Conversation

Uwe Kleine-König

Edited 24 days ago
The PGP Web of Trust in the kernel and SHA-1

PGP is used to sign and (hopefully) also verify pull requests. For a big and relevant part of our community the certifications and cross signatures that are the computational base for the trust in the transferred code changes are already long established.

The problem here is that security is a moving target and the algorithms used back then are not considered secure any more. For example GnuPG (and also other OpenPGP implementations) don’t consider SHA-1 secure any more. See my blog for some effects of that on the kernel Web of Trust.

1
10
7

Uwe Kleine-König

Edited 23 days ago

If you’re attending @embeddedrecipes this year in Nice (May 14-16), register for the PGP keysigning session with @a3f by sending your public key to er2025-keysigning@baylibre.com.

1
2
3

Uwe Kleine-König

Edited 19 days ago

The @embeddedrecipes keysigning will be done using the Zimmermann–Sassaman key-signing protocol and the deadline for handing in your certificates to make it on the list is over. If you still want to attend, please bring paper slips with your fingerprint (and of course your passport and a pen). No need to register for that.

0
1
1