[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Sks-devel] Implications of GDPR
From: |
dirk astrath |
Subject: |
Re: [Sks-devel] Implications of GDPR |
Date: |
Fri, 4 May 2018 08:44:31 +0000 |
User-agent: |
Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.7.0 |
Hi,
It may make sense to keep a revoked key in our database:
How is your decision, if a key can't be found on a keyserver?
Trust on first use? Don't trust?
If my key gets compromised, I want to tell the community: DO NOT trust
this key ... so I revoke it.
Therefore:
If revoked (or expired) keys are removed from keyservers, I'm unable to
tell this anymore.
Another issue are the "fake" keys or keys, which have been uploaded a
looooong time ago.
Even if you're the owner (or former owner) of the
username/mailadress-combination you're unable to revoke the key or add
any (trusted) signature to this key so it will get removed (or unlisted).
So these key can't get removed from the database.
Well ... using any fake email-adress i would be able to write "somebody"
"please remove my key from keyserver", but ... how am I able to proof
that I'm the one who is allowed to get this key removed?
And ... even if I have to answer to a "ping"-mail: If the domain doesn't
exist anymore (or belongs to somebody else) I will not be able to answer
and therefore confirm the deletion.
All in all:
It's not easy to find a perfect solution (if there is any) ... and it's
not the first time we have this discussion ...
... the first time I remember it was after the talk on OHM 2013
"Trolling the Openpgp-Web-of-trust" ... unfortunately nothing changed
since then ... ;-(
Kind regards,
dirk
signature.asc
Description: OpenPGP digital signature
- Re: [Sks-devel] Implications of GDPR, Mike O'Connor, 2018/05/03
- Re: [Sks-devel] Implications of GDPR, Gabor Kiss, 2018/05/03
- Re: [Sks-devel] Implications of GDPR, Ari Trachtenberg, 2018/05/03
- Re: [Sks-devel] Implications of GDPR, Moritz Wirth, 2018/05/03
- Re: [Sks-devel] Implications of GDPR, Kiss Gabor (Bitman), 2018/05/03
- Re: [Sks-devel] Implications of GDPR, Andrew Gallagher, 2018/05/03
- Re: [Sks-devel] Implications of GDPR, Fabian A. Santiago, 2018/05/03
- Re: [Sks-devel] Implications of GDPR, brent s., 2018/05/03
- Re: [Sks-devel] Implications of GDPR, Daniel Roesler, 2018/05/03
- Re: [Sks-devel] Implications of GDPR,
dirk astrath <=
- Re: [Sks-devel] Implications of GDPR, Arnold, 2018/05/04
- Re: [Sks-devel] Implications of GDPR, Andrew Gallagher, 2018/05/04