Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.project > #11972

Re: Keysigning in times of COVID-19

From Sam Hartman <hartmans@debian.org>
Newsgroups linux.debian.project
Subject Re: Keysigning in times of COVID-19
Date 2020-08-07 21:40 +0200
Message-ID <ABgnD-2QP-3@gated-at.bofh.it> (permalink)
References <AB64W-52C-5@gated-at.bofh.it> <AB6xZ-5rN-17@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

TL;DR: I think without some link back to real world identity, we open
ourselves up to attacks where people build trust only to betray us.

>>>>> "Jonas" == Jonas Smedegaard <dr@jones.dk> writes:

    Jonas> Quoting Gerardo Ballabio (2020-08-07 10:34:20)
    >> Johannes Schauer wrote:
    Jonas> If ok for first round of several months collaboration was
    Jonas> conducted without ties to governmental papers, then
    Jonas> continuation should as well.

    Jonas> If you are not confident that the person is the same from
    Jonas> coding style, text-chatting style, mimics in videochat etc.,
    Jonas> then apply same requirement as you did for first round: Trust
    Jonas> only after several months of collaboration tied to the _new_
    Jonas> key.

Jonas, first thanks for describing your rule about interacting with
someone enough that you'd recognize them later.

I think that makes sense.  I'm uncomfortable though with the idea that
someone could get their key signed by doing good work, lose the key and
get another key signed later by again doing good work.
That opens up attacks that I care about in our model of trust.

The threat I care about that I hope key signing will help protect us
from is the threat of someone intentionally decreasing the integrity of
Debian.  That is, someone includes malicious code (or similarly
undermines our reputation).

In my mind, we want to require

1) That someone builds up a significant positive reputation

and

2) That  it would be costly for them to burn that reputation to maount
an attack.

In this model the advantage of trying to tie a key back to a real-world
identity is that we only get one of those.
No matter how much good work I do in the future, I cannot escape a
betrayal of trust if we tie it back to Sam Hartman.

But if we don't tie it back, let's say I do a year's worth of good work
as DebianDude and eventually get my key signed.
I can burn that reputation for an attack, having lost a year, but not
lost my future possibility of spending another year and getting trusted
again (possibly for another attack).

An attacker might be much more willing to burn their DebianDude
reputation than their Sam Hartman reputation.


Now, that real world identity might not even need to be a real name.
If you're going to recognize the person, know that you've already signed
their key, that's probably enough.
You can think think about whether this is a legitimate and harmless
identifier change or whether this is an attempt to cause harm.  But you
can consider all the identities you've known and link it back to the
person.
For me, that linking is key to key signing being valuable.

Back to linux.debian.project | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: Keysigning in times of COVID-19 Gerardo Ballabio <gerardo.ballabio@gmail.com> - 2020-08-07 10:40 +0200
  Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-07 11:10 +0200
    Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-07 21:40 +0200
      Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-07 22:50 +0200
        Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-08 00:00 +0200
          Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-08 04:00 +0200
      Re: Keysigning in times of COVID-19 Cindy Sue Causey <butterflybytes@gmail.com> - 2020-08-07 23:30 +0200
      Re: Keysigning in times of COVID-19 Olek Wojnar <olek@debian.org> - 2020-08-08 04:00 +0200
        Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-08 18:30 +0200
          Re: Keysigning in times of COVID-19 Olek Wojnar <olek@debian.org> - 2020-08-08 22:50 +0200
            Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-09 01:10 +0200
              Re: Keysigning in times of COVID-19 Olek Wojnar <olek@debian.org> - 2020-08-09 03:40 +0200
                Re: Keysigning in times of COVID-19 Felix Lechner <felix.lechner@lease-up.com> - 2020-08-09 07:40 +0200
                Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-09 15:10 +0200
                Re: Keysigning in times of COVID-19 Holger Levsen <holger@layer-acht.org> - 2020-08-10 12:00 +0200
                How to Value a Community Sam Hartman <hartmans@debian.org> - 2020-08-10 14:20 +0200
              Re: Keysigning in times of COVID-19 Eldon Koyle <ekoyle@gmail.com> - 2020-08-09 06:20 +0200

csiph-web