Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.project > #11984
| From | Gunnar Wolf <gwolf@debian.org> |
|---|---|
| Newsgroups | linux.debian.project |
| Subject | Re: Keysigning in times of COVID-19 |
| Date | 2020-08-09 07:40 +0200 |
| Message-ID | <ABMdQ-5oo-9@gated-at.bofh.it> (permalink) |
| References | <AAQCS-4cZ-11@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
Hello Enrico, and thanks for bringing the discussion over here.
Enrico Zini dijo [Thu, Aug 06, 2020 at 05:54:21PM +0200]:
> Hello,
>
> we have people approaching Debian with a lack of GPG signatures, and we
> generally cannot ask them to travel and meet other developers in person
> to get their key signed.
>
> Technically, we are not requiring that people meet a DD in person, only
> that people have their key signed by a DD.
>
> Technically, every DD has their own policies for signing keys, which
> could go from not requiring meeting in person at all, to requiring to
> meet in person multiple times. It might require to check a government
> issued photo ID, or it might not.
>
> Practically, I feel like most of the time people's policies match what
> are the perceived expectations of the rest of the project. Meeting in
> person has always been a good safe bet, if only for the reson that it's
> been accepted without question for many years.
>
> It's time to review those expectations.
> (...)
Enrico brought up this topic to DPL, DAM, front-desk and keyring-maint
about two weeks ago. I will copy over what I answered back then:
We have been rehashing many of the (great) arguments you present
every now and then since... At least, I remember the point being
brought up after the Yuge KSP from HEL at DC5, and the
Transnational Republic incident of DC6.
Our guidelines have been for many many many years that "everybody
is free to set their own policy — but please be sensible and
careful". We have never sent out an official announcement, either
from DAM or from keyring-maint, about it... but AIUI we have been
basically in agreement and explicitly said so at KSP introductions
(I have, repeatedly).
We have often mentioned positive examples (i.e. pseudonymous
community members we completely trust). We have mentioned the ease
to acquire forged or plainly fake official-looking IDs.
So, where do I stand? I try not to sign keys for people I cannot
recognize without looking at their papers. That means, my signing
resembles a lot my group of friends, the group of peple we meet year
after year in DebConf, plus some others I've bumped into now and
then. IDs? Show them to me, I don't really mind, I have done many
signings without looking at IDs. I know first-hand¹ that forging them
is very easy.
I also know some of our friends have a made-up identity. Some of those
identities are close to twenty years old, at least. That's worth the
same as a birth-given name in my book...
And yes, I have often refused to sign people's keys when they approach
me at a DebConf if we have not held significative interactions in the
past. I usually insist that I do not sign at a first
meeting. Although, yes, if meeting somebody at other ocassions,
specially given Latin America is a quite PGP-sparse region... I tend
to be a bit more flexible, to aid people getting connected and start
contributing.
And... Well, to the point at hand: Yes, I do think we have to rethink
our policies. I don't have an answer right now, and most likely, I
won't sign any keys during this DebConf. But as more of our activities
are conducted online, we will have to start trusting videoconferences
to prove identities.
(of course... given deepfakes have been getting better and
better... who knows? :-\ )
¹ If you must know, >25 years ago I paid for a passport I should not
have received. My personal data was correct, but back then, my
country required a military service "clearance" I didn't have. I am
not proud of having paid for an illegal document, and would not do
it again. But it's part of what I learnt, and I am sure my
experience would not change _too much_ going to other
countries. More money to spend, perhaps...
Back to linux.debian.project | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Keysigning in times of COVID-19 Enrico Zini <enrico@enricozini.org> - 2020-08-06 18:10 +0200
Re: Keysigning in times of COVID-19 Roberto C. Sánchez <roberto@debian.org> - 2020-08-06 18:50 +0200
Re: Keysigning in times of COVID-19 Federico Ceratto <federico.ceratto@gmail.com> - 2020-08-17 20:30 +0200
Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-17 21:10 +0200
Re: Keysigning in times of COVID-19 Wouter Verhelst <wouter@debian.org> - 2020-08-19 16:20 +0200
Re: Keysigning in times of COVID-19 rhkramer@gmail.com - 2020-08-19 18:10 +0200
Re: Keysigning in times of COVID-19 Philip Hands <phil@hands.com> - 2020-08-20 10:20 +0200
Re: Keysigning in times of COVID-19 Andrey Rahmatullin <wrar@debian.org> - 2020-08-20 10:50 +0200
Re: Keysigning in times of COVID-19 Ansgar <ansgar@debian.org> - 2020-08-20 10:50 +0200
Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-20 12:20 +0200
Re: Keysigning in times of COVID-19 Russ Allbery <rra@debian.org> - 2020-08-20 19:30 +0200
Re: Keysigning in times of COVID-19 Florian Weimer <fw@deneb.enyo.de> - 2020-08-23 23:10 +0200
Re: Keysigning in times of COVID-19 Felix Lechner <felix.lechner@lease-up.com> - 2020-08-06 19:10 +0200
Re: Keysigning in times of COVID-19 Johannes Schauer <josch@debian.org> - 2020-08-06 19:30 +0200
Re: Keysigning in times of COVID-19 Holger Levsen <holger@layer-acht.org> - 2020-08-07 11:40 +0200
Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-06 19:40 +0200
Re: Keysigning in times of COVID-19 Christian Kastner <ckk@debian.org> - 2020-08-06 23:40 +0200
Re: Keysigning in times of COVID-19 Héctor Orón Martínez <hector.oron@gmail.com> - 2020-08-07 01:30 +0200
Re: Keysigning in times of COVID-19 Alexandre Viau <aviau@debian.org> - 2020-08-07 09:30 +0200
Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-07 12:00 +0200
Re: Keysigning in times of COVID-19 Didier 'OdyX' Raboud <odyx@debian.org> - 2020-08-07 12:00 +0200
Re: Keysigning in times of COVID-19 Alberto Garcia <berto@igalia.com> - 2020-08-07 12:10 +0200
Re: Keysigning in times of COVID-19 Adrian Bunk <bunk@debian.org> - 2020-08-07 16:10 +0200
Re: Keysigning in times of COVID-19 Ulrike Uhlig <ulrike@debian.org> - 2020-08-07 18:50 +0200
Re: Keysigning in times of COVID-19 Gunnar Wolf <gwolf@debian.org> - 2020-08-09 07:50 +0200
Re: Keysigning in times of COVID-19 Adrian Bunk <bunk@debian.org> - 2020-08-10 20:00 +0200
Re: Keysigning in times of COVID-19 Gunnar Wolf <gwolf@debian.org> - 2020-08-09 07:40 +0200
Re: Keysigning in times of COVID-19 Jonathan McDowell <noodles@earth.li> - 2020-08-12 10:10 +0200
Re: Expressing regrets for how I handled the transition to Identity Verification in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-12 14:30 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-12 14:10 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-12 14:30 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-13 08:20 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Adam Borowski <kilobyte@angband.pl> - 2020-08-13 19:30 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Pirate Praveen <praveen@onenetbeyond.org> - 2020-08-13 20:20 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Adam Borowski <kilobyte@angband.pl> - 2020-08-13 21:10 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Steve McIntyre <steve@einval.com> - 2020-08-13 23:10 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Adrian Bunk <bunk@debian.org> - 2020-08-14 18:50 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-14 23:00 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-14 23:10 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-15 00:30 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Christian Kastner <ckk@debian.org> - 2020-08-13 23:10 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Adam Borowski <kilobyte@angband.pl> - 2020-08-14 00:40 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-13 21:40 +0200
Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-12 17:30 +0200
Re: Keysigning in times of COVID-19 Paul Wise <pabs@debian.org> - 2020-08-13 08:20 +0200
Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-13 14:00 +0200
Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-13 14:20 +0200
Re: Keysigning in times of COVID-19 Guilhem Moulin <guilhem@debian.org> - 2020-08-13 14:50 +0200
Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-13 16:50 +0200
Re: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-14 04:00 +0200
Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-16 15:40 +0200
Re: Keysigning in times of COVID-19 rhkramer@gmail.com - 2020-08-13 14:00 +0200
Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-13 14:20 +0200
csiph-web