From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E02B4403E89 for ; Wed, 5 Aug 2026 10:30:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785925807; cv=none; b=Qfh8KOPVFg8JCqiT9AY+4p/yMbr5jXzfTdw1MiJSv0sVDzmz3/PysMFhURCTxOa5Y+7lxS7ATYY1ZxP4ejYptbkBaFJL03O8HKKanppz4U3Um5eisArnWgoXMtEcjWpQEdXuoOl1XuisMC2BHHBUBaOVQVTHIT/BmYqSl/w3u3o= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785925807; c=relaxed/simple; bh=IXANRNIlD8z+x+W+GjGf5Wlm8sy502aCJRiRUoBNTIs=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=V+gKAD65fR1W+YU2YIjtHcry77p8QWGjznOasx9+r6dd+CzCBCQC63yfyhD3R/F53ZcyKIhoWwnd+BXQOTHdNQmfHUCEQMu558M8e61h6ZTnh0udFzaSlv+bCviJzKUW0bi/WPYutIx+H/NxKMyTwkIeGWGcqU/o4K0ImGyKoGk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=baylibre.com; spf=pass smtp.mailfrom=baylibre.com; dkim=pass (2048-bit key) header.d=baylibre.com header.i=@baylibre.com header.b=DszuHv7d; arc=none smtp.client-ip=209.85.221.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=baylibre.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=baylibre.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=baylibre.com header.i=@baylibre.com header.b="DszuHv7d" Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-47f6609c657so384016f8f.2 for ; Wed, 05 Aug 2026 03:30:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=baylibre.com; s=google; t=1785925800; x=1786530600; darn=vger.kernel.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=IXANRNIlD8z+x+W+GjGf5Wlm8sy502aCJRiRUoBNTIs=; b=DszuHv7dET3qrSDa48r3DferIsg98x8AkbgtIf3THaPk/4SYr99wVULn8VAfZ9RPvC WwbGsPy6bqgcAzEChkmOu8HS1tLXu1QJLD98phYnufsc+qeNM+aw+1ys5Jx4Dw3QJ4gt 6JpV5F4JHvZ9idXb6+/Pvz5J/0PLJKZmuKilFZJe77SHEnMx/papumEI8SS4LY3HnDK/ Yv6IKgQJonBYoY+XPtNcc0qUFnO+XS7l1haTEava7xKij1q3DEqGaCvq8dUQSSlF9rC3 FAr+s9O/duMymVjg4wm0w6Gpo8m0qQxyVzvITwDm4erTcb/KE85r60XijGJ+JtOzsWcV h+pw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785925800; x=1786530600; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=IXANRNIlD8z+x+W+GjGf5Wlm8sy502aCJRiRUoBNTIs=; b=JpW5Wdb2VPidh6Dhpnwaqb/mHbUC+A7MZufN5Yo+bWckWuf2gYBD1JR9Rc/6y2tOuH ZHsCBce2+try/Fj8B90uyIFnhDkw2cn1KCBzQSbmJdv1gOvuHDdQPhuxW3jc4K8pGDrh tXCBKEVDEZ9UiAS4IC7o7Iy/BsY8S8n+YUvtuWlbByiBpJOYAa9AqwYIFNhXtKvhRDug 7WTl9f20mmtHQp/bkFbCDmPslSFyFAAkYGuavoPjuO0nVU+ijUXWu7h2jGshv/ATFne1 6Pi5XARaykUET3+cuEGjvUijxgF3Jrm1oxb+XMV0tk3+3G+RCerktqtZdFVY4snG7oS4 4/SA== X-Forwarded-Encrypted: i=1; AHgh+RrEVVZW/PCZW/FcIYChlj0nQWNqQd4LYex/q5wwJ/W83PujJIqN7f1B52PzlK0ggjqGLb1RYaamTeBKITs=@vger.kernel.org X-Gm-Message-State: AOJu0YybVJMUybtimDja56tr3rc3ATDb7cG0SO8PzMlZ0v2N8lPnaF/n MrYLNF3BBMH/NpRQEhNG6/f1uXKXjjKAKX2A5oc39aPhnI9MeI9QDGKgw7GJFrNIs+Q= X-Gm-Gg: AR+sD11KJfNqaSv7JgfOUv3UZcRj9i0/ZWSjC5e+styQcWb2jloAZdpmbtE181Sg5JT hnJJswfnkQEOG9xFu8q1XneasX1J72PvGQFewTezdSC62sZOfK0+LOtuGmeoeKduSWdkW+fQgqi y1MSXdHxmEa5FHbWGUUaUM6evgiNH+KMxcpGo4vmh0GJcmlXmRLspIvl4p8OS+iGxUOVadqI5xC kiz9eiMTpsHs66CPuBMtsrDCTm/sumIHHk21dnEbt4rWBcqUA2d/vroqTTZkPy68Ae+5Ehk79oq 5+OLtCGhawY4QWEUAtYLRlWR4r0Ztw52VVuyoAv8p3z3AEEs/r8hhulbrrh91DKgDmQUj81ygXa +aft0fx92C6+pIfcLo+sCB950Fe3nev363v1jAZBNo/1+ovlNdGNbpL+9RRSREjPuQ0VEQe58cR QYwiqOgqOuFrFnohxi5NY6va3QfgFvSS+SOxmygfIOw26Zngb8dp4thLaQXIP+U3hfUnWBk7ZDh rDajdZDSONLkvaxl08gFCorBgFEhF6TohUR99sb+s42wmqS19ic X-Received: by 2002:a05:6000:4796:b0:47f:86af:8fdd with SMTP id ffacd0b85a97d-47fec4e73b3mr7393495f8f.3.1785925800529; Wed, 05 Aug 2026 03:30:00 -0700 (PDT) Received: from localhost (p200300f65f017104b119ec4b8408a059.dip0.t-ipconnect.de. [2003:f6:5f01:7104:b119:ec4b:8408:a059]) by smtp.gmail.com with UTF8SMTPSA id ffacd0b85a97d-47fec232328sm8016431f8f.24.2026.08.05.03.29.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 05 Aug 2026 03:29:59 -0700 (PDT) Date: Wed, 5 Aug 2026 12:29:58 +0200 From: Uwe =?utf-8?Q?Kleine-K=C3=B6nig?