Keysigning party / trusting government-issued ID?
Will people be trusting Government-issued ID documents at the keysigning party this year? What are the alternatives? Would anybody be interested in expanding the information about this topic on the page[1] about FOSDEM keysigning? Regards, Daniel "Berlin truck killer Amri had 14 identities in Germany" http://www.bbc.com/news/world-europe-38516691 Spy agencies using fake passports for assassinations, why wouldn't they use them for keysigning too? https://en.wikipedia.org/wiki/Assassination_of_Mahmoud_Al-Mabhouh Fake passport at FOSDEM 2016 keysigning? https://lists.fosdem.org/pipermail/fosdem/2016-February/002445.html 1. https://fosdem.org/2017/keysigning/
Hi Daniel, Daniel Pocock wrote:
Will people be trusting Government-issued ID documents at the keysigning party this year? What are the alternatives? Would anybody be interested in expanding the information about this topic on the page[1] about FOSDEM keysigning?
I expect that people this year will not be trusting passports that have printed "SPECIMEN" on them... But a PGP keysigning does not aim to prevent signing keys from government spy agencies who offer genuine passports that have been issued to fake names. I doubt that many spies with such documents will be standing in line for a couple of PGP signatures though. Every keysigning participant is free to choose which documents they accept as proof of identity and which keys they will or will not sign. When you are unsure about somebody's proof of identity, I would recommend that you do not sign their key. And people who don't trust government issued ID documents at all, probably shouldn't join the keysigning. The organisers strongly recommend that every participant bring at least one valid, generally recognised, official government issued ID with a good photograph; such as a passport, or EU identity card. Bringing multiple documents (e.g. an additional driver's license) is even better. Regards, Johan
On 05/01/17 21:31, Johan van Selst wrote:
Hi Daniel,
Daniel Pocock wrote:
Will people be trusting Government-issued ID documents at the keysigning party this year? What are the alternatives? Would anybody be interested in expanding the information about this topic on the page[1] about FOSDEM keysigning?
I expect that people this year will not be trusting passports that have printed "SPECIMEN" on them...
But a PGP keysigning does not aim to prevent signing keys from government spy agencies who offer genuine passports that have been issued to fake names. I doubt that many spies with such documents will be standing in line for a couple of PGP signatures though.
Every keysigning participant is free to choose which documents they accept as proof of identity and which keys they will or will not sign. When you are unsure about somebody's proof of identity, I would recommend that you do not sign their key. And people who don't trust government issued ID documents at all, probably shouldn't join the keysigning.
The organisers strongly recommend that every participant bring at least one valid, generally recognised, official government issued ID with a good photograph; such as a passport, or EU identity card. Bringing multiple documents (e.g. an additional driver's license) is even better.
Given that free software doesn't discriminate against any field of endeavor, there is no reason why an MI6/Mossad/CIA/KGB hitman can't have his key signed. A bigger issue may arise when people email the signatures to addresses other than those they are actually signing, that is when the ID-spoofer can really benefit. Maybe it is more important to focus on that than the quality of the ID? Regards, Daniel
On Fri, Jan 06, 2017 at 11:08:17AM +0100, Daniel Pocock wrote:
Given that free software doesn't discriminate against any field of endeavor, there is no reason why an MI6/Mossad/CIA/KGB hitman can't have his key signed.
Nobody said anything to the contrary. Johan simply pointed out that such agents will probably not *want* to do this. Part of their job is "staying in the shadows". Stating your name for the record to a couple hundred people is anything but that (even if that name is not legitimate). -- < ron> I mean, the main *practical* problem with C++, is there's like a dozen people in the world who think they really understand all of its rules, and pretty much all of them are just lying to themselves too. -- #debian-devel, OFTC, 2016-02-12
participants (3)
-
Daniel Pocock -
Johan van Selst -
Wouter Verhelst