sks-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Sks-devel] The pool is shrinking


From: Stefan Claas
Subject: Re: [Sks-devel] The pool is shrinking
Date: Sat, 17 Aug 2019 00:24:01 +0200

Hendrik Visage wrote:

> > On 16 Aug 2019, at 23:29 , Stefan Claas <address@hidden> wrote:

> > Please explain in 2019 to you friends, wishing to learn secure email
> > communications, that they should use PGP, while everybody can sign
> > their pub key with arbritary  (and illegal) data, thanks to SKS.
> 
> The signature is a indication of who knows you, and SKS is a mechanism, not
> the only mechanism to setup a web of trusts

??? Mr. or Mrs. X signs my pub key, put some 'funny stuff' on it, without
my knowledge and I should know these people? Or look at prominent people's
keys with lots of sigs, while the key holder does not sign back ... Do
you think that those prominent key holders know the signers, or could
it be the case that those are only fan sigs, bringing no weight to the
WoT?

> > They will for sure show you a stinking finger.
> 
> You aren’t forced to be part of, nor use, the SKS.

Correct. I recently saw that my current pub key was uploaded, while
I am no longer part of SKS. Others may think that I am still using
SKS. :-(
 
> > A public key in 2019 does not mean that it can be used for nasty
> > things, while a public key holder can not defend him  / her self!
> 
> I may have an outer wall that get’s grafiti all the time… I can’t protect
> that every single minute of the day… but I can proof it is my home given the
> fact that only I have a set of keys that will open the (full of grafiti)
> garage door!!
> 
> that public key’s “signing” is the perpetrator that acknowledges it’s my key,
> even if/when he/she/they/them/whatever put horrible things on it, they are
> still the ones that can be shown as the ones that did it…

??? Then please tell us who did the 'funny' sigs on Facebook's pub key.

> > May I ask why you SKS operators did not implemented GnuPG's
> > feature the --no-modifiy flag? It is not a brand new feature …
> 
> Perhaps as it’s not running GnuPG/pgp inside the SKS key servers ;)

Mmmhhh ... and nobody liked to tackle this issue ...

> SKS is just a mechanism to share (decentralized) a blob of data with a random
> number ID

Yes, unfortunately.

Regards
Stefan





-- 
box: 4a64758de9e8ceded2c481ee526440687fe2f3a828e3a813f87753ad30847b56
GPG: C93E252DFB3B4DB7EAEB846AD8D464B35E12AB77 (avail. on Hagrid, WKD)



reply via email to

[Prev in Thread] Current Thread [Next in Thread]