Wednesday, 2022-06-15

fungigagehugo_: prometheanfire: heads up, i've sent you both encrypted e-mail just now. hopefully it arrives intact14:26
prometheanfireyep, got it, I'll update my key too14:52
fungithanks!14:55
prometheanfireI used to use sks-keyservers, what are people using now?15:02
fungikeyserver hkps://keys.openpgp.org15:03
fungithat's what i switched everything i'm managing over to after the sks network collapsed15:03
prometheanfireya, that's what I just switched to, cool then15:03
prometheanfireI do wonder what happened there, it's like he dropped off the face of the earth15:04
fungithere were multiple pressures15:04
fungifirst, the traditional design of allowing anyone to upload signatures for other people's keys was able to be abused in a number of ways, from attaching corrupt signatures, to flooding keys with so many bogus sigs that they couldn't be retrieved, to attaching signatures containing offensive words/phrases15:05
prometheanfireya, I know bots were using it for messaging15:06
fungibut then gdpr came, and sks was hit with a barrage of takedown demands for people's data, including attackers uploading things just so they could file takedowns15:06
fungiultimately it was unworkable to continue running the service15:07
fungiyou'll notice keys.openpgp.org doesn't allow uploading signatures at all15:07
fungior rather, it strips them when storing15:08
fungialso forces you to validate your key by e-mail before that id can even be searched by anything other than the raw hex number15:08
fungilonger term, there's this: https://datatracker.ietf.org/doc/html/draft-dkg-openpgp-abuse-resistant-keystore-0015:08
prometheanfireah, ya15:08
opendevreviewMatthew Thode proposed openstack/ossa master: update Matthew Thode's gpg key  https://review.opendev.org/c/openstack/ossa/+/84600715:11
prometheanfireUIDs may need updating, left a comment in review15:12

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!