Gentoo Archives: gentoo-project

From: Kristian Fiskerstrand <k_f@g.o>
To: gentoo-project@l.g.o, Rich Freeman <rich0@g.o>
Subject: Re: [gentoo-project] pre-GLEP: Gentoo OpenPGP web of trust
Date: Fri, 01 Feb 2019 14:54:49
Message-Id: 1af4e9ff-970c-13bf-77bc-1d8bfeded7e6@gentoo.org
In Reply to: Re: [gentoo-project] pre-GLEP: Gentoo OpenPGP web of trust by Rich Freeman
1 On 2/1/19 3:32 PM, Rich Freeman wrote:
2 > On Fri, Feb 1, 2019 at 9:17 AM Cynede <cynede@g.o> wrote:
3 >>
4 >> I'd like Gentoo to support pseudonyms (for the purposes of privacy) as
5 >> FSF projects does, and in that case ID/webcam verification with OpenPGP
6 >> keys being signed by members of trustee makes real sense. (probably
7 >> that could be off-topic here)
8 >
9 > IMO this is fairly tangential to the WoT issue.
10 >
11 > However, I'll point out the main issue with allowing pseudonyms is
12 > that it basically reduces skin in the game. People are probably less
13 > likely to treat each other terribly if it will result in them never
14 > getting another job. On the other hand, people will behave better if
15 > they know their reputation within Gentoo will translate into better
16 > opportunities for them in the real world.
17 >
18
19 Exactly, and that is only on the social element. Now what should we do
20 if we don't know the identities of our developers and there is a remote
21 code execution committed to our tree, obviously malicious, or someone
22 misuse access to information[N1]. This basically builds on the argument
23 of skin in the game, but it can be dragged further than your example.
24
25 Notes
26 [N1] Infra is in a special role here, but so are a lot of other projects
27 like comrel just to name another.
28 --
29 Kristian Fiskerstrand
30 OpenPGP keyblock reachable at hkp://pool.sks-keyservers.net
31 fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-project] pre-GLEP: Gentoo OpenPGP web of trust Kristian Fiskerstrand <k_f@g.o>