From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2B79848095D for ; Thu, 6 Aug 2026 16:00:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.52 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786032005; cv=none; b=NJuKHvsjTRiE/REP0dHB0/+U0pCfluVGkGs2fdBrwUYf5WBo6CAzLvLlkODn7IOgUf2Apy5gGK6F+qcxNGbVuSW2f6iYSGXQCViYe0zjA/Z8bMqXBJ3XUNQivSQKkwBjXI15fU5UVXy8UnIRtVDft8R7kGtDu8jmPMU7WvG2CDc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786032005; c=relaxed/simple; bh=ycJ8rKpBMdQFqbUz4M6Xb3769cBcyiJkmnsYtIgdRS4=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=Z7s4PqLxYCaAWYI7aMmxcAbcoJxhGuzSVA7Vs8nT80SpyLrSUL8OASrz7EaWwVHZUWWNlXPjkDrD54TB/FcyAgTq4++G7DwDtQqHsM1n3Izio1qB1p7Q/Z3cAhC/+CUJk2X+QBuF+QX7/zVnc+EwiGINOAsJib6ONMZirL1Wa6s= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=baylibre.com; spf=pass smtp.mailfrom=baylibre.com; dkim=pass (2048-bit key) header.d=baylibre.com header.i=@baylibre.com header.b=KqTnBLBX; arc=none smtp.client-ip=209.85.128.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=baylibre.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=baylibre.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=baylibre.com header.i=@baylibre.com header.b="KqTnBLBX" Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-49802c418b5so23120235e9.1 for ; Thu, 06 Aug 2026 09:00:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=baylibre.com; s=google; t=1786031998; x=1786636798; darn=vger.kernel.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=/57MP8Y6dfx+0v62gjjxAjBWKdRCHhuEATtBW55GLDg=; b=KqTnBLBXl5DGBJS5oLIPo9IqXODuTm5h+NNrp3UyyRJnb9UZ4LuEZRsmwDJbvM/xTY FzgWxfLKOubNJmp9B7JzO8+KXvfNBx0PQcB99DFLh6cGQ5Ntuz7Qpjuxq4uQ1eyG8j8O KFTeUXwuX0P6CHPFFM48VyiVwje/X5F5KuTdE72f8H/nFzqOD96516INCpEaoHFRt4Pi 1XVc2EUSS3ZZe1O37Y9Twd0fJBxUkXH4G4YlFilMg4aLpbMbs8cBZbdnDvudDXtZWwAk osGyf4JBQLffjdPcz7QB5t9iPNYIRvbVeFCFjJ+MEolnAydvQQe2wztaUCwG/tF2rPLe /MUw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786031998; x=1786636798; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=/57MP8Y6dfx+0v62gjjxAjBWKdRCHhuEATtBW55GLDg=; b=mrWgOpj6h23YTbPYQUWYc3wkuUbS/VWxWmRY8wijn3+e7IcJ5UcUqPyslDVDRB6mQ/ I/QD2CkEUlIvSKfhnyedzNh2w/SvkqDeRIJ7iizqV37Kzl4hSS1nKMpe9cB/QPmU7JQR yg7pd3WmFsKflnZMru7tJ5prz7NVDj3ogyanKIE33NzV32aYXeHb4cIKmsuOPUQElhbV SBnP2l0/U9c9020bc7h6FvsHhcfidfQPIxAt6X24o0ikKqA+BCiAiFmMqUPS72q7uGxt zm5y8w6dD/3yqM4OqIOB+3P0D4B5Mk7I4RWCmqUccFyNhJKloVptc+ds3CesMuSuUOoa uE7g== X-Forwarded-Encrypted: i=1; AHgh+RohKCJBUZN9hOftNnnJ3Qgwtnl9v9TM8ao+8spMSO7mF4n6FQTmFG5Pvg0Af89kisgt5Uiyn70PTt97NkU=@vger.kernel.org X-Gm-Message-State: AOJu0YzAI5r5sqq41RzzWSX/lIBdsiLW5VNNw0xUA053i+zNYPQIxnX6 KGl0esUN4mHoUml/CRGBgIEujtq20/7z0QNaj6Zcyli8i78TSGt6ZR3uWyXrhZRYVeY= X-Gm-Gg: AR+sD11u6x9OGFAr1Zu4+gfogC+WkU/VDCudZzMCy0X75tv81Ht56eamyXjTKi2aPGP 8lXYVX7SKF9zUlcsu4uLb8fs7LNOkNudmayCwv4YcHRP6BZlolRkoEBXXb6E+B4MwQxTMLaUyP4 sCnKRjnPagq2D0LHoj9KMh8rkVLw/zeDbMDwL2dWHUns24YFL6m1QNBrhI9QgYlrcIBJxe930HF YVZRVPu3kjyfb/eMU0muHsbD2qdIFi3e5ckGRFeYNO52kq7qZYWGoE4+OUnsqbJlPWEfS++BDJ/ D26TM1P1mxqGC6C1yzc3XnMJlaPZiTVybHUfm1n7Ya25J9nw5BAhrLIxR4tsOZBHZCOXG/Nrhpf wtO+Yd53cRtdmVB2Ccoix2phBzLk3IdtH2+Fznk5sTpncrSOhtPM2H2GKvFgkbU59SZ3r2BBfXh cQFk8J8KciDwqwWtmAYzKGvtPwrrWtGkFsAg4Ttud4Cueyl9VWNl76gdrJfPFTWVjrthyerEEtL hnpl0g9MjMVoh3swzaus33a0gF9OB+oSshtgkdZeDsVDr/esegD X-Received: by 2002:a05:600c:a21b:b0:495:4e89:3f30 with SMTP id 5b1f17b1804b1-4994e7c5e49mr167017945e9.15.1786031998252; Thu, 06 Aug 2026 08:59:58 -0700 (PDT) Received: from localhost (p200300f65f0171047dc1d03432df4abc.dip0.t-ipconnect.de. [2003:f6:5f01:7104:7dc1:d034:32df:4abc]) by smtp.gmail.com with UTF8SMTPSA id ffacd0b85a97d-47ff79a72f6sm7026503f8f.2.2026.08.06.08.59.