Gentoo Archives: gentoo-nfp

From: Matthew Thode <prometheanfire@g.o>
To: gentoo-nfp@l.g.o
Subject: Re: [gentoo-nfp] Re: PGP fingerprints of Foundation members (item for Trustees meeting)
Date: Fri, 04 Aug 2017 04:10:01
Message-Id: 20170804040954.GA20444@gentoo.org
In Reply to: Re: [gentoo-nfp] Re: PGP fingerprints of Foundation members (item for Trustees meeting) by "Andreas K. Huettel"
1 On 17-08-04 05:51:38, Andreas K. Huettel wrote:
2 > > > >Apparently, the Foundation only has a list of PGP key IDs in
3 > > > >https://wiki.gentoo.org/wiki/Foundation:Member_List. Even worse, most
4 > > > >IDs listed there are only 32 bit IDs, providing no security at all.
5 > > > >
6 > > > >I would like to ask the Foundation to keep a list with the (160 bit)
7 > > > >PGP fingerprints of its members. (For developers, this information
8 > > > >should be readily available in LDAP.)
9 > > > >
10 > > > >Ulrich
11 > >
12 > > What do we need to prove?
13 > >
14 > > That the the key belongs to a given individual or just that the key on the
15 > > vote is the same as the key used for the membership application.?
16 > >
17 >
18 > That the key on the vote is the same as the key used for the membership
19 > application.
20 >
21 > This is impossible without the full fingerprint.
22 > And with only the short keyid it's trivial to hack.
23 >
24 > --
25 > Andreas K. Hüttel
26 > dilfridge@g.o
27 > Gentoo Linux developer (council, perl, libreoffice)
28 >
29
30 I think we should just record the full key id, would we still need to
31 also have the fingerprint in that case?
32
33 --
34 Matthew Thode (prometheanfire)

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies