User: Password:
Subscribe / Log in / New account

Verification of Debian Developer identity

Verification of Debian Developer identity

Posted Jul 16, 2010 9:41 UTC (Fri) by tialaramex (subscriber, #21167)
In reply to: Verification of Debian Developer identity by jrn
Parent article: Debian declassification delayed

That requirement makes it impossible to be an _anonymous_ Debian Developer, but not to be a _pseudonymous_ one which is why I chose the wording I did.

The requirement (the one other Debian Developers can see being enforced) is just that each member has an OpenPGP key with at least one identity signed by another Debian Developer.

Perhaps if Debian was created today, it would be required that the signed identity be a photographic image of the face (the necessary PGP features did not exist when Debian was created). A poor identifier, but one that's fairly verifiable. In reality, as I understand it, the main identifier for Debian Developers is an email address, since that's how most discussion is undertaken. Usually the address is associated with a name, and someone might ("by convention") check that the name vaguely matches one shown on some official looking photo ID (e.g. they'd sign "Bill Thomson" based on photo ID in the name "William Thompson"). That's just not a high enough barrier to use words like "impossible".

Fake identity documents are commonplace, particularly in jurisdictions where they are abused as licenses (e.g. to permit purchasing alcoholic beverages, tobacco, pharmaceuticals or firearms). Debian isn't an organisation of highly trained forensic experts, but of Free Software hackers. So we cannot expect miracles of detective work.

As to my tone, as usual there's no hidden agenda here, I'd scoff just as much if someone told me Microsoft's Windows division could keep secrets for five years. Only small groups, on whom secrecy of a particular matter is impressed as utterly critical, can be expected to keep secrets for more than a short while. Ultra is an example often cited - few people had routine access to Ultra, though more knew of its existence at least tangentially. Ultra was kept secret for the remaining duration of the war and perhaps 10 years or so beyond, but by the 1970s people were writing about it in memoirs of the war. Those told about Ultra were mostly military personnel, and it was clear lives were at stake. I'm not pretending the DDs are all gossips, straight over to a neighbour to tell them the latest, but only that it would be quite extraordinary to think of a secret that mustn't be public in five years time, but can be told to 1000 of these essentially random people from around the world.

(and moreover, told to them via unsecured SMTP email...)

(Log in to post comments)

Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds