Re: kernel.org status: establishing a PGP web of trust

From: Mark Brown
Date: Thu Oct 06 2011 - 13:52:22 EST


On Thu, Oct 06, 2011 at 07:45:45PM +0200, Krzysztof Halasa wrote:
> Mark Brown <broonie@xxxxxxxxxxxxxxxxxxxxxxxxxxx> writes:

> > A common approach to this for at least the e-mail portion of the address
> > is to sign the ID with the address and then mail the signed key
> > encrypted to the address, deleting all local copies and requiring that
> > the recipient publish the signature. This at least demonstrates that
> > the owner of the key can read mail at that address.

> The assumption here is the attacker can read (and write) victim's email.
> It's not about verifying email access or address.

Bear in mind that this is only done after a successful out of band
verification - it's purely about verifying the e-mail portion of the
identity which the person has already asserted that they control.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/