git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Lack of detached signatures

From
JPJoseph Parmelee <jparmele@wildbear.com>
Date
Sep 29, 2011, 16:47 UTC
Message-ID
<alpine.LNX.2.00.1109291013220.29373@bruno>
In-Reply-To
<20110929131845.GQ19250@thunk.org>
On Thu, 29 Sep 2011, Ted Ts'o wrote:
Show 31 quoted lines
> On Wed, Sep 28, 2011 at 08:50:49PM -0700, Junio C Hamano wrote:
>>
>> I was actually more worried about helping consumers convince themselves
>> that thusly signed keys indeed belong to producers like Linus, Peter,
>> etc. There are those who worry that DNS record to code.google.com/ for
>> them may point at an evil place to give them rogue download material.
>> "Here are the keys you can verify our trees with" message on the mailing
>> list, even with the message is signed with GPG, would not be satisfactory
>> to them.
>
> What do you mean by "consumers" in this context?  Most end users don't
> actually download tarballs from www.kernel.org or code.google.com!  :-)
>
> If you mean developers at Linux distributions Red Hat, SuSE, or
> Handset manufacturers such as Samsung, HTC, Motorola, etc., there will
> be many of those reprsenatives at LinuxCon Europe and CELF (Consumer
> Electronics Linux Forum) Europe conferences, which will be colocated
> with the Kernel Summit in Prague.
>
> If you are thinking of random developers located in far-flung places
> of the world who don't have any contact with other Linux developers,
> this is a previously unsolved problem.  There are links into the
> developing Kernel GPG tree that are signed by the GPG web trust used
> by Debian, OpenSuSE, and (soon) Fedora.  Given that people generally
> have to trust one or more of those web of trusts, that's the best we
> can do, at least as far as I know.  If you can suggest something
> better, please let me know!
>
>
> 						- Ted
>

Also included is distro developers that gen custom distros for limited corporate use on specific hardware, and anyone else that is sufficiently concerned about security and/or survivability that they prefer/need to build from the upstream source.

As far as accepting public keys, a key obtained from the key servers and signed by others, while not perfect, is vastly superior to nothing at all. I am located in the mountains of Costa Rica. Over the years I have collected a fair number of public keys making it very difficult for bad guys to fake both a public key and all the signatures too, even though I can't travel to a "key signing party" which would of course be better.

Even if we have to change all the keys now its going to be risky but still vastly better than nothing. I would hope that a new key would be signed by an existing valid private key as well as newly issued keys. This would reassure people like me who have a substantial stash of old but valid public keys, while at the same time thwarting bad guys who can fake only those old signatures for which they have stolen valid private keys.

Joseph
Previous: Sverre RabbelierNext: Joseph Parmelee
Message 19 of 24 in “Lack of detached signatures”
  1. Joseph ParmeleeSep 27, 2011
  2. Junio C HamanoSep 28, 2011
  3. Michael WittenSep 28, 2011
  4. Olsen, Alan RSep 28, 2011
  5. Carlos Martín NietoSep 28, 2011
  6. Joseph ParmeleeSep 28, 2011
  7. Junio C HamanoSep 28, 2011
  8. Michael WittenSep 28, 2011
  9. Matthieu MoySep 28, 2011
  10. Jeff KingSep 28, 2011
  11. Ted Ts'oSep 28, 2011
  12. Junio C HamanoSep 29, 2011
  13. Ted Ts'oSep 29, 2011
  14. Junio C HamanoSep 29, 2011
  15. Ted Ts'oSep 29, 2011
  16. Sverre RabbelierSep 29, 2011
  17. Ted Ts'oSep 29, 2011
  18. Sverre RabbelierSep 29, 2011
  19. Joseph ParmeleeSep 29, 2011
  20. Joseph ParmeleeSep 29, 2011
  21. Jeff KingSep 29, 2011
  22. Olsen, Alan RSep 29, 2011
  23. Joseph ParmeleeSep 28, 2011
  24. Ben WaltonSep 28, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.