= To: Krzysztof Kozlowski Cc: lpcosse-keysigning@baylibre.com, users@linux.kernel.org, linux-kernel@vger.kernel.org, Konstantin Ryabitsev Subject: Re: PGP keysigning at LPC/OSSE 2026 Message-ID: References: <31bcf7e3-171b-45fe-86a6-69731c95412e@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="bmnkx6spcmr7no5v" Content-Disposition: inline In-Reply-To: <31bcf7e3-171b-45fe-86a6-69731c95412e@kernel.org> --bmnkx6spcmr7no5v Content-Type: text/plain; protected-headers=v1; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Subject: Re: PGP keysigning at LPC/OSSE 2026 MIME-Version: 1.0 Hello Krzysztof, On Wed, Aug 05, 2026 at 08:32:22AM +0200, Krzysztof Kozlowski wrote: > While as much as I like key signing, I do not believe in > Zimmermann=E2=80=93Sassaman protocol to work, because of people's neglige= nce. It > requires the participants to check if THEIR key is correct, but based on > my recent practice (people generated new key and week later they lost > password to it; people received my signed keys and could not decrypt the > message because they never used encrypted email, people sent me emails > asking to send their keys) I think it has significant risk of this not > happening. People just do not understand the security principles here > thus they do not think certain steps are an absolute requirement. I see your point. However if Bob confirms his fingerprint on the Zimmermann=E2=80=93Sassaman list is right while he didn't actually checked = and as an effect a forged certificate is signed, that's mostly Bob's problem. Also if Bob doesn't check his own fingerprint, he probably also doesn't check the certificates he signs carefully and thus his signatures shouldn't be trusted. That's why a keysigning is about a *web* of trust where the (little?) trust in each individual path between me and a given other person sums up. > IOW, I do not believe people will check their key fingerprints and email > IDs, they will gladly accept what you prepared on the server and that > could have been modified by an attacker or mischievous actor wanting to > prank us. >=20 > That's why I require that the keys to be given to me must be prepared by > that owner, not by a third party. I have some proofs that at least that > key was in the possession of the owner, when he was preparing it. I will > be happy to sign keys of developers given to me that way. Last time I talked to Greg about these paper slips, he had trouble finding gpg-key2ps on Arch and I prepared the postscript file for him :-D > I know that you want to speed it up, but honestly korg keysigning should > not have that many participants, so exchanging key slips should be fine > as I was doing in the past. I think even if we're only 10 in the end, the speedup is noticeable. And it also simplifies the actual signing process for everyone, as I will provide a keyring of all the handed in certificates. If you still want a paper slip from each participant before being ok to sign their certificate, that's fine. I'm still convinced that preparing the Zimmermann=E2=80=93Sassaman list is a net win. And you're welcome to participate no matter if your cert is on the list or not. Best regards Uwe --bmnkx6spcmr7no5v Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEEP4GsaTp6HlmJrf7Tj4D7WH0S/k4FAmpzEKMACgkQj4D7WH0S /k6mLAgAsqqgmEzVX7AWfrgCNiRHoTHZRviScNG9h3OFn2n6rq+VUsFTFNCr8yM8 FjoJU6aPsKL5TbnnXrRrnEyfafhURDRAmCi2Bg3DWN1PxDd4WT/Z7KAfLyVkDL2h MA02j+IsjT4B+2Kl+oz+dKXkmKBEtyX1QjRsNLmSFQuXsU+P8VxnNlSsszqNKXsw GqlgXoCYdUN1fiYB9fadi1SeI1gIeWrdM4LmUa/9RgPzFxedEGgJYmHe/yE+yY0Y P20mIGKPE1GxSzqA8TtewQINumff2evjKJ/XMUCAWYyu81Hw7vxTsFaP4DxavBnb PT4kmps07oMRDw2OZaC9tWzxg35i2A== =l8WC -----END PGP SIGNATURE----- --bmnkx6spcmr7no5v--