Re: kernel.org status: establishing a PGP web of trust

From: Chris Friesen
Date: Wed Oct 05 2011 - 20:19:37 EST


On 10/05/2011 05:57 PM, Thomas Gleixner wrote:
On Wed, 5 Oct 2011, Adrian Bunk wrote:

Or if I have to bother Linus to meet me and sign my key the next
time he is here in Helsinki.

And how would that change the fact that your personal trust value in
this community is exactly ZERO?

As your idea of trust seems to be based on an ID card you better find
some other place with people who are stupid enough to believe that
technical measures can replace deep personal trust.

Aren't you sort of conflating personal trust with a web-of-trust?

A web-of-trust exists simply to associate a person with a key. It *is* a technical measure. If Linus is willing to assert that Adrian's key matches up with Adrian-as-individual, and you trust Linus, then you should accept Adrian's key as valid regardless of whether or not you personally trust him.

Chris



--
Chris Friesen
Software Developer
GENBAND
chris.friesen@xxxxxxxxxxx
www.genband.com
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/