[prev in list] [next in list] [prev in thread] [next in thread] 

List:       qubes-devel
Subject:    Re: [qubes-devel] Re: GitLab
From:       Andrew David Wong <adw () qubes-os ! org>
Date:       2017-05-13 21:35:18
Message-ID: 16745b77-4840-ab31-3e91-868878940aab () qubes-os ! org
[Download RAW message or body]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 2017-05-13 16:01, Felipe Dau wrote:
> On Sat, May 13, 2017 at 03:18:39PM -0500, Andrew David Wong wrote:
> > There are many other methods you could use to attempt to verify the
> > master key fingerprint aside from relying on the Qubes website. Here's
> > a brief, non-exhaustive list:
> > 
> > * Use different search engines to search for the fingerprint.
> > * Use Tor to view and search for the fingerprint on various websites.
> > * Use various VPNs and proxy servers.
> > * Use different Wi-Fi networks (work, school, internet cafe, etc.).
> > * Ask people to post the fingerprint in various forums and chat rooms.
> > * Check against PDFs and photographs in which the fingerprint appears
> > (e.g., slides from a talk or on a T-shirt).
> > * Repeat all of the above from different computers and devices.
> 
> Good examples! It would be nice if these were also on the verification
> page [0].
> 
> I would like suggest an additional approach that might be useful as
> well, which is using the debian-keyring. Assuming that the system
> which you are using to download Qubes is running a legitimate Debian
> (oh well), then you can easily verify Qubes' master key, as most of
> the ones that signed it are either in that keyring or were signed by
> others that are. This is what Tails instructs users to verify their
> key in one of their guides [1].
> 
> Thanks,
> -Felipe
> 
> [0]: https://www.qubes-os.org/security/verifying-signatures/
> [1]: https://tails.boum.org/install/expert/usb/index.en.html#verify-key
> 

Thanks. I've added this information to the document.

- -- 
Andrew David Wong (Axon)
Community Manager, Qubes OS
https://www.qubes-os.org
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJZF3wUAAoJENtN07w5UDAwX9UQAKbGZgP1G4u0OX7l5BBPtwW6
aCe2xzFQOoXXg9ux8sGyrrEDtkcEiYABv6lCocnb1cAwW+rCOnX8k8y1xonwbtRH
Z216wgAo1Pnlme8HKkEFR/TXAY3k5+9ABSDLv3Q613knzJFm3yj37hOQkotNHGjV
RLWfRsC4GbC5gAPTryZEbcsea4EPjKxo7549WH9p9OYjP7Sz1KxtMISmHtH9WaBe
qH+9zlL/JzV+Ivmt7QMA3aTMNhla4rOFLrZGLWGNer6WyEryd6CQkoL1AwtOJcek
cisMzclf30CtLmqUiTfbMT3vm4uIjavElgFiCww8AwC/TRrBtPHtuRTlOHunaCZj
oIRnd2lV1ztutPwILMbB9r8p1WL5mPfjY3uedigdwPhX1ML/hrqgx3e6YuwelkFV
O4jSJrzdEspyzknqz7evSGweoKc3HGpbwICFwk2Fm+C8R1NbYufUem/5fMC2XQEV
CZPDsYaO5oJITrJNfFi9PAeZQZpApUA2q33MEqJVK+Pwa20jwZyLplHLBg/CTVBE
nv1TVPpT/1Znd7ASXGhJsAtvbOqyUFjGkB/2NXwkuCIg7Gb9MyvQJAm01L4OOMgY
Ag/lgCNaPOqnk26OTnyrK5UODk8Zcy41YioEJvNSx1OkBLpM8CEeD+4/+tN5yFZt
es56EhrkF5JoGUPlKUCe
=S0N0
-----END PGP SIGNATURE-----

-- 
You received this message because you are subscribed to the Google Groups \
"qubes-devel" group. To unsubscribe from this group and stop receiving emails from \
it, send an email to qubes-devel+unsubscribe@googlegroups.com. To post to this group, \
send email to qubes-devel@googlegroups.com. To view this discussion on the web visit \
https://groups.google.com/d/msgid/qubes-devel/16745b77-4840-ab31-3e91-868878940aab%40qubes-os.org.
 For more options, visit https://groups.google.com/d/optout.


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic