4 ms·
OR, you could use already well-established key servers, e.g. pgp.mit.edu. Why reinvent the wheel?
by cgtyoder 10y ago
OR, you could use already well-established key servers, e.g. pgp.mit.edu. Why reinvent the wheel?
- finnn 10y agoThis is providing that information in the GitHub web UI, which previously did not mention that if particular commit was signed. It has always been available via well-established key servers using the git/gpg command line tools.
- eggman 10y agoI would love this to become a list of the benefits of adopting a 'reinvent the wheel' approach to building things.
- jlgaddis 10y agoI recall a discussion a while ago (on the cryptography list, I believe) where it was mentioned that pgp.mit.edu is often out-of-date, stops syncing, or is otherwise broken. The SKS keyserver pool was recommended instead.
- AdmiralAsshat 10y agohttps://pgp.mit.edu/faq.html https://pgp.mit.edu/faq.html >Can you delete my key from the key server? >No, we cannot remove your key from the key server. When you submit a key to our key server the key is also forwarded to other key servers around the world, and they in turn forward the key to still other servers. Deleting the key from our server would not cause it to be deleted from any of the other servers in the world and so this is not an effective way to ensure the discontinued use of your key. I discovered the above the hard way when I was testing an Android app called OpenKeyChain, which creates your PGP key and, without telling you, uploads it to several keyservers for "convenience". Since I was testing the thing, I used a private e-mail and my name. As a result, real name is now inextricably tied to that e-mail address through a keyserver that was ostensibly supposed to provide privacy... Neither here nor there, but I mention it because the experience somewhat soured me on the idea of non-deletable keys.
- dave2000 10y agoOn the other hand, it would appear to be a great way of persisting information you don't want removed.
- Spivak 10y agoSo an Android app in no way affiliated with the maintainers of PGP, GnuPG, or the key servers in question published your private information, that you gave it voluntarily, to a by-design decentralized key distribution system and it's somehow their fault? You're publishing completely public information on the internet. Even in a world where key servers will delete your key that doesn't really help you when anyone has access. The best you can do is mark your keys as invalid by submitting a revocation certificate. > If you still have the private key, you can use your PGP software to generate a revocation certificate, and upload that to the keyserver. The exact procedure for generating a revocation certificate varies depending on what PGP software you are using, please consult the documentation for more information. This will not delete your key from the key server, but it will tell people who download it that the key has been revoked, and should not be used. If you're annoyed that unpublishing something on the internet is futile there are a lot of government officials and celebrities who will sympathize with you.
- AdmiralAsshat 10y agoSurprisingly hostile reply, given that I made clear that I don't blame the keyserver for this. I did attempt to contact the app developers about their app's behavior--unfortunately, the only method they provided was a mailing list, so, upon having my first attempt at being discrete blow up in my face, I decided that being forced to send an e-mail to a public mailing list in order to draw attention the fact that I had inadvertently de-masked myself just seemed like rubbing salt into a wound. To boot, it seems like something of a stretch to put a privacy-conscious user who misconfigured (or was unaware what the default behavior was, in my case) his privacy app to be in the same boat as a G-man or a celebrity who took nude selfies, don'tcha think?
- lmm 10y agoPGP is modeled on physical mail: content is private, but identity is very public. (I mean, the very idea of signing something is inextricably linked to having a public identity - if you're signing commits on github then you're creating an identity that stands by those commits).
- kgo 10y agoAnyone can create a random key with a random email. See all the president@whitehouse.gov addresses on the keyservers. So if they used the keyserver network I could just make a fake key for anyone I want to impersonate and upload it. Github has no way to authenticate which keys are good and bad if they only use the keyserver network. So they have you upload the key on their site to implicitly authorize the key as one that you (the person with the github account, or at least its password) consider valid. http://pool.sks-keyservers.net/pks/lookup?op=vindex&search=president%40whitehouse.gov http://pool.sks-keyservers.net/pks/lookup?op=vindex&search=p...
- cyphar 10y ago> Github has no way to authenticate which keys are good and bad if they only use the keyserver network. So they have you upload the key on their site to implicitly authorize the key as one that you (the person with the github account, or at least its password) consider valid. Yes they do. It's called "the web of trust" and has existed for quite a long time.