Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.project > #11977
| From | Olek Wojnar <olek@debian.org> |
|---|---|
| Newsgroups | linux.debian.project |
| Subject | Re: Keysigning in times of COVID-19 |
| Date | 2020-08-08 04:00 +0200 |
| Message-ID | <ABmjn-6lb-3@gated-at.bofh.it> (permalink) |
| References | <AB64W-52C-5@gated-at.bofh.it> <AB6xZ-5rN-17@gated-at.bofh.it> <ABgnD-2QP-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
Hi Sam, On Fri, Aug 7, 2020 at 3:39 PM Sam Hartman <hartmans@debian.org> wrote: > > TL;DR: I think without some link back to real world identity, we open > ourselves up to attacks where people build trust only to betray us. > I agree with you that this is a potentially-serious problem. However, I'm not sure that keysigning is the right place to address it. I've seen a number of comments, including yours, seemingly conflate the trust we place in the validity of a cryptographic key and the trust we place in someone during the NM process. I think it is important to distinguish between the two. So, I don't really care (much) how technically competent or hard-working someone is when I sign their key. Thanks to some great tools, it's fairly easy to verify that they do indeed control the email addresses tied to their key. That's what I care about at that point in time. Now, if they want me to sponsor them in the NM process, that's when I am going to take a much closer look at their work and their attitude and determine if we should grant them the level of trust that goes with completing that process. That is also where I humbly submit we should have some level of identity verification. I'm not sure what that should look like but the point is where it should take place. If we previously verified someone's identity and subsequently banned them from the project, the NM process seems like the logical place to ensure that such a person is not able to slip back into Debian. Centralized and standardized is much easier in a process administered by a few people (NM) than in a distributed process with substantial variability and no means of reliable QA (random keysigning party). -Olek
Back to linux.debian.project | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: Keysigning in times of COVID-19 Gerardo Ballabio <gerardo.ballabio@gmail.com> - 2020-08-07 10:40 +0200
Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-07 11:10 +0200
Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-07 21:40 +0200
Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-07 22:50 +0200
Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-08 00:00 +0200
Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-08 04:00 +0200
Re: Keysigning in times of COVID-19 Cindy Sue Causey <butterflybytes@gmail.com> - 2020-08-07 23:30 +0200
Re: Keysigning in times of COVID-19 Olek Wojnar <olek@debian.org> - 2020-08-08 04:00 +0200
Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-08 18:30 +0200
Re: Keysigning in times of COVID-19 Olek Wojnar <olek@debian.org> - 2020-08-08 22:50 +0200
Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-09 01:10 +0200
Re: Keysigning in times of COVID-19 Olek Wojnar <olek@debian.org> - 2020-08-09 03:40 +0200
Re: Keysigning in times of COVID-19 Felix Lechner <felix.lechner@lease-up.com> - 2020-08-09 07:40 +0200
Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-09 15:10 +0200
Re: Keysigning in times of COVID-19 Holger Levsen <holger@layer-acht.org> - 2020-08-10 12:00 +0200
How to Value a Community Sam Hartman <hartmans@debian.org> - 2020-08-10 14:20 +0200
Re: Keysigning in times of COVID-19 Eldon Koyle <ekoyle@gmail.com> - 2020-08-09 06:20 +0200
csiph-web