1 |
On 17-08-04 05:51:38, Andreas K. Huettel wrote: |
2 |
> > > >Apparently, the Foundation only has a list of PGP key IDs in |
3 |
> > > >https://wiki.gentoo.org/wiki/Foundation:Member_List. Even worse, most |
4 |
> > > >IDs listed there are only 32 bit IDs, providing no security at all. |
5 |
> > > > |
6 |
> > > >I would like to ask the Foundation to keep a list with the (160 bit) |
7 |
> > > >PGP fingerprints of its members. (For developers, this information |
8 |
> > > >should be readily available in LDAP.) |
9 |
> > > > |
10 |
> > > >Ulrich |
11 |
> > |
12 |
> > What do we need to prove? |
13 |
> > |
14 |
> > That the the key belongs to a given individual or just that the key on the |
15 |
> > vote is the same as the key used for the membership application.? |
16 |
> > |
17 |
> |
18 |
> That the key on the vote is the same as the key used for the membership |
19 |
> application. |
20 |
> |
21 |
> This is impossible without the full fingerprint. |
22 |
> And with only the short keyid it's trivial to hack. |
23 |
> |
24 |
> -- |
25 |
> Andreas K. Hüttel |
26 |
> dilfridge@g.o |
27 |
> Gentoo Linux developer (council, perl, libreoffice) |
28 |
> |
29 |
|
30 |
I think we should just record the full key id, would we still need to |
31 |
also have the fingerprint in that case? |
32 |
|
33 |
-- |
34 |
Matthew Thode (prometheanfire) |