[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] upstream source code authenticity checking
From:       Daniel Kahn Gillmor <dkg () fifthhorseman ! net>
Date:       2013-04-30 18:24:24
Message-ID: 51800C58.9090604 () fifthhorseman ! net
[Download RAW message or body]


On 04/26/2013 01:57 AM, Alistair Crooks wrote:
> All people can see from a key listing is who trusted them and
> when, not how much, or whether the trust was warranted.

Just for the record, most OpenPGP key certification listings don't
indicate anything at all about trust, including "who trusted them".
they show cryptographically-verifiable assertions of identity and
control over key material.

Put another way, a signature on an OpenPGP key+userid says "I believe
that this key belongs to this person" -- it doesn't say anything about
trust in that person (or about their intrinsic trustworthiness).

Sorry for the nit-pick, but the term "trust" is so overused and confused
in these contexts that i think it's important to clarify it when it's
getting muddled.

Regards,

	--dkg


["signature.asc" (application/pgp-signature)]

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic