Re: [FOSDEM] Fake passport at FOSDEM 2016 keysigning?
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 On 02/01/2016 11:27 PM, Jens Stomber wrote: Hi, First of all: I didn't notice the counterfeit passport and signed the key. I should have noticed. And this incident is a wake-up call to better check the presented ID's before accepting them. Secondly, the knowledge about the fake passport brings me in a difficult situation. Let me explain that a bit. Any attempt to undermine the web of trust, is a serious blow to both the open source and the security community. Though the motivation to present a fake passport may be noble, its consequences can be severe because it undermines an important tool for secure and authenticated communication. So only if there are enough safeguards such a 'wakeup call' can be done in a ethical way. I think about safeguards like: - - revoking the offending key /before/ the keysigning event - - announcing on forehand that, as part of a test, a fake passport may be presented - - revealing all the details right after the key signing event The person causing the incident at FOSDEM did not have any safeguards like these in place and seemed to have lacked any ethical or legal consideration before taking this action. From a legal point of view it is fraud to 'present a fake passport as if it is real'. At FOSDEM it was done under Belgian jurisdiction and that kind of fraud is punishable in Belgium with a jail sentence up to 10 years. That brings me to my dilemma: Because of the consequences for the web of trust, I would normally file a complaint (for fraud) against anybody who presents me a fake id at a key signing party, except when this was part of a test with enough ethical (and legal) safeguards. It is clear that this action was not a case of malicious intent but mere a case of being unthoughtful. But the only way that the person who has done this can still make his actions more or less ethical is by still revoking the key and by publicly stepping up and making a statement about this test. But by doing so, he would provide the evidence for his own fraud. I can not demand that from anyone. So I don't believe this incident can still be turned into an 'ethical test'. I really don't want to file a complaint against a fellow member of the open source community. Neither do I want to bring Jens Stomber, Teddy Hogeborn or the organisers of FOSDEM in the position of being witness of a crime. But at the same time I believe that 'it was unthoughtful' is not enough to not do so. I honestly don't know how to react on this. I am in a position right now, I don't want to be in. I also honestly hope there is an other resolution possible then filing a complaint. The best I can do now, is to give it some time and to think about it before taking action of any kind. with kind regards, Winfried Tilanus Coba Ritsemastraat 12 2642 CD Pijnacker The Netherlands +31.6.23303960
Hi, I have been asked to forward this explaination with some backgroundinformation to you:
Hi,
I'd be thankfull if you could forward my response to all (as web.de <http://web.de> won't let me send a mail to so many people).
Greetings
----.
Hi,
looking back I must say it may not have been the best idea to do this test. But at first I would like to inform you that the "fake" passport was a sample passport,which actually contained correct data.
About the passport: It was made by the same company which actually makes the official documents,there for most people which where only looking at the fancy security features failed here.
I would like to remind the people who verify the documents for PGP to actually check if the document makes any sense.Because besides the fact that it was marked "Specimen" (which means example) it had some more noticeable points like:- the number of the passport was KD000000- the countrycode was non existent- there was no country named on the Document- the name of the company which manufactured it was printed on it multiple times
Besides that (and yes I know with so many people there it is hard to do so),I would prefer that you check the documents if you don't know them andmaybe have a look at some of the basic security features of the documents like cacert does for example.
To the result of the test: From all people who where at the key signing sadly only 20 noticedthat it was a sample Passport, to those I then showed my correct passport.
Greetings
2016-02-01 20:44 GMT+01:00 Teddy Hogeborn <teddy@recompile.se <mailto:teddy@recompile.se>>:
First, please excuse me for this mass unsolicited mailing, but I believe that this will be of interest to you.
At the FOSDEM 2016 keysigning, or rather, right after the keysigning event, an unknown person approached me in the hallway and my associate and suggested that they pitied us, and, upon inquiry, admitted that it was due to us now having signed a fake key. When pressed for further details, he would only say that someone unknown to him had confessed to using a false passport, presumably in the keysigning. He would not divulge anything further.
Now, surely this person, i.e. the person with the fake passport who may or may not exist, is willing to come forward and share the results of their experiment? No doubt they will be announcing the details of their stunt, if only to make some point or other? (See also “Do not disrupt Wikipedia to illustrate a point”: <https://en.wikipedia.org/wiki/WP:POINT>)
In case they are not willing to immediately announce themselves, is anyone else able to shed further light or provide additional details?
/Teddy Hogeborn
-- The Mandos Project http://www.recompile.se/mandos
--
Mit freundlichen Grüßen
Jens Stomber
Schönbergstr. 23
85057 Ingolstadt
Germany
E-Mail: jens.stomber@gmx.de <mailto:jens.stomber@gmx.de>
Jabber: zombb@jabber.ccc.de <mailto:zombb@jabber.ccc.de>
Tel.: +49 (0)841 / 37 99 285
Mobil: +49 (0)151 / 54 82 82 37
Fax: +49 (0)3212 / 1178019
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCgAGBQJWr/xkAAoJEHZ7UH0X6LdcaUwP/2md6YFagzeRE5UFwaq/ujh1 vgxaMN53yP227a8mu/XgbaiKn8ngqTame8uGNfQy7734dYWgF+9Yvs2PJvfAiCXC ffIHl0umxc3qQFHJeCQWi7K9RgFPNEecQUhUZQTC7fp5TBApiojKa7XeEReETthD 5e/qp940qyArsp1WOWG6Y8BhJWy6X7E32dwNtts5ptgjX8KLxnLAws57kNUK3TOs lmhHAjlFOEk+0vvDgd7DFDabjiDS4gdoGRKnkQRs2qODJNm8tf8ejbAbIclP+4ZD n0ge15ODW5JO9h3+g8/2MbDMyHxW8S2Malq0DShYClXWFZ7w60dRbknSnP74pnCy 8yU0ZYh8Ijba7qjgwQil3pPozyDLsyTyvoV+LJonf8VT+Uf+gX4rlbDfqeRyJ9qS N46mv+0MVD/gX89AK6W2SG9LRIphmVsuevmvu+t7aV9VdJsyZa74t8Ukdh6JFvwd Ohtt9hYMxoZIfHuB/YmDJXTLLSA3WDZxzBinw18RIwoFoWtGLlW+JBkfIZ8lYlYm TO0jYP9pznDTQzygNkuLuZRnLluwfN2tleuEHIdsH4YeTR8/PpTsPUHxo5eaEHKg pE9Y6ml+A2z5NJUfR+W4zu3FjE6/RX/5maUfVnd47HO9ae053cUsYGOs+E7WytUt lv6KAqKPhJJxX0uZJojM =OKZq -----END PGP SIGNATURE-----
Dear Jens, Dear list, Now let's not go all legal-ballistic on this. 1. The "fake ID" didn't present a fake identification. It was just a fake document. It did not generate a fake personality. 2. There were plenty of safeguards... if there was SPECIMEN written all over it, I would call that a small clue. I don't think this would stand up in court. Now, let's approach this with a developer's mindset. What happened? The same thing that happens when peers review code: they review code with a certain "assumption" and expectaction of what code should do. You'll need a hacker to actually look into code and find "unintended usages" for it. If it's a white hat hacker, you're in luck. :) Between coders, it's frowned upon to go after someone exposing a vulnerability. Please don't do the same if someone pulls the same trick on you. I appreciate this happened. For 2 reasons: 1. It shows to me that the aspect "web of trust" can only happen with people we trust and know. Acting on it with people we only trust blindly and under time pressure (a line filing is quite some time pressure) is undermining the whole system. This is actually the main reason I don't do the keysigning party anymore. 2. When signing a key, you can also designate a level op trust. More focus should be set on this. I would "completely trust" those people I already know a long time and in person... I would take the lowest level of trust when signing a "documented stranger". Bottom line: it doesn't surprise me that a coder actually exposed this hack. I'm glad (s)he did this in an ethical way (using their real name, etc...) and came forward with it. (S)he didn't abuse the fake key e.g. to inject malicious code into some GIT repository. You have no idea how many people have done this trick on this or other events but shut up about it. We should take the hit in dignity and start looking on how to patch this. Grtz, Jurgen P.S. I didn't sign this mail intentionally. On 02-02-16 01:46, Winfried Tilanus wrote:
On 02/01/2016 11:27 PM, Jens Stomber wrote:
Hi,
First of all: I didn't notice the counterfeit passport and signed the key. I should have noticed. And this incident is a wake-up call to better check the presented ID's before accepting them.
Secondly, the knowledge about the fake passport brings me in a difficult situation. Let me explain that a bit.
Any attempt to undermine the web of trust, is a serious blow to both the open source and the security community. Though the motivation to present a fake passport may be noble, its consequences can be severe because it undermines an important tool for secure and authenticated communication. So only if there are enough safeguards such a 'wakeup call' can be done in a ethical way. I think about safeguards like: - revoking the offending key /before/ the keysigning event - announcing on forehand that, as part of a test, a fake passport may be presented - revealing all the details right after the key signing event
The person causing the incident at FOSDEM did not have any safeguards like these in place and seemed to have lacked any ethical or legal consideration before taking this action. From a legal point of view it is fraud to 'present a fake passport as if it is real'. At FOSDEM it was done under Belgian jurisdiction and that kind of fraud is punishable in Belgium with a jail sentence up to 10 years.
That brings me to my dilemma: Because of the consequences for the web of trust, I would normally file a complaint (for fraud) against anybody who presents me a fake id at a key signing party, except when this was part of a test with enough ethical (and legal) safeguards. It is clear that this action was not a case of malicious intent but mere a case of being unthoughtful. But the only way that the person who has done this can still make his actions more or less ethical is by still revoking the key and by publicly stepping up and making a statement about this test. But by doing so, he would provide the evidence for his own fraud. I can not demand that from anyone. So I don't believe this incident can still be turned into an 'ethical test'.
I really don't want to file a complaint against a fellow member of the open source community. Neither do I want to bring Jens Stomber, Teddy Hogeborn or the organisers of FOSDEM in the position of being witness of a crime. But at the same time I believe that 'it was unthoughtful' is not enough to not do so.
I honestly don't know how to react on this. I am in a position right now, I don't want to be in. I also honestly hope there is an other resolution possible then filing a complaint. The best I can do now, is to give it some time and to think about it before taking action of any kind.
with kind regards,
Winfried Tilanus Coba Ritsemastraat 12 2642 CD Pijnacker The Netherlands +31.6.23303960
Hi, I have been asked to forward this explaination with some backgroundinformation to you:
Hi,
I'd be thankfull if you could forward my response to all (as web.de <http://web.de> won't let me send a mail to so many people).
Greetings
----.
Hi,
looking back I must say it may not have been the best idea to do this test. But at first I would like to inform you that the "fake" passport was a sample passport,which actually contained correct data.
About the passport: It was made by the same company which actually makes the official documents,there for most people which where only looking at the fancy security features failed here.
I would like to remind the people who verify the documents for PGP to actually check if the document makes any sense.Because besides the fact that it was marked "Specimen" (which means example) it had some more noticeable points like:- the number of the passport was KD000000- the countrycode was non existent- there was no country named on the Document- the name of the company which manufactured it was printed on it multiple times
Besides that (and yes I know with so many people there it is hard to do so),I would prefer that you check the documents if you don't know them andmaybe have a look at some of the basic security features of the documents like cacert does for example.
To the result of the test: From all people who where at the key signing sadly only 20 noticedthat it was a sample Passport, to those I then showed my correct passport.
Greetings
2016-02-01 20:44 GMT+01:00 Teddy Hogeborn <teddy@recompile.se <mailto:teddy@recompile.se>>:
First, please excuse me for this mass unsolicited mailing, but I believe that this will be of interest to you.
At the FOSDEM 2016 keysigning, or rather, right after the keysigning event, an unknown person approached me in the hallway and my associate and suggested that they pitied us, and, upon inquiry, admitted that it was due to us now having signed a fake key. When pressed for further details, he would only say that someone unknown to him had confessed to using a false passport, presumably in the keysigning. He would not divulge anything further.
Now, surely this person, i.e. the person with the fake passport who may or may not exist, is willing to come forward and share the results of their experiment? No doubt they will be announcing the details of their stunt, if only to make some point or other? (See also “Do not disrupt Wikipedia to illustrate a point”: <https://en.wikipedia.org/wiki/WP:POINT>)
In case they are not willing to immediately announce themselves, is anyone else able to shed further light or provide additional details?
/Teddy Hogeborn
-- The Mandos Project http://www.recompile.se/mandos
--
Mit freundlichen Grüßen
Jens Stomber
Schönbergstr. 23
85057 Ingolstadt
Germany
E-Mail: jens.stomber@gmx.de <mailto:jens.stomber@gmx.de>
Jabber: zombb@jabber.ccc.de <mailto:zombb@jabber.ccc.de>
Tel.: +49 (0)841 / 37 99 285
Mobil: +49 (0)151 / 54 82 82 37
Fax: +49 (0)3212 / 1178019
_______________________________________________ FOSDEM mailing list FOSDEM@lists.fosdem.org https://lists.fosdem.org/listinfo/fosdem
A few observations on this: - at the end of a conference in the US a few years ago, I offered to sign somebody's key. They showed me a non-US passport that was only valid for a few more days and I asked them if many people had noticed this already and I was told that I was the first. It left me wondering how many people really check for expired documents. The probability that an expired document is lost or stolen is much higher, amongst other things, people often don't notice if their old expired passport is missing and fraudsters keep trying to use documents after they expire because they have no way to renew them legitimately. - don't blame the user, blame the training. Can more be done to train people, or is this very exercise the best training? - don't blame the user, blame the system. If people feel they are presented with a false document, does PGP provide any way to assert that? Or does it only provide for positive assertions of identity?
Daniel Pocock <daniel@pocock.pro> writes:
- don't blame the user, blame the training. Can more be done to train people, or is this very exercise the best training?
In the US, bartenders, bouncers, and restaurant servers have books full of samples of valid IDs from the different states. They have lights that show the special markings. They go to training. They still get fooled. I suggest people stop relying on ID. It makes the web of trust pretty meaningless. "trust" <> "I looked at what they told me was their ID once". -john -- John Sullivan | Executive Director, Free Software Foundation GPG Key: 61A0963B | http://status.fsf.org/johns | http://fsf.org/blogs/RSS Do you use free software? Donate to join the FSF and support freedom at <http://my.fsf.org/join>.
On 02/04/2016 08:38 PM, John Sullivan wrote:
I suggest people stop relying on ID. It makes the web of trust pretty meaningless. "trust" <> "I looked at what they told me was their ID once".
I'm not a huge fan of keysigning parties for this reason. I like setting aside time at an event to do this with people you actually know, but I am uncomfortable with signing someone's key that I have never interacted with previously. Best, jzb -- Joe Brockmeier | Community Team, OSAS jzb@redhat.com | http://community.redhat.com/ Twitter: @jzb | http://dissociatedpress.net/
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 On 02-02-16 06:30, Jurgen Gaeremyn wrote: Hi,
Now let's not go all legal-ballistic on this.
1. The "fake ID" didn't present a fake identification. It was just a fake document. It did not generate a fake personality.
2. There were plenty of safeguards... if there was SPECIMEN written all over it, I would call that a small clue. I don't think this would stand up in court.
I don't know the jurisprudence in Belgium, but for a Dutch court 'presenting a fake document as if it is real' is enough to convict. Beside that, I have only seen the fake ID, not the real ID. So I can't confirm anymore the identity of this person. (Whoever it is)
Now, let's approach this with a developer's mindset. What happened? The same thing that happens when peers review code: they review code with a certain "assumption" and expectaction of what code should do. You'll need a hacker to actually look into code and find "unintended usages" for it. If it's a white hat hacker, you're in luck. :)
Between coders, it's frowned upon to go after someone exposing a vulnerability. Please don't do the same if someone pulls the same trick on you.
I will never go after and ethical hacker, I even support them when I become aware of their activities. Been there, done that. But when a hacker shows to be unethical by going off-limit for example by reading confidential information or DOSsing a production system, I will file a complaint. Been there, done that.
I appreciate this happened. For 2 reasons: 1. It shows to me that the aspect "web of trust" can only happen with people we trust and know. Acting on it with people we only trust blindly and under time pressure (a line filing is quite some time pressure) is undermining the whole system. This is actually the main reason I don't do the keysigning party anymore.
Yes it certainly does show a weakness in the system. I would really appreciate full disclosure (including scans of the used documents) so I can learn from the incident and discuss with the community on how to deal with it.
2. When signing a key, you can also designate a level op trust. More focus should be set on this. I would "completely trust" those people I already know a long time and in person... I would take the lowest level of trust when signing a "documented stranger".
That would be a way of dealing with this vulnerability in this system.
Bottom line: it doesn't surprise me that a coder actually exposed this hack. I'm glad (s)he did this in an ethical way (using their real name, etc...) and came forward with it. (S)he didn't abuse the fake key e.g. to inject malicious code into some GIT repository. You have no idea how many people have done this trick on this or other events but shut up about it. We should take the hit in dignity and start looking on how to patch this.
The test causes harm, as long as the signatures from the KSP for the offending key are in the web of trust. Until it is clear the offending key is revoked, I consider this an unethical hack. Best wishes, Winfried Tilanus -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCgAGBQJWsM5CAAoJEHZ7UH0X6LdcTOUP/jKPPf0bVYdkkqOQ+Y6PB1vF VjSUxEBhS5FP28xjOEjKgbnuuHeqFo+Ug82lvoQ2WvtaISoa4bD6/Kmdt+L/kt2M ZE2lLC6i9nbBuRTbf2yaMhEH2TYEZWnTffMz7ffqdxy1mvjRierpKRN8jeAUBb+Y +KPBMLButm/VFES7ibyPd3Vyyy54E05qfXeuZWVn9t0IE7qvfUKRe9AA4AI+CY9n B0iPs8PNbPfWA6MqtWijz8UHjmzLWFAIEC4VS+isCJjXt75N/ApAtDRuLY5Pbp1X 2XvG57DmQBv8/EcOrZLMUd6eIWPI/tu6F5C1zvXY3jMTFbS7WHjy4Seb9TQsHQGh R447Mt1ttrb9Dpdr8K9ljwviezUUk0JocBrmlvfSlDpQegBIw9nA6BapfmnYzj5Z biFenTgvL9Sdv11Hhxl3Qho4zDaBF9Z7bbimDYzEuxeIi4tkvpn307IJ9PcjRsL9 G7WPmhi6RAHPu1ioxy07ishy/u/Hwp32YeLaSmLXTNaB8s2woUB+mpQcP0izqSXg M+x3VlOYRWSxXNUd9dwF33mtj5dbkfpSXDWkS0KeQz+hoic6CwqgZC6Gzi314uia pT7YIeLU162ngIlgebMloYFge7mM2ULb6bjK6/hGZ+ni+B1lWQqtgSF+2akUDNAt ZkaSDKaXFOyvOgfORwhQ =5D+n -----END PGP SIGNATURE-----
Le 02/02/2016 16:41, Winfried Tilanus a écrit :
I don't know the jurisprudence in Belgium, but for a Dutch court 'presenting a fake document as if it is real' is enough to convict.
Did he present it as if it was real ? AFAIK. Was that a fake official document ? No. AFAIK it wasn't written passport, using its colors. Only layout and text was similar, but with safeguards. (also see last paragraph)
Beside that, I have only seen the fake ID, not the real ID. So I can't confirm anymore the identity of this person. (Whoever it is)
I agree this is a problem, but in that case, you can now only rely on trust chain and spotters to guarantee it was the same (which doesn't makes any difference as you won't sign it now).
Yes it certainly does show a weakness in the system. I would really appreciate full disclosure (including scans of the used documents) so I can learn from the incident and discuss with the community on how to deal with it.
Learning from his address that he belongs to CaCert, you should head for their stand at next fosdem and do the ID verification tests. They'll probably show up. (caution, pls do not incriminate cacert for the key-signing stuff)
The test causes harm, as long as the signatures from the KSP for the offending key are in the web of trust. Until it is clear the offending key is revoked, I consider this an unethical hack.
Seems ok to me. He didn't try to acquire any benefits fraudulently and even explained when spotted. I would also quote FOSDEM's keysigning instructions: " Please bring the printed list, a pen and appropriate form of identification with you to FOSDEM 2016" I can try to find any violation, i can't. He had a list, a pen and a form of identification. "After the participants have verified each other's identity, (...)" Again, nothing here says that the form of ID must be official, issued by a state. Francois
As some organisations allow penetration testing to see if their security is in order, something similar could be set up for the key signing, *with* prior knowledge of the FOSDEM organisation and an infrastructure in place to revoke it at the end of the key signing. So, for example, one person and only one person, in collaboration with the organisation, is in there with a fake ID, ID from some else or incorrect key or whatever. He or she is there in order to validate that the process works correctly. An ID with SPECIMEN written all over it is in my view not presenting a fake document as real, as it is stating that it is a specimen. When someone does not notice it, then it is about the intention and the damage done. The intention is to improve the process and the damage done is zero. So this will, in my layman's view, not something you will get a conviction over, but you can waste time and money with it. On 02/02/2016 04:41 PM, Winfried Tilanus wrote:
On 02-02-16 06:30, Jurgen Gaeremyn wrote:
Hi,
Now let's not go all legal-ballistic on this.
1. The "fake ID" didn't present a fake identification. It was just a fake document. It did not generate a fake personality.
2. There were plenty of safeguards... if there was SPECIMEN written all over it, I would call that a small clue. I don't think this would stand up in court.
I don't know the jurisprudence in Belgium, but for a Dutch court 'presenting a fake document as if it is real' is enough to convict.
Beside that, I have only seen the fake ID, not the real ID. So I can't confirm anymore the identity of this person. (Whoever it is)
Now, let's approach this with a developer's mindset. What happened? The same thing that happens when peers review code: they review code with a certain "assumption" and expectaction of what code should do. You'll need a hacker to actually look into code and find "unintended usages" for it. If it's a white hat hacker, you're in luck. :)
Between coders, it's frowned upon to go after someone exposing a vulnerability. Please don't do the same if someone pulls the same trick on you.
I will never go after and ethical hacker, I even support them when I become aware of their activities. Been there, done that. But when a hacker shows to be unethical by going off-limit for example by reading confidential information or DOSsing a production system, I will file a complaint. Been there, done that.
I appreciate this happened. For 2 reasons: 1. It shows to me that the aspect "web of trust" can only happen with people we trust and know. Acting on it with people we only trust blindly and under time pressure (a line filing is quite some time pressure) is undermining the whole system. This is actually the main reason I don't do the keysigning party anymore.
Yes it certainly does show a weakness in the system. I would really appreciate full disclosure (including scans of the used documents) so I can learn from the incident and discuss with the community on how to deal with it.
2. When signing a key, you can also designate a level op trust. More focus should be set on this. I would "completely trust" those people I already know a long time and in person... I would take the lowest level of trust when signing a "documented stranger".
That would be a way of dealing with this vulnerability in this system.
Bottom line: it doesn't surprise me that a coder actually exposed this hack. I'm glad (s)he did this in an ethical way (using their real name, etc...) and came forward with it. (S)he didn't abuse the fake key e.g. to inject malicious code into some GIT repository. You have no idea how many people have done this trick on this or other events but shut up about it. We should take the hit in dignity and start looking on how to patch this.
The test causes harm, as long as the signatures from the KSP for the offending key are in the web of trust. Until it is clear the offending key is revoked, I consider this an unethical hack.
Best wishes,
Winfried Tilanus
_______________________________________________ FOSDEM mailing list FOSDEM@lists.fosdem.org https://lists.fosdem.org/listinfo/fosdem
participants (7)
-
Daniel Pocock -
Francois Cartegnie -
Joe Brockmeier -
John Sullivan -
Jurgen Gaeremyn -
Pander -
Winfried Tilanus