Gentoo Archives: gentoo-project

From: Michael Orlitzky <mjo@g.o>
To: gentoo-project@l.g.o
Subject: Re: [gentoo-project] Require OpenPGP signatures from existing devs on new developer applications?
Date: Thu, 05 Jan 2017 13:17:03
Message-Id: 856c8a07-10b3-fa9f-5fdb-620e27741160@gentoo.org
In Reply to: Re: [gentoo-project] Require OpenPGP signatures from existing devs on new developer applications? by "Paweł Hajdan
1 On 01/05/2017 08:10 AM, Paweł Hajdan, Jr. wrote:
2 > On 04/01/2017 22:19, Michael Orlitzky wrote:
3 >> b) Verify that we can each SSH into dev.gentoo.org, confirming
4 >> that I am really mjo and that he is really pesa. Again, we
5 >> already know that the guy who has mjo's key is mjo and the guy
6 >> who has pesa's key is pesa. Nothing new is learned.
7 >
8 > Somewhat off-topic nit-picking: how would you verify the other person is
9 > connecting to the real dev.gentoo.org instead of some local trickery on
10 > their machine?
11 >
12
13 Not at all, it's fun to think about. I could create a text file on the
14 server while I've got eyes on the other guy. Our home directories are
15 world-traversable, and if he can cat /home/mjo/path/to/whatever.txt and
16 it looks correct, then I would be convinced.