From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753425Ab1JHSEF (ORCPT ); Sat, 8 Oct 2011 14:04:05 -0400 Received: from edison.jonmasters.org ([173.255.233.168]:45457 "EHLO edison.jonmasters.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753264Ab1JHSED (ORCPT ); Sat, 8 Oct 2011 14:04:03 -0400 From: Jon Masters To: Valdis.Kletnieks@vt.edu Cc: Krzysztof Halasa , Adrian Bunk , "Frank Ch. Eigler" , "H. Peter Anvin" , "Rafael J. Wysocki" , Linux Kernel Mailing List , Greg KH In-Reply-To: <58779.1318084612@turing-police.cc.vt.edu> References: <4E8655CD.90107@zytor.com> <201110020304.28288.rjw@sisk.pl> <4E87B885.50005@zytor.com> <201110021354.57995.rjw@sisk.pl> <4E88A537.4010008@zytor.com> <20111003093239.GB25136@localhost.pp.htv.fi> <20111003180441.GD3072@localhost.pp.htv.fi> <34045.1317760188@turing-police.cc.vt.edu> <1317916702.19519.1.camel@constitution.bos.jonmasters.org> <14191.1317930659@turing-police.cc.vt.edu> <15324.1318004954@turing-police.cc.vt.edu> <1318050133.19519.184.camel@constitution.bos.jonmasters.org> <58779.1318084612@turing-police.cc.vt.edu> Content-Type: text/plain; charset="UTF-8" Organization: World Organi[sz]ation Of Broken Dreams Date: Sat, 08 Oct 2011 13:59:48 -0400 Message-ID: <1318096788.19519.187.camel@constitution.bos.jonmasters.org> Mime-Version: 1.0 X-Mailer: Evolution 2.30.3 (2.30.3-1.fc13) Content-Transfer-Encoding: 7bit X-SA-Exim-Connect-IP: 74.92.29.237 X-SA-Exim-Mail-From: jonathan@jonmasters.org Subject: Re: kernel.org status: establishing a PGP web of trust X-SA-Exim-Version: 4.2.1 (built Sun, 08 Nov 2009 07:31:22 +0000) X-SA-Exim-Scanned: Yes (on edison.jonmasters.org) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Sat, 2011-10-08 at 10:36 -0400, Valdis.Kletnieks@vt.edu wrote: > On Sat, 08 Oct 2011 01:02:13 EDT, Jon Masters said: > > > What I'm saying is that unless you sign something (random text, my > > actual key(s)) in my presence, I can't actually know it was you I was > > dealing with or someone else claiming to be you (or your identity). > > Now see, this is *exacltly* why security people have to be pedantic about > stuff. What you originally asked for was "sign random data to demonstrate > control of the key", and I pointed out that being able to sign a key was as > good as being able to sign random data to prove control of the key. Good point about being pedantic, and the rest of your comments :) I understand that I'm taking this a little far but I'm just trying to point out one particular gaping hole in the way these things are currently done. One reason I stopped doing keysigning parties is that I realized they were mostly a show. You turn up and get a key signed and then everyone is impressed that you're in the strong set...wupdedoo. Not that I've anything against signing stuff on kernel.org and trying to improve things (I've long directly signed everything on master with my own keys in slight violation of policy, but that turned out to right). :) Jon.