Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.project > #11996
| From | Ángel <debian-project@debian.16bits.net> |
|---|---|
| Newsgroups | linux.debian.project |
| Subject | Re: Potential Summary: Keysigning in times of COVID-19 |
| Date | 2020-08-13 08:20 +0200 |
| Message-ID | <ADeKJ-1EM-3@gated-at.bofh.it> (permalink) |
| References | <AAQCS-4cZ-11@gated-at.bofh.it> <ACXJT-8bc-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
Thanks for the summary, Sam. As an 'amicus' of the project, and interested on these topics, I wanted to provide my 2 cents. First of all, you are not the only one with this situation. The issue arises from the vague meaning of a signature on a pgp key, and also appears on other venues when using a network of pgp signatures. Be that "the" WoT or an internal one of DD, as soon as you have many people acting as introducers, with slightly different criteria, it ends up with a somewhat diffuse meaning. I do think it is important to define what are the objectives of the Developers PGP keys. Is it to ensure that the same online entity is responsible for all the uploads of that named individual? So that if there is some questionable action it can be traced back to the responsible individual? To make it hard to "game" the project? To have a single identifier? On the topic of malicious activity, I should note that, while it is important that there is a cost of entry that would be "burned" by activities that went to undermine the project goal, and certainly a zero-cost approach would attract many trolls, it is not impossible for a determined attacker: - A single determined individual might be able to get several identities by identifying through different DD, either under the same or different alias. I'd also not consider entirely true that "Each person only gets one real-world identity", but I don't think corner cases would be needed, when cleverly presenting itself through different introducers could probably get them in. - A 'company' that had a specific interest to weaken Debian (perhaps so that its systems are easier to compromise, or because it competes with their own products), to the point of tasking a number of individuals to that end. This would probably be a bigger threat than the previous one as there would be an external motivation to do that which is financing such activity. Please note that by 'company' I am not meaning just business entities, but also three letter agencies, nation states, malicious hacker groups, mafia... Even ignoring the (likely) ability of such groups to get a passport under a name different than the one given at birth to an individual, it seems they would have little trouble to produce a new identity to present to Debian. I assume they would probably only have a few people on payroll with the required expertise tasked to infiltrate into the project, *however* it would be very easy to let them assume online the identity of any other employee (such as a non-technical receptionist), which would be plenty if compared to the number of "ghosthacker developers". Finally, some technical points: * PGP signatures can include notations. The main problem is that they are not standardized, but a number of them could be defined with the desired meanings "I have checked a Government ID", "Online only", "Long time online interaction", "COVID-19", "Verified that the key owner has access to the associated email", "Group key" * PGP signatures can include an expiration. It is often the case that it is set to the key expiration, but it would be possible to sign a key for only a few months (considering that after that time it will be possible to meet IRL again). * The piece about matching them with a legal identity (the equivalent to verify a Passport) could be done through the Government eID, at least for those in the European Union (see eIDAS regulation). It may be possible to generalise it to other countries through ePassport. Probably "fun" to make it work (both the client and the verification part), but a PGP key cryptographically linked to the Government PKI would be more than a DD looking at a passport. Best regards Ángel
Back to linux.debian.project | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Keysigning in times of COVID-19 Enrico Zini <enrico@enricozini.org> - 2020-08-06 18:10 +0200
Re: Keysigning in times of COVID-19 Roberto C. Sánchez <roberto@debian.org> - 2020-08-06 18:50 +0200
Re: Keysigning in times of COVID-19 Federico Ceratto <federico.ceratto@gmail.com> - 2020-08-17 20:30 +0200
Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-17 21:10 +0200
Re: Keysigning in times of COVID-19 Wouter Verhelst <wouter@debian.org> - 2020-08-19 16:20 +0200
Re: Keysigning in times of COVID-19 rhkramer@gmail.com - 2020-08-19 18:10 +0200
Re: Keysigning in times of COVID-19 Philip Hands <phil@hands.com> - 2020-08-20 10:20 +0200
Re: Keysigning in times of COVID-19 Andrey Rahmatullin <wrar@debian.org> - 2020-08-20 10:50 +0200
Re: Keysigning in times of COVID-19 Ansgar <ansgar@debian.org> - 2020-08-20 10:50 +0200
Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-20 12:20 +0200
Re: Keysigning in times of COVID-19 Russ Allbery <rra@debian.org> - 2020-08-20 19:30 +0200
Re: Keysigning in times of COVID-19 Florian Weimer <fw@deneb.enyo.de> - 2020-08-23 23:10 +0200
Re: Keysigning in times of COVID-19 Felix Lechner <felix.lechner@lease-up.com> - 2020-08-06 19:10 +0200
Re: Keysigning in times of COVID-19 Johannes Schauer <josch@debian.org> - 2020-08-06 19:30 +0200
Re: Keysigning in times of COVID-19 Holger Levsen <holger@layer-acht.org> - 2020-08-07 11:40 +0200
Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-06 19:40 +0200
Re: Keysigning in times of COVID-19 Christian Kastner <ckk@debian.org> - 2020-08-06 23:40 +0200
Re: Keysigning in times of COVID-19 Héctor Orón Martínez <hector.oron@gmail.com> - 2020-08-07 01:30 +0200
Re: Keysigning in times of COVID-19 Alexandre Viau <aviau@debian.org> - 2020-08-07 09:30 +0200
Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-07 12:00 +0200
Re: Keysigning in times of COVID-19 Didier 'OdyX' Raboud <odyx@debian.org> - 2020-08-07 12:00 +0200
Re: Keysigning in times of COVID-19 Alberto Garcia <berto@igalia.com> - 2020-08-07 12:10 +0200
Re: Keysigning in times of COVID-19 Adrian Bunk <bunk@debian.org> - 2020-08-07 16:10 +0200
Re: Keysigning in times of COVID-19 Ulrike Uhlig <ulrike@debian.org> - 2020-08-07 18:50 +0200
Re: Keysigning in times of COVID-19 Gunnar Wolf <gwolf@debian.org> - 2020-08-09 07:50 +0200
Re: Keysigning in times of COVID-19 Adrian Bunk <bunk@debian.org> - 2020-08-10 20:00 +0200
Re: Keysigning in times of COVID-19 Gunnar Wolf <gwolf@debian.org> - 2020-08-09 07:40 +0200
Re: Keysigning in times of COVID-19 Jonathan McDowell <noodles@earth.li> - 2020-08-12 10:10 +0200
Re: Expressing regrets for how I handled the transition to Identity Verification in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-12 14:30 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-12 14:10 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-12 14:30 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-13 08:20 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Adam Borowski <kilobyte@angband.pl> - 2020-08-13 19:30 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Pirate Praveen <praveen@onenetbeyond.org> - 2020-08-13 20:20 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Adam Borowski <kilobyte@angband.pl> - 2020-08-13 21:10 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Steve McIntyre <steve@einval.com> - 2020-08-13 23:10 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Adrian Bunk <bunk@debian.org> - 2020-08-14 18:50 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-14 23:00 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-14 23:10 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-15 00:30 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Christian Kastner <ckk@debian.org> - 2020-08-13 23:10 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Adam Borowski <kilobyte@angband.pl> - 2020-08-14 00:40 +0200
Re: Potential Summary: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-13 21:40 +0200
Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-12 17:30 +0200
Re: Keysigning in times of COVID-19 Paul Wise <pabs@debian.org> - 2020-08-13 08:20 +0200
Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-13 14:00 +0200
Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-13 14:20 +0200
Re: Keysigning in times of COVID-19 Guilhem Moulin <guilhem@debian.org> - 2020-08-13 14:50 +0200
Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-13 16:50 +0200
Re: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-14 04:00 +0200
Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-16 15:40 +0200
Re: Keysigning in times of COVID-19 rhkramer@gmail.com - 2020-08-13 14:00 +0200
Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-13 14:20 +0200
csiph-web