From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756808Ab1JCQ2v (ORCPT ); Mon, 3 Oct 2011 12:28:51 -0400 Received: from mx1.redhat.com ([209.132.183.28]:27811 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753085Ab1JCQ2r (ORCPT ); Mon, 3 Oct 2011 12:28:47 -0400 To: Adrian Bunk Cc: "H. Peter Anvin" , "Rafael J. Wysocki" , Linux Kernel Mailing List , Greg KH Subject: Re: kernel.org status: establishing a PGP web of trust References: <4E8655CD.90107@zytor.com> <201110020304.28288.rjw@sisk.pl> <4E87B885.50005@zytor.com> <201110021354.57995.rjw@sisk.pl> <4E88A537.4010008@zytor.com> <20111003093239.GB25136@localhost.pp.htv.fi> From: fche@redhat.com (Frank Ch. Eigler) Date: Mon, 03 Oct 2011 12:28:17 -0400 In-Reply-To: <20111003093239.GB25136@localhost.pp.htv.fi> (Adrian Bunk's message of "Mon, 3 Oct 2011 12:32:39 +0300") Message-ID: User-Agent: Gnus/5.1008 (Gnus v5.10.8) Emacs/21.4 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org bunk@stusta.de wrote: > [...] >> You probably know enough people (including myself) that would be willing >> to sign your key over the phone. >>... > > You have personally checked Rafael's user id (e.g. passport)? > > This might or might not be true in this case, but generally signing keys > without having ever checked the user id (no matter how long you know the > person) is a common mistake. What is the threat that this passport checking is intended to cure? That someone else might have been impersonating Rafael for years, sending patches, chatting in email and over the phone, and attending conferences? If so, perhaps the impostor is of more value to the project than the Real Rafael. - FChE