oss-sec mailing list archives
Re: upstream source code authenticity checking
From: Daniel Kahn Gillmor <dkg () fifthhorseman net>
Date: Tue, 30 Apr 2013 14:24:24 -0400
On 04/26/2013 01:57 AM, Alistair Crooks wrote:
All people can see from a key listing is who trusted them and when, not how much, or whether the trust was warranted.
Just for the record, most OpenPGP key certification listings don't indicate anything at all about trust, including "who trusted them". they show cryptographically-verifiable assertions of identity and control over key material. Put another way, a signature on an OpenPGP key+userid says "I believe that this key belongs to this person" -- it doesn't say anything about trust in that person (or about their intrinsic trustworthiness). Sorry for the nit-pick, but the term "trust" is so overused and confused in these contexts that i think it's important to clarify it when it's getting muddled. Regards, --dkg
Attachment:
signature.asc
Description: OpenPGP digital signature
Current thread:
- Re: upstream source code authenticity checking, (continued)
- Re: upstream source code authenticity checking Kurt Seifried (Apr 25)
- Re: upstream source code authenticity checking Daniel Kahn Gillmor (Apr 25)
- Re: upstream source code authenticity checking Alistair Crooks (Apr 25)
- Re: upstream source code authenticity checking Kurt Seifried (Apr 25)
- Re: upstream source code authenticity checking Dag-Erling Smørgrav (Apr 26)
- Re: upstream source code authenticity checking Kurt Seifried (Apr 26)
- Re: upstream source code authenticity checking Dag-Erling Smørgrav (Apr 26)
- Re: upstream source code authenticity checking Alistair Crooks (Apr 26)
- Re: upstream source code authenticity checking Kurt Seifried (Apr 26)
- Re: upstream source code authenticity checking Eric H. Christensen (Apr 29)
- Re: upstream source code authenticity checking Daniel Kahn Gillmor (Apr 30)
- Re: upstream source code authenticity checking Robbie MacKay (May 01)
- Re: upstream source code authenticity checking Alistair Crooks (May 02)
- OpenPGP certifications are identity assertions [was: Re: upstream source code authenticity checking] Daniel Kahn Gillmor (May 02)
- Re: OpenPGP certifications are identity assertions [was: Re: upstream source code authenticity checking] Simon McVittie (May 02)
- Re: upstream source code authenticity checking Kurt Seifried (May 02)
- Re: upstream source code authenticity checking Russ Allbery (May 02)
- Re: upstream source code authenticity checking Alan Coopersmith (May 02)
- Re: upstream source code authenticity checking Russ Allbery (May 02)
- Re: upstream source code authenticity checking Josh Bressers (Apr 25)
- Re: upstream source code authenticity checking Alistair Crooks (Apr 25)