Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.project > #11996

Re: Potential Summary: Keysigning in times of COVID-19

From Ángel <debian-project@debian.16bits.net>
Newsgroups linux.debian.project
Subject Re: Potential Summary: Keysigning in times of COVID-19
Date 2020-08-13 08:20 +0200
Message-ID <ADeKJ-1EM-3@gated-at.bofh.it> (permalink)
References <AAQCS-4cZ-11@gated-at.bofh.it> <ACXJT-8bc-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Thanks for the summary, Sam.

As an 'amicus' of the project, and interested on these topics, I wanted
to provide my 2 cents.


First of all, you are not the only one with this situation. The issue
arises from the vague meaning of a signature on a pgp key, and also
appears on other venues when using a network of pgp signatures. Be that
"the" WoT or an internal one of DD, as soon as you have many people
acting as introducers, with slightly different criteria, it ends up with
a somewhat diffuse meaning.

I do think it is important to define what are the objectives of the
Developers PGP keys. Is it to ensure that the same online entity is
responsible for all the uploads of that named individual? So that if
there is some questionable action it can be traced back to the
responsible individual? To make it hard to "game" the project? To have a
single identifier?


On the topic of malicious activity, I should note that, while it is
important that there is a cost of entry that would be "burned" by
activities that went to undermine the project goal, and certainly a
zero-cost approach would attract many trolls, it is not impossible for a
determined attacker:

- A single determined individual might be able to get several identities
by identifying through different DD, either under the same or different
alias. I'd also not consider entirely true that "Each person only gets
one real-world identity", but I don't think corner cases would be
needed, when cleverly presenting itself through different introducers
could probably get them in.

- A 'company' that had a specific interest to weaken Debian (perhaps so
that its systems are easier to compromise, or because it competes with
their own products), to the point of tasking a number of individuals to
that end. This would probably be a bigger threat than the previous one
as there would be an external motivation to do that which is financing
such activity. Please note that by 'company' I am not meaning just
business entities, but also three letter agencies, nation states,
malicious hacker groups, mafia...
Even ignoring the (likely) ability of such groups to get a passport
under a name different than the one given at birth to an individual,
it seems they would have little trouble to produce a new identity to
present to Debian. I assume they would probably only have a few people
on payroll with the required expertise tasked to infiltrate into the
project, *however* it would be very easy to let them assume online the
identity of any other employee (such as a non-technical receptionist),
which would be plenty if compared to the number of "ghosthacker
developers".




Finally, some technical points:

* PGP signatures can include notations. The main problem is that they
are not standardized, but a number of them could be defined with the
desired meanings "I have checked a Government ID", "Online only", "Long
time online interaction", "COVID-19", "Verified that the key owner has
access to the associated email", "Group key"

* PGP signatures can include an expiration. It is often the case that it
is set to the key expiration, but it would be possible to sign a key for
only a few months (considering that after that time it will be possible
to meet IRL again). 

* The piece about matching them with a legal identity (the equivalent to
verify a Passport) could be done through the Government eID, at least
for those in the European Union (see eIDAS regulation). It may be
possible to generalise it to other countries through ePassport.
Probably "fun" to make it work (both the client and the verification
part), but a PGP key cryptographically linked to the Government PKI
would be more than a DD looking at a passport.


Best regards

Ángel

Back to linux.debian.project | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Keysigning in times of COVID-19 Enrico Zini <enrico@enricozini.org> - 2020-08-06 18:10 +0200
  Re: Keysigning in times of COVID-19 Roberto C. Sánchez <roberto@debian.org> - 2020-08-06 18:50 +0200
    Re: Keysigning in times of COVID-19 Federico Ceratto <federico.ceratto@gmail.com> - 2020-08-17 20:30 +0200
      Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-17 21:10 +0200
        Re: Keysigning in times of COVID-19 Wouter Verhelst <wouter@debian.org> - 2020-08-19 16:20 +0200
          Re: Keysigning in times of COVID-19 rhkramer@gmail.com - 2020-08-19 18:10 +0200
            Re: Keysigning in times of COVID-19 Philip Hands <phil@hands.com> - 2020-08-20 10:20 +0200
              Re: Keysigning in times of COVID-19 Andrey Rahmatullin <wrar@debian.org> - 2020-08-20 10:50 +0200
              Re: Keysigning in times of COVID-19 Ansgar <ansgar@debian.org> - 2020-08-20 10:50 +0200
              Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-20 12:20 +0200
                Re: Keysigning in times of COVID-19 Russ Allbery <rra@debian.org> - 2020-08-20 19:30 +0200
              Re: Keysigning in times of COVID-19 Florian Weimer <fw@deneb.enyo.de> - 2020-08-23 23:10 +0200
  Re: Keysigning in times of COVID-19 Felix Lechner <felix.lechner@lease-up.com> - 2020-08-06 19:10 +0200
  Re: Keysigning in times of COVID-19 Johannes Schauer <josch@debian.org> - 2020-08-06 19:30 +0200
    Re: Keysigning in times of COVID-19 Holger Levsen <holger@layer-acht.org> - 2020-08-07 11:40 +0200
  Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-06 19:40 +0200
  Re: Keysigning in times of COVID-19 Christian Kastner <ckk@debian.org> - 2020-08-06 23:40 +0200
  Re: Keysigning in times of COVID-19 Héctor Orón Martínez <hector.oron@gmail.com> - 2020-08-07 01:30 +0200
  Re: Keysigning in times of COVID-19 Alexandre Viau <aviau@debian.org> - 2020-08-07 09:30 +0200
    Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-07 12:00 +0200
  Re: Keysigning in times of COVID-19 Didier 'OdyX' Raboud <odyx@debian.org> - 2020-08-07 12:00 +0200
  Re: Keysigning in times of COVID-19 Alberto Garcia <berto@igalia.com> - 2020-08-07 12:10 +0200
  Re: Keysigning in times of COVID-19 Adrian Bunk <bunk@debian.org> - 2020-08-07 16:10 +0200
    Re: Keysigning in times of COVID-19 Ulrike Uhlig <ulrike@debian.org> - 2020-08-07 18:50 +0200
    Re: Keysigning in times of COVID-19 Gunnar Wolf <gwolf@debian.org> - 2020-08-09 07:50 +0200
      Re: Keysigning in times of COVID-19 Adrian Bunk <bunk@debian.org> - 2020-08-10 20:00 +0200
  Re: Keysigning in times of COVID-19 Gunnar Wolf <gwolf@debian.org> - 2020-08-09 07:40 +0200
  Re: Keysigning in times of COVID-19 Jonathan McDowell <noodles@earth.li> - 2020-08-12 10:10 +0200
    Re: Expressing regrets for how I handled the transition to Identity Verification  in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-12 14:30 +0200
  Re: Potential Summary: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-12 14:10 +0200
    Re: Potential Summary: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-12 14:30 +0200
    Re: Potential Summary: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-13 08:20 +0200
      Re: Potential Summary: Keysigning in times of COVID-19 Adam Borowski <kilobyte@angband.pl> - 2020-08-13 19:30 +0200
        Re: Potential Summary: Keysigning in times of COVID-19 Pirate Praveen <praveen@onenetbeyond.org> - 2020-08-13 20:20 +0200
          Re: Potential Summary: Keysigning in times of COVID-19 Adam Borowski <kilobyte@angband.pl> - 2020-08-13 21:10 +0200
            Re: Potential Summary: Keysigning in times of COVID-19 Steve McIntyre <steve@einval.com> - 2020-08-13 23:10 +0200
              Re: Potential Summary: Keysigning in times of COVID-19 Adrian Bunk <bunk@debian.org> - 2020-08-14 18:50 +0200
                Re: Potential Summary: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-14 23:00 +0200
                Re: Potential Summary: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-14 23:10 +0200
                Re: Potential Summary: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-15 00:30 +0200
            Re: Potential Summary: Keysigning in times of COVID-19 Christian Kastner <ckk@debian.org> - 2020-08-13 23:10 +0200
              Re: Potential Summary: Keysigning in times of COVID-19 Adam Borowski <kilobyte@angband.pl> - 2020-08-14 00:40 +0200
        Re: Potential Summary: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-13 21:40 +0200
  Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-12 17:30 +0200
    Re: Keysigning in times of COVID-19 Paul Wise <pabs@debian.org> - 2020-08-13 08:20 +0200
      Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-13 14:00 +0200
        Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-13 14:20 +0200
          Re: Keysigning in times of COVID-19 Guilhem Moulin <guilhem@debian.org> - 2020-08-13 14:50 +0200
            Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-13 16:50 +0200
              Re: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-14 04:00 +0200
                Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-16 15:40 +0200
      Re: Keysigning in times of COVID-19 rhkramer@gmail.com - 2020-08-13 14:00 +0200
      Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-13 14:20 +0200

csiph-web