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 06 Aug 2026 08:59:57 -0700 (PDT) Date: Thu, 6 Aug 2026 17:59:54 +0200 From: Uwe =?utf-8?Q?Kleine-K=C3=B6nig?= To: Krzysztof Kozlowski Cc: lpcosse-keysigning@baylibre.com, users@linux.kernel.org, linux-kernel@vger.kernel.org, Konstantin Ryabitsev Subject: Re: PGP keysigning at LPC/OSSE 2026 Message-ID: References: <31bcf7e3-171b-45fe-86a6-69731c95412e@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="2zgdfhj62ofwx2lh" Content-Disposition: inline In-Reply-To: --2zgdfhj62ofwx2lh Content-Type: text/plain; protected-headers=v1; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Subject: Re: PGP keysigning at LPC/OSSE 2026 MIME-Version: 1.0 Hello Krzysztof, On Thu, Aug 06, 2026 at 12:11:06PM +0200, Krzysztof Kozlowski wrote: > On 05/08/2026 12:29, Uwe Kleine-K=C3=B6nig wrote: > > On Wed, Aug 05, 2026 at 08:32:22AM +0200, Krzysztof Kozlowski wrote: > >> While as much as I like key signing, I do not believe in > >> Zimmermann=E2=80=93Sassaman protocol to work, because of people's negl= igence. It > >> requires the participants to check if THEIR key is correct, but based = on > >> my recent practice (people generated new key and week later they lost > >> password to it; people received my signed keys and could not decrypt t= he > >> message because they never used encrypted email, people sent me emails > >> asking to send their keys) I think it has significant risk of this not > >> happening. People just do not understand the security principles here > >> thus they do not think certain steps are an absolute requirement. > >=20 > > I see your point. However if Bob confirms his fingerprint on the > > Zimmermann=E2=80=93Sassaman list is right while he didn't actually chec= ked and > > as an effect a forged certificate is signed, that's mostly Bob's > > problem. > >=20 > > Also if Bob doesn't check his own fingerprint, he probably also doesn't > > check the certificates he signs carefully and thus his signatures > > shouldn't be trusted. > >=20 > > That's why a keysigning is about a *web* of trust where the (little?) > > trust in each individual path between me and a given other person sums > > up. >=20 > I am rather thinking of someone planting their key in place of the > person's one, thus of course Bob will have a problem, but bigger problem > is that I would sign malicious actor's key. Yeah, I got that. And that probably helps the attacker that Alice has confidence in Bob's alleged key and thus that's also bad for Alice and might come with a loss of trust into your and my signature. But note that this isn't unfixable for eternity. You can still revoke your signature once the fraud becomes known to you. > >> IOW, I do not believe people will check their key fingerprints and ema= il > >> IDs, they will gladly accept what you prepared on the server and that > >> could have been modified by an attacker or mischievous actor wanting to > >> prank us. I already wondered if I should delete 2 or 3 random nibbles in each fingerprint on the list (e.g. making my line 0D25 11_3 22BF AB1C 1580 266_ E2DC DD91 _266 9BD6 instead of 0D25 11F3 22BF AB1C 1580 266B E2DC DD91 3266 9BD6 such that I have to tell "F-B-3" additionally to convince the potential signer that I really checked my fingerprint). > >> That's why I require that the keys to be given to me must be prepared = by > >> that owner, not by a third party. I have some proofs that at least that > >> key was in the possession of the owner, when he was preparing it. I wi= ll > >> be happy to sign keys of developers given to me that way. > >=20 > > Last time I talked to Greg about these paper slips, he had trouble > > finding gpg-key2ps on Arch and I prepared the postscript file for him := -D >=20 > 1. gpg --fingerprint your-name > 2. Paste it to a TXT file without the "sub" parts > 3. Copy+paste to fill up the page > 4. Print and cut >=20 > No need for gpg-key2ps. There is no *need* for gpg-key2ps, but it's convenient that you can just do 1. gpg-key2ps ukleinek@kernel.org > mycert.ps 2. Print and cut instead of your four steps above. (Actually I would recommend a step 1.5 in both your and my recipe to double check the output before further processing, or at least use the fingerprint instead of your-name or the email address.) > >> I know that you want to speed it up, but honestly korg keysigning shou= ld > >> not have that many participants, so exchanging key slips should be fine > >> as I was doing in the past. > >=20 > > I think even if we're only 10 in the end, the speedup is noticeable. And > > it also simplifies the actual signing process for everyone, as I will > > provide a keyring of all the handed in certificates. >=20 > And now I have one more doubt because Bob, who I did not trust that he > understands security principles of key signing (see my previous email > why), might not verify that keys in above keyring are the ones from the > paper. IOW, Bob will happily sign whatever you send him, to speed things > up. Otherwise there is no speed up comparing to: >=20 > $ gpg --recv-key it is 100% verified> `gpg --recv-key` has its own problems. You can use it with a full fingerprint, but the Bob you talk about will probably use it with the "long id", i.e. only the last 16 nibbles of the fingerprint (assuming pgpv4). And it also doesn't give you 3rd party signatures which might give a hint that the received certificate is valid without exposing you to Certificate Flooding[1]. So getting the certificates to sign from a curated source (like the keyring I'll provide, or WKD or the kernel pgpkeys repo or DNS) also has its upsides. And I encourage you to not rely on my key collection, but cross check it. But the effort to find a certain key and convince yourself it's not forged obviously grows. So this is another trade-off between security and comfort. [1] https://dkg.fifthhorseman.net/blog/openpgp-certificate-flooding Best regards Uwe --2zgdfhj62ofwx2lh Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEEP4GsaTp6HlmJrf7Tj4D7WH0S/k4FAmp0r3gACgkQj4D7WH0S /k5vagf/Qb4wrQuTYXlrqx8YqSVzjoodH/HMN5nk8pDKxWTi7gwTeE6CL6i4OXWC 70RZtqYdZr2+tNgOUdrGL7eyWMTTkXXcEBlO+j2yl056fIdbNXS2XazNUUEV+YVD nCETLtc+jia76CSiTDURskeWmtFny5c+sD5a7NKEsKvw5y890CgstBgKOoEb+GVM /Mhu1/svkNxEiJ2ChbsO5w8ie48GYzwVrUUoGe5K0ysVK3MRHaEH1p35rhQIT29c Y2SkR/pySDYTRwzZtLk7F1h4KluiBUtR4a0Iy6pQBMGfqGyTp7kd84I9+DLXH6JW Y3NL2xSGFDLtStzARumMPqhWrTjaqg== =QZnt -----END PGP SIGNATURE----- --2zgdfhj62ofwx2lh--