project once we have validated
their reliability and trustworthiness *in the scope of the Debian Project*?
Do we absolutely *have* to have a real life identity connected to someone
to sign their key? Or to accept a patch? Or a packaging job? Or permissions
as a DM?

I'm not advocating a position since I'm not 100% sure what the answer
should be. But I think that these are important questions to ask ourselves
and an important conversation to have. Perhaps this will eventually lead to
a GR, or perhaps we'll develop a consensus here. But we absolutely need to
be having this conversation and considering all points of view and
repercussions.

-Olek

>

Back to linux.debian.project | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: Keysigning in times of COVID-19 Gerardo Ballabio <gerardo.ballabio@gmail.com> - 2020-08-07 10:40 +0200
  Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-07 11:10 +0200
    Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-07 21:40 +0200
      Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-07 22:50 +0200
        Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-08 00:00 +0200
          Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-08 04:00 +0200
      Re: Keysigning in times of COVID-19 Cindy Sue Causey <butterflybytes@gmail.com> - 2020-08-07 23:30 +0200
      Re: Keysigning in times of COVID-19 Olek Wojnar <olek@debian.org> - 2020-08-08 04:00 +0200
        Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-08 18:30 +0200
          Re: Keysigning in times of COVID-19 Olek Wojnar <olek@debian.org> - 2020-08-08 22:50 +0200
            Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-09 01:10 +0200
              Re: Keysigning in times of COVID-19 Olek Wojnar <olek@debian.org> - 2020-08-09 03:40 +0200
                Re: Keysigning in times of COVID-19 Felix Lechner <felix.lechner@lease-up.com> - 2020-08-09 07:40 +0200
                Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-09 15:10 +0200
                Re: Keysigning in times of COVID-19 Holger Levsen <holger@layer-acht.org> - 2020-08-10 12:00 +0200
                How to Value a Community Sam Hartman <hartmans@debian.org> - 2020-08-10 14:20 +0200
              Re: Keysigning in times of COVID-19 Eldon Koyle <ekoyle@gmail.com> - 2020-08-09 06:20 +0200

csiph-web