Shouldn't there be a better way to handle departures?
Shouldn't there be a better way to handle departures?
Posted Aug 9, 2025 14:19 UTC (Sat) by KJ7RRV (subscriber, #153595)Parent article: Some turbulence at CalyxOS
      Posted Aug 9, 2025 18:14 UTC (Sat)
                               by rra (subscriber, #99804)
                              [Link] 
       
We all knows this, and we do a lot of this, but hard drives only fail occasionally and if you're anything like me you find double-checking your backup process to be one of the most tedious and mind-numbing chores you can possibly imagine. So when the day comes and the hard drive really does die, often you discover, quite unhappily, that your backups were not in as good of shape as you thought. 
Signing keys are like that except way worse. The rules about how to handle them are not as well-developed and automated as backups are, fewer people have that problem so there aren't as mature of tools, and you rarely have a problem so you have to go out of your way to simulate failure in a way that really tests your procedures (and it's very easy to think that you have done this when you haven't). On top of that, thinking about departures in small, close-knit groups can be a bit like thinking about a relative dying. It shouldn't be, and everyone knows that, and yet. It requires thinking about uncomfortable topics like "what if we all end up hating each other, how is this going to work" and working them out in detail and making and testing procedures and this is all emotionally fraught and taxing and it's very easy to put it off. 
     
      Posted Aug 10, 2025 1:48 UTC (Sun)
                               by skissane (subscriber, #38675)
                              [Link] 
       
Which suggests to me that there is more to this story than they are saying publicly. 
Of course, ideally it would be stored in a HSM with secret sharing, so even if they retained their share, absent access to the HSM it would be useless, and then you could invalidate their existing share so it wouldn’t work even if they somehow gained HSM access 
But, so long as trust remains intact, you possibly can tolerate the security risks the less than ideal situation entails-once trust is destroyed, you can’t. 
     
      Posted Aug 12, 2025 12:19 UTC (Tue)
                               by iabervon (subscriber, #722)
                              [Link] 
       
     
    Shouldn't there be a better way to handle departures?
      
Shouldn't there be a better way to handle departures?
      
Shouldn't there be a better way to handle departures?
      
 
           