[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [Debconf-discuss] Key Signing at Debconf: Attend the BoF for Checksum reading!



On Sat, Aug 15, 2015 at 08:50:55PM +0200, Daniel Kahn Gillmor wrote:
> On Sat 2015-08-15 20:00:29 +0200, Anibal Monsalve Salazar wrote:
> > On 15/08/2015 5:08 PM, "Sven Bartscher" <sven.bartscher@weltraumschlangen.de> wrote:

> >> Unfortunately I arrived after that. Is there any other opportunity,
> >> to compare the hash, in sight?

> > Look for dkg or me to compare the hash.

> Or, come to the live demo lightning talks session Sunday evening at
> 18:00 in Berlin/London, where Aníbal and i will give a live demo of how
> to sign keys with people in person.

> The hash of the file will be displayed during the live demo.

This is only a valid proxy if you and the people you're exchanging keys with
are present for the *same* display of the checksum and confirm that it
matches.  Otherwise, it's just another example of that sketchy dkg character
trying to compromise the Debian keyring by using different checksums for
non-overlapping audiences.

-- 
Steve Langasek                   Give me a lever long enough and a Free OS
Debian Developer                   to set it on, and I can move the world.
Ubuntu Developer                                    http://www.debian.org/
slangasek@ubuntu.com                                     vorlon@debian.org

Attachment: signature.asc
Description: Digital signature


Reply to: