[00:03.980 --> 00:04.860] I'm sorry. [00:09.520 --> 00:10.380] Welcome, everyone. [00:11.280 --> 00:13.480] It is Saturday, twenty-hundred hours. [00:13.680 --> 00:20.000] Area B, that means it's time for Breaking Down the Web of Trust, presented to you by number 125, Seth Hardy. [00:20.240 --> 00:20.580] That's me. [00:27.030 --> 00:29.150] I still see a lot of activity outside. [00:29.350 --> 00:30.650] Are people still filtering in? [00:30.650 --> 00:32.530] Or should I just get going? [00:34.950 --> 00:35.450] Welcome. [00:35.770 --> 00:36.130] Welcome. [00:36.430 --> 00:36.930] Welcome. [00:37.250 --> 00:37.810] Okay, then. [00:38.430 --> 00:38.930] Woo! [00:39.670 --> 00:40.170] Alright. [00:40.610 --> 00:41.570] So, my name is Seth. [00:41.870 --> 00:43.850] Title of the talk, Breaking Down the Love of Trust. [00:46.170 --> 00:48.610] Before we begin, I just want to ask a question. [00:49.170 --> 00:53.090] Well, who here uses PGP in some variant? [00:53.490 --> 00:54.590] Who here has a key pair? [00:54.810 --> 00:55.570] Okay, cool. [00:56.290 --> 00:59.410] So, does anybody here not know what it is? [00:59.410 --> 01:02.230] Does anybody here not know anything about PGP? [01:03.490 --> 01:04.010] Okay. [01:05.370 --> 01:07.470] Hopefully, you'll pick up what this is about, then. [01:07.750 --> 01:13.830] But it's an encryption program, and it's well used all over the world. [01:13.970 --> 01:17.330] It's considered the standard for doing strong encryption. [01:17.910 --> 01:20.190] So, I'm going to be talking about it. [01:20.330 --> 01:21.190] So, hopefully, you'll pick this up. [01:21.750 --> 01:35.070] But for those of you who are PGP, and I use that in the general sense, not the PGP Corporation sense, who would sign this key, right here, given that information? [01:35.690 --> 01:38.410] Would anybody here sign this key? [01:38.690 --> 01:39.170] Can I... [01:39.170 --> 01:39.290] Just that? [01:39.490 --> 01:39.930] Huh? [01:40.150 --> 01:40.690] Just that? [01:41.760 --> 01:45.170] Assuming that somebody gave it to you and verified the fingerprint. [01:45.710 --> 01:47.790] Would anybody here sign this key? [01:48.170 --> 01:49.590] Can I see a show of hands? [01:50.650 --> 01:51.130] No. [01:51.470 --> 01:52.450] Not a single person. [01:52.450 --> 01:52.470] Not a single person. [01:52.550 --> 01:52.770] Oh, wait. [01:53.050 --> 01:53.470] Max would. [01:53.730 --> 01:53.850] Okay. [01:54.110 --> 01:56.250] So, nobody here would sign that key. [01:56.550 --> 01:56.870] No. [01:57.170 --> 01:59.770] Would anybody here actively refuse to sign that key? [02:01.490 --> 02:01.670] Yes. [02:02.210 --> 02:02.690] Okay. [02:02.870 --> 02:07.390] So, a few people, and most of you are just not wanting to commit to a stand. [02:07.470 --> 02:08.610] You're responding to your leading question. [02:08.790 --> 02:09.010] Yes. [02:09.330 --> 02:12.090] You guys don't want to respond to my leading question. [02:12.590 --> 02:17.310] Well, what would you need to know before you signed a key like this to all those people that wouldn't sign it? [02:17.670 --> 02:17.910] Anybody? [02:18.250 --> 02:18.450] Yeah. [02:18.610 --> 02:19.570] I just wouldn't sign it. [02:19.830 --> 02:20.070] Okay. [02:20.170 --> 02:21.350] So, you just wouldn't sign it. [02:22.730 --> 02:25.950] Proof that the email is whoever the email is. [02:26.190 --> 02:26.490] Okay. [02:26.670 --> 02:29.830] Proof that the email goes to the person holding the key? [02:29.990 --> 02:30.550] Some ID. [02:31.030 --> 02:31.710] Some ID. [02:33.070 --> 02:44.950] Proof that the person who gave me that key actually just gave me a copy of that key, which would, of course, align with what it would actually be. [02:45.910 --> 02:50.090] I could use a key server or some other key server. [02:50.190 --> 02:50.290] Okay. [02:50.370 --> 02:52.730] So, you would just care about the fingerprint and nothing else? [02:52.930 --> 02:54.110] You would still sign it? [02:58.210 --> 02:58.650] Okay. [02:58.770 --> 02:59.810] Depending on if you knew the person. [03:00.910 --> 03:03.090] Anybody else want to offer a standpoint? [03:04.070 --> 03:04.990] Proof of ownership. [03:05.230 --> 03:05.910] Proof of ownership. [03:06.170 --> 03:07.290] How do you prove ownership? [03:08.230 --> 03:09.030] Proof of ID. [03:09.310 --> 03:09.530] Okay. [03:09.650 --> 03:10.030] Proof of... [03:10.030 --> 03:10.970] What about the ID? [03:10.970 --> 03:11.650] Sign a message. [03:12.190 --> 03:14.310] Is it your real name or your driver's license? [03:14.610 --> 03:14.990] Okay. [03:15.690 --> 03:16.870] Well, everybody else... [03:16.870 --> 03:20.510] If I got a key server, I would totally sign that. [03:20.790 --> 03:21.050] Okay. [03:21.630 --> 03:25.310] Well, think about this question as I give the talk. [03:25.730 --> 03:27.990] And I will come back to this sometime at the end. [03:29.210 --> 03:29.670] Yeah. [03:31.150 --> 03:34.590] Is this person going to have a driver's license that says ultra laser on? [03:35.950 --> 03:37.410] That's a very good question. [03:37.410 --> 03:37.430] That's a very good question. [03:38.710 --> 03:43.550] It would require the first person to demonstrate that he has the private key belonging to the public key. [03:43.910 --> 03:44.230] Okay. [03:44.850 --> 03:44.930] Okay. [03:45.110 --> 03:47.730] Had I had like three drinks before the key signing? [03:48.010 --> 03:48.150] Yep. [03:49.250 --> 03:49.590] Okay. [03:49.710 --> 03:51.710] If you're drinking before the key signing, you would sign this key. [03:51.930 --> 03:55.050] So, keep this in mind as I go through. [03:55.050 --> 04:01.550] The very first thing I'm going to do is a short, short version of what the web of trust is. [04:01.710 --> 04:06.510] Just to give everybody a general context of what it is I'm talking about here. [04:07.630 --> 04:10.150] And the first question is, why a web of trust? [04:10.150 --> 04:14.810] And the whole point is to trust the validity of keys you've never seen before. [04:15.170 --> 04:17.090] So, that's me up on top there. [04:17.750 --> 04:20.110] And the three keys underneath are keys that I've signed. [04:20.490 --> 04:23.550] And the third row is somebody I know has signed a key. [04:23.710 --> 04:27.630] And the fourth row is somebody that they know he's signed their key. [04:28.110 --> 04:43.170] And the whole point of this exercise is that despite the fact that the person on the bottom is a number of steps away, I can still, using this web of trust, trust the key at the bottom that is three steps away from me, and everything will be fine. [04:43.550 --> 04:46.890] And this sort of thing is in use all the time in real-world scenarios. [04:46.890 --> 04:48.630] I'll show you some examples of that. [04:49.450 --> 04:56.130] It's just taking a well-known social phenomenon and translating it over into the world of computer security. [04:56.910 --> 04:58.190] So, what, social networks? [04:58.750 --> 05:00.310] Like integrating social networking? [05:00.530 --> 05:00.730] Yes. [05:01.370 --> 05:04.750] It is using social networking like, I know you and I trust you. [05:05.010 --> 05:07.090] And you know that guy and you trust that guy. [05:07.270 --> 05:10.870] And if I trust your judgment, then I can trust the friend of a friend. [05:10.990 --> 05:11.670] Trusted introductions. [05:12.270 --> 05:13.390] It's like trusting a rattlesnake. [05:13.730 --> 05:14.370] Trusting a what? [05:14.570 --> 05:15.850] It's like trusting a rattlesnake. [05:15.990 --> 05:17.770] It may be tame, but it can still f*cking kill you. [05:18.470 --> 05:19.630] Depends on who the person is. [05:20.790 --> 05:22.750] So, here's an example web of trust. [05:23.230 --> 05:26.390] And I just pulled this image down off the net, so I don't know whose it is. [05:26.790 --> 05:30.710] But here is an example of all of the cross signatures between... [05:30.710 --> 05:31.250] Between keys. [05:31.570 --> 05:32.250] Yeah, that's me. [05:34.090 --> 05:34.910] Actually, no. [05:35.050 --> 05:35.890] It's the other fizz. [05:36.150 --> 05:37.030] Believe it or not. [05:37.590 --> 05:38.070] Oh, the chick? [05:38.450 --> 05:38.650] Yeah. [05:38.870 --> 05:39.510] Oh, f*ck that. [05:41.890 --> 05:45.410] So, this is a graphical representation of what the web of trust looks like. [05:46.470 --> 05:47.590] And it's just... [05:47.590 --> 05:49.170] It goes in multiple directions. [05:49.750 --> 05:53.890] And I'm sure you are all familiar with this concept if you have friends. [05:54.370 --> 06:01.010] I'm not sure that everybody here has friends, but if you have friends, or even probably if you don't have friends, you're familiar with this. [06:01.090 --> 06:02.970] It's just whether you're bitter about it or not. [06:03.990 --> 06:05.930] So, I'm sure everybody is familiar with this. [06:06.070 --> 06:08.930] If anybody has any questions, just stop me at any time. [06:09.050 --> 06:10.090] Just, like, wave your arm. [06:10.270 --> 06:11.550] Shout, hey, you guy up there. [06:11.670 --> 06:12.310] I have a question. [06:13.030 --> 06:17.770] I'm gonna go quickly through this introductory part, and just to get it out of the way. [06:19.130 --> 06:23.390] So, the thing about the web of trust is it's really more like a web of validation. [06:23.990 --> 06:29.310] By signing a key, you're supposed to sign a key only when you know that the key is completely valid. [06:29.770 --> 06:35.510] So, if I trust somebody, but I don't trust that the key is actually theirs, I won't sign the key. [06:35.790 --> 06:38.550] And the reason for this is quite simple. [06:38.550 --> 06:42.630] It's, you're not handling identities and verifying identities here. [06:42.750 --> 06:43.690] You're verifying keys. [06:44.070 --> 06:54.230] And the purpose of this is to send secure email or just encrypt files in some way or another that somebody else will be the only person who is able to read it. [06:55.250 --> 06:59.170] So, when you sign a key, you don't sign a key until you know that it's completely valid. [06:59.570 --> 07:05.770] No matter how much you trust the person, if, you know, somebody else walks up to you with a key with their name on it, you're not gonna trust the key. [07:05.770 --> 07:07.990] So, it's a two-part thing. [07:09.190 --> 07:13.550] The other thing that you're doing in terms of trust is you're setting a trust level for introductions. [07:14.050 --> 07:19.190] So, there's a notion of assigned trust versus the notion of calculated trust. [07:19.650 --> 07:24.130] Assigned trust are the decisions that I make about the people around me. [07:24.450 --> 07:29.190] I might trust Alice, trust Bob, but not trust Charlie at all. [07:29.190 --> 07:31.530] So, those are the assignments. [07:31.870 --> 07:34.510] I'm making a first level declaration. [07:34.790 --> 07:35.970] This is who I trust. [07:36.110 --> 07:37.090] This is who I don't trust. [07:37.710 --> 07:39.750] After that, it's calculated trust. [07:40.030 --> 07:43.290] So, I can trust somebody, but not trust their judgment. [07:43.730 --> 07:48.630] So, a second level person, their trust has to be calculated by way of the first person that I know. [07:49.030 --> 07:50.710] And I'll get more into this in a little bit. [07:51.470 --> 07:54.270] So, keys that you sign are really validated. [07:55.430 --> 08:01.090] Trust is implied in this, but you're going one step further, and you're validating the key as well. [08:01.630 --> 08:04.850] Validation of a key implies trust, not the other way around. [08:05.590 --> 08:09.210] Unsigned keys or keys that are not signed by you are trusted. [08:09.430 --> 08:11.670] So, you can say, I've never seen this key before. [08:11.830 --> 08:13.250] It does not have my signature on it. [08:13.290 --> 08:16.410] I have not personally verified it, but I still trust it. [08:16.410 --> 08:22.650] I still believe based on the introducer, whoever introduced me to this key, I trust this key. [08:22.870 --> 08:24.970] So, that is validation versus trust. [08:25.350 --> 08:34.410] And the way you do this, a lot of times people miss out on this extremely critical part when using PGP, is you have to update your trust DB. [08:34.770 --> 08:37.030] And in GPG, this is the command to do it. [08:37.110 --> 08:41.270] There are other similar commands in GPG or PGP and other programs. [08:41.270 --> 08:50.770] But unless you assign trust values for introductions to all of your keys, you will never get beyond one step in this trust network. [08:51.210 --> 08:59.630] So, you will have all of the keys that you've signed that you trust, but unless you say how much you trust their judgment, you'll never have anybody else in your network. [08:59.830 --> 09:06.990] And this is an example of using GPG to set the trust level on somebody's key. [09:06.990 --> 09:10.210] You don't say, I believe this key is valid or not. [09:10.410 --> 09:11.870] That's implied when you sign it. [09:12.090 --> 09:17.290] What you're doing is you say, how much do you trust this user to correctly verify other users' keys? [09:17.650 --> 09:26.030] And the examples they give are by looking at passports, checking fingerprints from different sources, just the way that other people handle introductions. [09:27.510 --> 09:29.850] So, you know, it's, I don't know, I won't say. [09:30.070 --> 09:31.030] I don't trust them. [09:31.210 --> 09:32.470] I trust them marginally. [09:32.550 --> 09:33.330] I trust them fully. [09:34.150 --> 09:40.630] This is sort of like the distinction, like, oh yeah, my best friend Susie, she's an awesome person. [09:40.830 --> 09:41.250] Yeah. [09:41.370 --> 09:41.690] Drink. [09:41.890 --> 09:42.210] Drink. [09:42.930 --> 09:47.530] My best friend Susie, she's an awesome person, but she always dates assholes. [09:47.930 --> 09:53.890] You're saying that she's your best friend and you trust her with anything, but you don't trust her judgment with other people. [09:54.070 --> 09:55.750] And that is what you are doing here. [09:55.890 --> 10:01.710] You are setting a trust level on how well that they deal with other people, not with you. [10:05.090 --> 10:07.610] And some people might find this one kind of funny. [10:08.110 --> 10:10.390] Here's an example of validity versus trust. [10:11.330 --> 10:14.410] I don't know who knows that person on there. [10:16.610 --> 10:20.450] But this is a person where I know that this key belongs to him. [10:21.830 --> 10:26.690] I am absolutely 100% positive that this key belongs to him. [10:27.390 --> 10:31.910] And I am also 100% positive that any signature he makes on another key is worthless. [10:33.290 --> 10:34.930] It's not because he's a bad guy. [10:35.190 --> 10:36.690] It's not because I don't like him. [10:36.750 --> 10:37.630] He's one of my friends. [10:37.650 --> 10:38.550] He's a cool person. [10:38.730 --> 10:39.930] I think he's alright. [10:40.170 --> 10:41.110] He lives under a bridge. [10:42.230 --> 10:43.910] But he does live under a bridge. [10:44.370 --> 10:50.110] And as a result, his interactions with other people aren't really trustworthy. [10:51.190 --> 10:54.270] So, I trust his key, but I do not trust his judgment. [10:54.810 --> 10:58.470] I'm sorry if this is a stupid question, but is this information broadcast somewhere? [10:58.710 --> 11:00.410] Like when you say you trust somebody... [11:00.410 --> 11:02.650] The trust database is kept private. [11:02.650 --> 11:04.610] It is for your eyes only. [11:04.930 --> 11:11.730] Your signatures on other keys asserting that the key is valid and the user ID is valid are public. [11:12.010 --> 11:15.350] But whether you trust somebody else's judgment is private. [11:15.870 --> 11:19.310] So, if you say, I don't trust this guy, that person will never know. [11:19.470 --> 11:21.150] It is for your reference only. [11:21.350 --> 11:24.510] But there's a system of broadcasting that you validate the key... [11:24.510 --> 11:24.690] Yes. [11:25.050 --> 11:29.670] When you validate somebody's key, you put a signature on it, and it becomes a permanent part of their key. [11:29.890 --> 11:30.730] Key servers. [11:31.250 --> 11:31.650] Yeah. [11:31.790 --> 11:38.730] You upload it to a key server, and then anybody else can get it, and they can see that you've validated the information, but they don't know how you trust their judgment. [11:39.330 --> 11:43.890] The trusting of judgment is for your personal trust calculations only. [11:43.990 --> 11:45.570] It doesn't affect anybody else's. [11:45.930 --> 11:52.450] So, if you have signed that guy's key, and you trust him completely, I don't know him. [11:52.510 --> 11:54.310] So, I don't know if he's going to try to screw me. [11:54.510 --> 11:56.030] You guys might be best friends. [11:56.150 --> 11:58.430] He'd never screw you, but he might screw me. [11:58.430 --> 12:01.210] So, I'm not going to trust him, but you can. [12:01.430 --> 12:04.390] So, the trust judgments are for you and you alone. [12:06.390 --> 12:08.950] What's the usage CS and usage A being? [12:10.970 --> 12:12.750] That is just what the key can be used for. [12:12.890 --> 12:15.350] It's not really applicable to this discussion. [12:15.350 --> 12:16.770] I can explain it later if you'd like. [12:18.890 --> 12:20.770] So, that is the Web of Trust. [12:21.050 --> 12:24.690] Does anybody have any questions on the Web of Trust before I move on? [12:25.430 --> 12:25.830] Yes? [12:26.030 --> 12:27.230] It's a stupid question. [12:27.330 --> 12:27.650] It's okay. [12:27.830 --> 12:32.030] Why is the use of, like, servers that show some trust to store this information? [12:32.030 --> 12:32.250] Yes. [12:32.690 --> 12:37.910] There are public key servers, and you can upload your key to a key server so that anybody can get it. [12:38.390 --> 12:44.370] And the point of the Web of Trust is that, so, you don't need to personally hand your key to somebody else. [12:44.370 --> 12:48.630] Somebody else can sign your key and then upload it to the key server. [12:49.470 --> 12:59.670] And because a digital signature requires their private key, if you see the digital signature on it, even if they didn't get it from you directly, they know they can still trust it because the signature is good. [13:02.660 --> 13:03.100] Okay? [13:03.320 --> 13:05.040] Well, I guess I will proceed on with trust. [13:05.660 --> 13:13.160] And the whole point of all this signing, there are a few goals of signing a key, and people often get one or a couple, but not all of them. [13:13.680 --> 13:16.140] The first goal is to verify that a key is accurate. [13:16.360 --> 13:18.100] And this one, everybody usually gets. [13:18.360 --> 13:29.360] So, with a key server, if you download a key off the Web, there is a possibility that somebody will launch a man-in-the-middle attack and give you a bad key instead of the real key you're trying to get. [13:29.980 --> 13:33.560] So, the way this is foiled is by having a fingerprint. [13:34.060 --> 13:42.860] It is... you take a hash of the key, and you're just verifying certain bytes of the key, basically, through a known secure channel. [13:42.860 --> 13:54.320] And in this case, a known secure channel is almost always meeting the person face-to-face and exchanging the short string of bytes, and that way there is no possibility of garbled information. [13:55.000 --> 13:57.880] Over the phone can work, if you're familiar with the person's voice. [13:58.360 --> 14:06.540] Over the Internet is possible if you're using a channel previously secured by one of these secure channels. [14:07.580 --> 14:12.120] It is entirely up to your discretion, but the usual way it works is face-to-face in person. [14:12.340 --> 14:14.060] I have my fingerprint on my business cards. [14:14.320 --> 14:17.100] So, every time I give out a business card, my fingerprint's right there. [14:17.260 --> 14:17.960] Somebody can see it. [14:18.100 --> 14:18.720] It's on my key. [14:19.020 --> 14:19.680] It works. [14:21.000 --> 14:24.360] The second goal is to verify that the key ownership is accurate. [14:25.400 --> 14:39.040] And this basically means that somebody is not making keys in your name and going around and trying to convince people that if you send a message encrypted to this key, then it's actually going to this person. [14:39.900 --> 14:42.680] So, I could put any name I wanted on a key. [14:42.800 --> 14:44.640] I could put George Bush on a key. [14:45.300 --> 14:57.460] And the goal of verifying that the key ownership is accurate is to make sure that the person who owns the key with the name George Bush is actually George Bush or who you think is the person named George Bush. [14:57.520 --> 14:59.400] And there is a distinction there, which I'll get into later. [15:00.180 --> 15:05.500] So, the way this is usually done is to check the name on the key against the name on a photo ID. [15:06.480 --> 15:20.520] People generally trust government-issued documents for some reason or another, and if you can show a driver's license or a passport that has the name on it and the name is on the key, then, you know, possession nine-tenths of the law, that plus the photo on it, [15:20.640 --> 15:30.120] you generally assume that the person's legal name for whatever that's worth is the same as the name on the key and the person, the abstract identity, is the same. [15:30.680 --> 15:38.280] So that's only to verify one of my many identities, which is the one that is issued by the trust of third party, the government. [15:38.520 --> 15:38.900] Yes. [15:39.000 --> 15:42.400] I have many identities that are not backed by photo ID, so... [15:42.400 --> 15:44.000] Exactly, and I will get into that. [15:45.620 --> 15:52.480] So the way this usually works is either the photo ID and people usually put an email address on the key as well. [15:52.780 --> 15:57.740] So the way this is usually verified is by emailing the signed key to that email address. [15:57.740 --> 16:04.540] And the theory is, if the person can read email sent to that address, then they must be the owner of that email address. [16:04.740 --> 16:05.940] This isn't always the case. [16:05.940 --> 16:10.860] I don't really feel comfortable with this, but that's common practice, and that's how most people do it. [16:12.620 --> 16:21.480] And the third thing, which is really the most important part, but the least tangible part, is verifying the key identity binding. [16:21.480 --> 16:25.200] So, user IDs are only there for human convenience. [16:25.460 --> 16:35.060] When you have a name attached to a key, the only purpose that name is there is because when you think of other people, you generally think of them by a certain name. [16:35.680 --> 16:42.840] So, if I know, you know, say, that guy over there, I don't think of him as that guy over there. [16:42.840 --> 16:44.660] I don't always visualize him in my head. [16:44.780 --> 16:49.100] It's a lot easier to use the name Brandon, as the person that represents that person. [16:50.000 --> 16:50.800] Doc's dropped. [16:53.160 --> 17:05.940] So, the user IDs are there for human convenience, and by verifying the key identity binding, what you're doing is you're saying this key material is associated with this individual or group or whatever. [17:06.760 --> 17:08.060] A name isn't important. [17:08.360 --> 17:09.620] The details aren't important. [17:09.800 --> 17:13.540] You just know that if you send a message, it's going to whoever you think it's going to. [17:13.700 --> 17:21.320] That is the most important part, and it is also the goal that is stated explicitly the least. [17:22.200 --> 17:22.760] All right. [17:22.900 --> 17:27.820] So, I'm just going back towards the, uh, second point as far as verifying the name and email address of the key. [17:28.100 --> 17:37.700] If memory serves, at least a GPG, I know, allows you to add on various aliases, so, like, you can add on, uh, like, two or three, uh, different, uh, email addresses. [17:37.960 --> 17:40.160] You can have multiple user IDs on a key. [17:40.280 --> 17:41.220] You can have as many as you want. [17:41.620 --> 17:41.940] Sorry. [17:42.200 --> 17:43.080] Can you repeat the question, please? [17:43.420 --> 17:48.020] Uh, he's, I, I'm, I'm guessing, I think, you're asking about multiple user IDs. [17:48.500 --> 17:48.800] Correct. [17:49.060 --> 18:01.760] And also the fact that you can also, uh, change the ones that are already on there, so there's, at least as far as the, uh, real name and the email addresses go, I mean, I can give you one that has my real information. [18:01.980 --> 18:08.680] I can change it, upload the changed, uh, user name and email address, and then, uh, give it to someone else. [18:10.120 --> 18:11.960] I'm not fully sure that works. [18:12.140 --> 18:14.260] You have to sign the, uh, IDs individually. [18:14.680 --> 18:14.840] Yes. [18:15.180 --> 18:24.550] You, you sign, you sign the user IDs on a key individually, um, and the signature, if you change, like, you're not supposed to be able to change user IDs. [18:24.810 --> 18:25.810] It doesn't work. [18:25.990 --> 18:42.650] So, um, you can have multiple user IDs, and signing one user ID makes the entire key valid, but it only means, uh, it is up to the application to, to determine whether a user ID is trusted versus whether the key is trusted. [18:42.910 --> 19:01.890] So if you have five different email addresses, somebody can sign one of your five user IDs, and then the key is considered validated by that other key, but for the individual user IDs, uh, it is left entirely up to the user, the application handling it, [19:01.990 --> 19:08.190] whatever, to determine that not only is the key valid, but the user ID that has been signed is trusted. [19:08.690 --> 19:12.250] It doesn't calculate the hash based on the information in the signature. [19:12.350 --> 19:15.570] Yeah, it, it's, it's per user ID, so you, you, you can't really do that, yeah. [19:15.690 --> 19:20.830] Yeah, yeah, because then you could just sign a user ID, completely change it, and it defeats the purpose of it, so you can't do that. [19:21.230 --> 19:21.450] Yeah. [19:21.830 --> 19:25.130] So, these, these are the goals of signing a key. [19:25.470 --> 19:29.470] And the third one is what I'm going to be focusing on through this talk. [19:30.850 --> 19:33.810] And a little more explanation on that. [19:33.990 --> 19:35.070] Um, I mentioned this before. [19:35.070 --> 19:38.830] Signatures are actually on user IDs and not on the key itself. [19:39.210 --> 19:42.850] So you have to pick a user ID when you're signing somebody's key. [19:43.310 --> 19:50.370] And a lot of people will have their name and their email address and an additional comment sometimes in their user ID. [19:50.590 --> 19:54.950] And sometimes you can verify a name and not the email or the other way around. [19:55.450 --> 19:59.270] And if this happens, then do you sign the entire user ID? [19:59.390 --> 20:02.350] You can't sign a certain chunk of bytes of the user ID. [20:02.350 --> 20:05.250] You can't say, I believe the name but not the email. [20:05.610 --> 20:08.810] So, this scares people off from signing things sometimes. [20:09.130 --> 20:18.890] It causes people to send email addresses, uh, the signed key, and assume that that is a verification of the email address. [20:19.190 --> 20:20.150] It's sketchy. [20:20.270 --> 20:20.750] It's tenuous. [20:20.870 --> 20:22.650] But for the most part, it works. [20:23.770 --> 20:26.810] Uh, the fingerprint is part of verifying the key material. [20:26.810 --> 20:30.570] And again, this is implied in any UID signature. [20:30.890 --> 20:34.250] So, uh, you sign one user ID, the entire key. [20:34.610 --> 20:37.470] Key material is good, but the identity is not good. [20:38.550 --> 20:44.950] And this is very, very confusing to people who are not familiar with the inner workings of EGP and how it works. [20:45.730 --> 20:48.050] Um, I use Mutt as my mail reader. [20:48.830 --> 20:53.730] And it will actually look at the user IDs and see... [20:54.190 --> 21:00.750] Uh, if you're sending somebody an email, it'll look up the emails in the user IDs and see if that particular user ID has been... [21:00.750 --> 21:03.430] has been signed by your key. [21:03.810 --> 21:07.930] And it will give you a warning saying, I don't know this person even though the key is valid. [21:08.350 --> 21:09.050] If not... [21:09.570 --> 21:11.050] Uh, but not everything does that. [21:11.210 --> 21:14.470] Some things completely ignore that and they just go, oh, the key is valid. [21:14.590 --> 21:15.830] Web of Trust says it's fine. [21:15.830 --> 21:16.890] Do whatever. [21:17.590 --> 21:32.350] And I could put, you know, president at whitehouse.gov as a user ID on my key and I wouldn't be able to read any email going to that address, but people might still try to send encrypted email with my key to that address and it's stupid because it won't work. [21:32.810 --> 21:40.310] So, that is one problem that needs to be fixed and people need to be aware of because it is not universal. [21:41.030 --> 21:45.670] But you can send a key with president at whitehouse.gov as the primary identity and put it on the keys. [21:45.750 --> 21:46.110] Yes, you can. [21:46.310 --> 21:46.850] It's the same thing. [21:46.970 --> 21:47.190] Yes. [21:48.930 --> 21:55.030] It's different in the sense that it's like guilt by association. [21:56.530 --> 22:06.650] If they sign one user ID and they go, okay, this key is good, and then later on I add a user ID, they will, the application might not... [22:06.650 --> 22:07.310] It will not be my key then. [22:07.450 --> 22:08.390] It will not be my key ring. [22:08.710 --> 22:10.470] I did not get your updated key. [22:10.470 --> 22:10.850] Okay. [22:10.990 --> 22:17.050] Well, say you accidentally do a GPG refresh keys and pull in new signatures so you can expand. [22:17.090 --> 22:18.570] You can have private conversations over there. [22:18.690 --> 22:19.650] We don't know what you're talking about. [22:19.650 --> 22:20.230] Oh, I'm sorry. [22:20.330 --> 22:20.770] I'm sorry. [22:20.810 --> 22:21.810] We can't hear him. [22:21.810 --> 22:22.310] Okay. [22:22.850 --> 22:23.790] I understand. [22:24.250 --> 22:30.770] He asked what happens if the additional user ID is added afterwards. [22:31.550 --> 22:33.610] He says that it's not the same key. [22:33.670 --> 22:41.070] Because if I add an extra user ID afterwards, then he has a copy of my key and it's not the same key. [22:41.730 --> 22:43.130] And I said it's... [22:43.130 --> 22:44.550] Or is that what you were asking? [22:44.690 --> 22:45.510] Or is that the gist of it? [22:45.770 --> 22:46.290] Sort of, yeah. [22:46.350 --> 22:48.010] Would you like repeat the question then? [22:48.550 --> 22:49.670] Or go to the microphone? [22:52.130 --> 22:52.850] Hi, I'm Paul. [22:53.090 --> 23:06.410] My comment was that if you give me your key and I sign it because I trust it and then you later on add president at whitehouse.gov, that I will not have that copy of the key so I will not be confused into trusting that signature. [23:06.650 --> 23:07.110] Okay. [23:07.110 --> 23:16.670] And I think if I do a GPG refresh, I'm assuming GPG would tell me what the new identities are and say, you know, this is a new president at whitehouse.gov identity. [23:16.830 --> 23:18.010] Do you want to trust this or not? [23:18.130 --> 23:19.770] It will not actually do that. [23:20.450 --> 23:31.550] It will inform you that new identities have been added, but what you're assuming is that you are using GPG directly there are many programs that build on top of GPG. [23:32.150 --> 23:35.170] For example, I use Mutt as a mail reader. [23:35.350 --> 23:36.930] I use Thunderbird as a mail reader. [23:37.430 --> 23:46.890] And these programs, because they operate at the higher level, they will use the output of GPG and make decisions accordingly. [23:47.210 --> 24:07.570] And they will not... the programs that you may use, you being the general you, not necessarily you individually, you say that you don't do stuff like this, but somebody else who gets one of these programs like Thunderbird might just say, okay, well, my email program is going to run this plug-in and it's going to tell me whether I should trust it or not. [24:07.870 --> 24:11.190] It might not make the same security decisions that you do. [24:11.370 --> 24:11.710] Okay. [24:11.790 --> 24:16.150] I don't know about all these software out, obviously, but did you file a bug report to the Thunderbird people then? [24:16.150 --> 24:17.210] Um, I have not. [24:17.410 --> 24:20.290] Because it is... it's not really a security issue. [24:20.550 --> 24:20.890] It's... [24:20.890 --> 24:21.790] You just said it was. [24:22.090 --> 24:22.570] Well... [24:23.810 --> 24:25.790] It is... it is a design flaw. [24:26.150 --> 24:27.790] It is a matter of personal preference. [24:28.030 --> 24:29.010] I don't like it. [24:29.170 --> 24:39.670] For the average user who wants something that's easy to use, the argument on the other side can be made, well, if you've signed the key, then you should be familiar with what's in the key. [24:40.770 --> 24:41.210] And... [24:41.670 --> 24:43.270] I don't... I agree with you. [24:43.470 --> 24:44.730] I definitely do agree with you. [24:44.870 --> 24:49.290] And I... I can send them a bug report, but I don't expect it to be fixed. [24:49.970 --> 24:51.410] Because they say if you... [24:51.410 --> 25:01.390] Their... their counter argument will be is, if you update your key ring, you should personally verify every ID in that and user judgment. [25:01.690 --> 25:07.190] We... we stop and we ask you a yes or no question whether you trust this, because we are leaving it up to you. [25:07.330 --> 25:21.390] And it is up to you whether you say yes or no, to trusting it, but they present you with misleading information sometimes in that case by saying you've signed this key, so you think it's good, but we can't verify this identity. [25:22.130 --> 25:24.390] Um, so it's not really a bug. [25:24.530 --> 25:26.710] It's a user issue. [25:26.950 --> 25:27.990] Can you file a bug report? [25:28.090 --> 25:28.730] Okay, I will. [25:28.890 --> 25:29.590] I will do that. [25:30.210 --> 25:31.790] Um, and... [25:31.790 --> 25:37.130] the... the bottom line with that is it's easier to fool the user than to hack the system. [25:37.130 --> 25:40.550] And users either... [25:40.550 --> 25:47.730] and with cryptography, unfortunately, users either generally know what they're doing completely or don't know that well. [25:47.830 --> 25:51.650] So it's easier to fool people when they're getting into it. [25:51.710 --> 25:56.790] And that often gives people a bad taste in their mouth about using this encryption stuff in general. [25:57.990 --> 25:58.510] And... [25:59.970 --> 26:03.850] better education is needed for this kind of stuff, which is why I'm doing this kind of talk. [26:03.850 --> 26:04.310] So... [26:04.570 --> 26:07.410] I'm just trying to say don't trust this kind of thing. [26:07.650 --> 26:11.970] Always say no if you have any doubts whatsoever if it asks you do you trust this. [26:12.830 --> 26:13.330] Um... [26:14.110 --> 26:14.710] so... [26:15.370 --> 26:15.970] But... [26:15.970 --> 26:19.990] Are there any other questions before I get back to key identity binding? [26:20.730 --> 26:21.550] Anybody else? [26:22.170 --> 26:22.770] Okay. [26:23.670 --> 26:24.150] Um... [26:24.150 --> 26:28.150] This is one common argument that is made at key signing parties. [26:28.150 --> 26:28.970] And... [26:28.970 --> 26:30.450] This actually... [26:30.450 --> 26:34.910] This talk started two years ago at DEFCON when I was at a key signing party there. [26:35.210 --> 26:38.050] And there were four people at this key signing party. [26:38.390 --> 26:39.070] There was me. [26:39.590 --> 26:42.150] This other guy who was very strict about checking... [26:43.550 --> 26:44.390] photo IDs. [26:44.850 --> 26:47.650] And had already signed my key so I didn't really care about him. [26:48.090 --> 26:51.770] And two other people who didn't want to identify by their real names. [26:52.190 --> 27:00.370] Well, one wanted to if necessary, but she didn't have any supporting evidence that she was really who she claimed to be. [27:00.610 --> 27:02.290] And the other guy was like, screw you. [27:02.410 --> 27:03.730] I'm not showing you my real name. [27:03.970 --> 27:05.990] It doesn't even matter because it's not on my key. [27:06.390 --> 27:09.810] So he walked away from this key signing party without signing anybody's keys. [27:10.310 --> 27:21.310] And I thought that was pretty stupid because the guy who refused to give out his real name was speaking at DEFCON under the alias that he gave and the alias that was on his key. [27:21.550 --> 27:26.950] So he went up in front of more than a thousand people and identified himself by a made-up name. [27:27.230 --> 27:29.950] And everybody in the audience went, okay, right on. [27:30.230 --> 27:31.110] That's who you are. [27:31.230 --> 27:31.390] Cool. [27:31.870 --> 27:34.270] And everybody in the audience accepted it. [27:34.550 --> 27:39.110] More than a thousand people said, okay, we'll take that as what you'd like to call yourself. [27:39.450 --> 27:48.850] And this guy would not view that as acceptable for signing a key with that alias on it because he wanted to see photo ID. [27:48.850 --> 27:52.690] So, there is no way to verify a handle. [27:53.550 --> 27:54.630] Does anybody agree? [27:55.070 --> 27:55.430] No. [27:55.610 --> 27:56.150] No? [27:56.450 --> 27:56.950] Yes? [27:57.170 --> 27:58.510] Is there a single yes in the room? [27:59.670 --> 28:00.270] Yes. [28:00.270 --> 28:00.850] Okay, well... [28:01.370 --> 28:01.950] Yes. [28:02.430 --> 28:03.030] What... [28:03.030 --> 28:04.050] Where'd my... [28:05.290 --> 28:05.890] Okay. [28:06.170 --> 28:06.990] Who's this guy? [28:08.190 --> 28:09.110] Dark Tangent. [28:09.390 --> 28:09.730] Okay. [28:09.890 --> 28:12.070] Dark Tangent was the first thing that is said. [28:13.010 --> 28:13.610] DT. [28:13.610 --> 28:14.890] Jeff Moss. [28:15.810 --> 28:16.890] Would you sign... [28:16.890 --> 28:23.850] you in the general sense, would anybody here sign a key that this guy gave you that had the name Dark Tangent on it? [28:23.950 --> 28:26.350] Do I know him already- Do you know him already? [28:26.910 --> 28:28.630] You identified him by name. [28:28.890 --> 28:29.630] Do you know him? [28:29.690 --> 28:31.830] Everyone else anyone knows him as Dark Tangent and... [28:31.830 --> 28:39.470] But you saw a photo of this guy, this random guy, and you identified him first as Dark Tangent. [28:39.470 --> 28:44.130] If this guy here were to give you a key that said Dark Tangent on it, would you sign it? [28:44.230 --> 28:44.790] I probably would. [28:44.910 --> 28:45.570] Okay, you would. [28:45.670 --> 28:47.030] Would anybody here not sign it? [28:48.570 --> 28:50.590] Okay, we have a decent number of people who wouldn't. [28:51.030 --> 28:53.190] Does anybody want to offer why they wouldn't? [28:54.030 --> 28:56.010] I've never actually met Dark Tangent. [28:56.110 --> 28:57.250] I don't know what he looks like. [28:57.410 --> 29:00.250] So if this guy walks up and says, this is Dark Tangent's key... [29:00.250 --> 29:01.830] Okay, so you don't know him. [29:02.090 --> 29:07.670] Is there anybody here who has identified this guy as Dark Tangent, not sign this key? [29:09.950 --> 29:10.510] Why not? [29:11.470 --> 29:13.370] Just because it's an alias, you don't know who he is. [29:14.010 --> 29:14.370] Okay. [29:15.090 --> 29:17.430] If it's just because it's an alias, you don't know who he is. [29:18.190 --> 29:26.250] The fact that I know who he is or not, and I can either prove that I know who he is or not, is completely irrelevant from the question of whether or not I would sign his key. [29:28.110 --> 29:28.830] If he personally... [29:28.830 --> 29:31.110] Because I know thousands of people. [29:31.230 --> 29:33.450] I'm not going to sign thousands of people's keys. [29:34.350 --> 29:36.370] Okay, so you just don't care about signing his key. [29:36.370 --> 29:43.830] I don't see why you're coupling the whether I would sign this key with whether I know this person, because those are two completely separate issues. [29:44.030 --> 29:47.890] I'm talking about this in the context of you're at a key signing party, you are intentionally choosing... [29:47.890 --> 29:50.230] I don't do key signing parties for the same obvious reason. [29:50.310 --> 29:50.470] Okay. [29:50.890 --> 29:54.770] I'm talking about the context of you are trying to actively build the web of trust. [29:55.550 --> 29:57.530] I guess I should have said that at the beginning. [29:57.750 --> 29:57.970] Sorry. [29:58.630 --> 30:01.750] Are you trying to build a relationship between photos and... [30:02.750 --> 30:05.370] That's part of it, but not all of it. [30:05.370 --> 30:06.610] So, let's move on. [30:10.070 --> 30:11.950] So, who's this guy? [30:13.950 --> 30:14.590] Okay. [30:14.990 --> 30:15.730] Evil Corley. [30:19.390 --> 30:25.730] Would anybody sign this guy's key if he identified himself as Emanuel Goldstein? [30:27.710 --> 30:29.350] You would sign his key? [30:29.530 --> 30:29.710] Yes. [30:29.870 --> 30:30.150] Okay. [30:30.670 --> 30:33.530] Emanuel Goldstein is a fictional character in a book. [30:33.890 --> 30:36.310] Emanuel Goldstein is not a real person. [30:36.310 --> 30:37.970] This guy doesn't f*cking exist. [30:40.070 --> 30:43.510] He just... he likes to call himself Emanuel Goldstein. [30:43.950 --> 30:44.810] It's an identity. [30:45.150 --> 30:46.010] It's an identity. [30:46.330 --> 30:46.510] Yes. [30:48.050 --> 30:48.530] But... [30:48.530 --> 30:49.810] It's the same with that guy. [30:51.070 --> 30:51.990] It's an identity. [30:52.250 --> 30:53.850] He... he calls himself Dark Tangent. [30:54.050 --> 30:56.130] He calls himself Jeff Moss when applicable. [30:56.450 --> 30:57.910] But it's just the same. [30:58.050 --> 31:15.670] I mean, just because we're at a 2600 conference instead of a DEFCON conference, somebody chooses the identity that they want to present themselves as, and it doesn't matter, or it shouldn't matter, is the argument I'm making, whether they present a fake name or a real name. [31:15.770 --> 31:20.370] As long as you are able to bind the name to the identity, you're verifying the identity. [31:20.370 --> 31:25.550] You're not verifying the fact that this is the name on the person's birth certificate. [31:25.550 --> 31:26.570] Right. [31:27.290 --> 31:33.490] Would it be more important because he's been tied in, like, court papers with the alias and the real name? [31:33.970 --> 31:37.730] You're asking about court papers and his name in those. [31:38.470 --> 31:41.370] Is his name in the court papers actually Emanuel Goldstein? [31:41.610 --> 31:41.850] Both. [31:42.390 --> 31:43.090] I'm sorry? [31:43.290 --> 31:43.550] Both. [31:43.710 --> 31:44.570] It is both. [31:44.850 --> 31:44.970] Okay. [31:45.390 --> 31:45.910] Yes. [31:46.090 --> 31:51.470] So the AK8, then if you consider that acceptable to tie that in, then that's great. [31:51.630 --> 31:55.190] But I can be like, my name is Emanuel Goldstein. [31:55.190 --> 32:07.390] And then I can go out and I can register www.fuckriaa.com, get sued by them, and then in the court proceedings it'll be like, Seth Hardy, AKA Emanuel Goldstein. [32:10.070 --> 32:11.910] Do you really trust that? [32:12.050 --> 32:13.890] Do you really think that nobody else could do that? [32:13.970 --> 32:18.490] I mean, this guy is well known and high profile, so it's a lot easier to verify. [32:19.090 --> 32:22.450] But would you verify anything like that, is what I'm asking. [32:23.290 --> 32:28.930] And if the answer is no, then it's not something that automatically counts. [32:30.170 --> 32:30.790] Uh-oh. [32:31.410 --> 32:31.850] Sorry. [32:32.130 --> 32:32.990] I should sit here. [32:33.650 --> 32:35.210] Just take the microphone with you. [32:35.430 --> 32:38.730] If you want to come up on stage with me and turn this into a panel, I'm cool with that. [32:38.730 --> 32:38.810] Yeah! [32:39.310 --> 32:39.910] Yeah! [32:40.030 --> 32:41.550] I can't argue with her! [32:42.330 --> 32:42.950] Come on up! [32:45.570 --> 32:46.170] Yeah! [32:46.170 --> 32:51.350] Whether or not you're signing somebody keys does not only depend on the identity of the person. [32:51.550 --> 33:00.190] I might not want to associate myself with you and not sign your key or I might not want to associate myself with either Eric or with Jeff. [33:00.870 --> 33:08.070] The whole purpose of a key is to be able to send somebody encrypted stuff so only that person can read it. [33:08.210 --> 33:12.170] And it doesn't matter what label you attach to that person. [33:12.410 --> 33:16.910] As long as only that person can get it, what does it matter what labels you put on it. [33:16.910 --> 33:32.790] Okay, so I guess our goal is somewhat different in building a web of trust, because my web of trust, and if you look at my key, you will find people that I have some sort of binding with, and not like my arch enemies just because I've seen a driver's license. [33:33.130 --> 33:33.650] Okay. [33:35.270 --> 33:36.990] Okay, completely different... [33:37.510 --> 33:39.130] That will definitely go through court papers. [33:39.270 --> 33:44.730] Okay, so what you're saying is you define trust completely differently, and that's acceptable. [33:44.950 --> 33:49.170] I'm talking about trusting in terms of using the GPG framework only. [33:50.070 --> 33:55.710] Like, I will sign somebody's key even if I think they're a complete and total scumbag who will always lie to me. [33:55.790 --> 34:05.570] If they show proper fingerprint verification, and a user ID that associates the key with them, I will sign it even if I think they're a lying asshole. [34:06.050 --> 34:13.090] Because the only reason I'm using the key is to send them encrypted material, and to get encrypted stuff to that guy only. [34:13.510 --> 34:14.930] Whoever that guy may be. [34:15.550 --> 34:16.310] Sure, okay. [34:16.510 --> 34:16.890] So, yeah. [34:17.130 --> 34:22.770] Okay, so in that sense, I agree that there's no point in signing a million people identity in a web of trust. [34:23.690 --> 34:24.050] Okay. [34:25.490 --> 34:28.030] Well, I mean, isn't there kind of a fallacy there that you're tying? [34:28.930 --> 34:31.370] If you would like to come up and argue with me, you're welcome to. [34:32.290 --> 34:32.650] Ruckus! [34:35.430 --> 34:37.210] If you want to introduce yourself first. [34:37.450 --> 34:38.490] But you have to drink. [34:38.590 --> 34:39.990] Those are the rules of the arena. [34:40.890 --> 34:42.310] Can we get the other mic on? [34:43.830 --> 34:45.010] Somebody pour the gentleman? [34:45.250 --> 34:45.610] Thank you. [34:45.870 --> 34:46.510] That's right. [34:46.970 --> 34:48.070] Adam Smasher. [34:48.590 --> 34:54.450] And I had an article on PGP key signing in the Winter 05-06 2600 magazine. [34:54.810 --> 35:01.130] For the record, despite our differing opinions about how to handle this stuff, we do not agree on everything. [35:01.290 --> 35:05.630] I was more than happy to help him proofread the article, and I trust his judgment. [35:06.170 --> 35:08.970] So, even if we disagree, I trust his judgment. [35:09.990 --> 35:10.510] Okay. [35:11.030 --> 35:21.030] And most of where we differ in opinions, I think, is probably on the issue of verifying the identity of the key ownership. [35:22.550 --> 35:24.570] As I said, my name is Adam Smasher. [35:24.890 --> 35:30.670] I've got, off the top of my head, I can think of three different birth certificates of mine with three different names. [35:31.130 --> 35:31.570] Okay. [35:33.450 --> 35:51.670] So, I kind of think that if somebody builds up a reputation, as Emanuel Goldstein, or as Dark Tangent, or whatever their handle is, that their reputation under that identity establishes them to a certain extent with that identity. [35:51.950 --> 35:57.310] And I don't think that's exclusively different than a legal name to a large extent. [35:57.550 --> 35:58.670] And also... [35:58.670 --> 36:00.130] But that's what I'm arguing right here. [36:01.650 --> 36:04.130] I mean, if we go to the next slide... [36:10.400 --> 36:11.780] I agree with you on that. [36:11.960 --> 36:12.020] Okay. [36:12.440 --> 36:22.070] So, now, what I would say, then, from there, is that once we establish someone's identity, that we can then go ahead and sign their key, if they've established themselves under that identity. [36:22.070 --> 36:42.590] And also because we're establishing, if you read the article, and don't just go ahead and post the key once you sign it, but encrypt the key, send it to them, so that you're requiring that somebody with control of that email address then has control of the key that they can decrypt your signature on it, [36:42.760 --> 36:44.760] then they can upload it to a key server. [36:44.760 --> 36:53.460] You've then established their identity, partly through the reputation of whatever handle that is, and partly through their email address. [36:55.110 --> 37:05.820] I'm gonna sort of agree with Adam Smasher here, and the example that I'm gonna raise, but first point of order, that serial killer, I think the cop was Emmanuel Goldstein in the movie. [37:06.820 --> 37:08.300] No, he used the word Goldstein. [37:08.520 --> 37:08.940] Okay. [37:09.900 --> 37:11.000] That was his real name. [37:11.000 --> 37:11.360] But... [37:13.670 --> 37:23.070] So what about the scenario of like a public open source project, where you interact with this person all the time, you have no idea who they are as a physical identity? [37:23.720 --> 37:32.340] I mean, we're really transitioning to the 21st century here, where identity is gonna be divorced of the physical person through technologies like Tor and whatnot. [37:32.610 --> 37:37.990] I mean, there can be criteria to establish the fact that, you know, this is the entity that I relate with frequently... [37:38.760 --> 37:45.780] I don't have a simple answer for you, so the only thing I can say is if I could finish my talk, I would answer that, but it's already turned into something else. [37:45.780 --> 37:47.150] Which I'm more than happy to let you now do. [37:47.480 --> 37:51.550] It's not you, but it's already turned into something else, so I'll have to answer that sometime later. [37:51.960 --> 37:52.360] Cheers. [37:52.980 --> 37:53.260] Cheers! [37:53.780 --> 37:53.880] Woo! [37:55.070 --> 37:55.570] What's up? [37:56.840 --> 37:58.810] Yeah, I would ask if there's any way... [37:58.820 --> 38:04.960] like, I wonder if there's actually any way to verify an identity... [38:04.960 --> 38:07.020] or to prove an identity fully. [38:07.300 --> 38:09.120] Do we even really have identities? [38:09.820 --> 38:10.820] I'm not sure... [38:10.820 --> 38:13.240] Dude, what makes a man? [38:13.500 --> 38:14.570] Like, what is a person? [38:26.660 --> 38:29.680] No, no, that's a legitimate question. [38:30.340 --> 38:31.860] You're talking about identity. [38:32.020 --> 38:35.000] Identity is an intangible thing. [38:35.260 --> 38:37.680] It comes down to you and only you decide. [38:37.980 --> 38:47.420] And for me, in my head, it's if I can associate this key with that guy, or that girl as the case may be, then that's good enough for me. [38:47.620 --> 38:50.260] If you would like to overthink it and be like, what makes a man? [38:50.460 --> 38:51.600] And, you know, what is really... [38:52.480 --> 38:53.820] what defines a person? [38:53.960 --> 38:54.780] What is their identity? [38:55.400 --> 38:56.540] Then, good for you. [38:56.620 --> 38:56.820] No, I don't... [38:56.820 --> 38:58.460] I just want to send security... [38:58.460 --> 38:59.140] I don't mean it in that sense. [38:59.240 --> 39:02.340] I mean it in the sense of, like, anything can be forged or impersonated. [39:02.460 --> 39:05.540] I mean, I know plenty of people with fake driver's licenses. [39:05.900 --> 39:08.160] Most of them say they're... [39:09.180 --> 39:09.580] Okay. [39:09.960 --> 39:10.360] Let's... [39:10.760 --> 39:11.920] Let's not talk about... [39:11.920 --> 39:12.900] I'm not giving any names. [39:13.160 --> 39:13.460] Don't worry. [39:14.180 --> 39:16.040] Let's not talk about fake IDs. [39:16.320 --> 39:21.100] By the way, anybody who wants to come to the key signing party tomorrow, it's at one o'clock in the workshop area. [39:23.000 --> 39:23.440] Yeah. [39:24.200 --> 39:25.560] Anyways, I'm sorry, keep going. [39:25.920 --> 39:30.140] But anyway, what I'm saying is that these things do definitely exist and that... [39:30.140 --> 39:30.660] That's exactly the point I'm trying to make. [39:30.660 --> 39:33.560] Even with a real name, it can be forged just like a handle. [39:33.800 --> 39:35.900] You can impersonate someone else. [39:36.100 --> 39:38.100] That is exactly the point I'm trying to make. [39:38.100 --> 39:38.140] Thank you. [39:38.140 --> 39:39.980] But you can impersonate a private key. [39:41.980 --> 39:43.400] And that's the identity. [39:43.620 --> 39:44.640] It is the private key. [39:50.090 --> 39:51.010] I think... [39:51.010 --> 39:53.310] What the hell is wrong? [39:53.350 --> 39:54.050] How's it going, Miles? [39:55.410 --> 39:55.870] Sorry. [39:58.750 --> 39:59.510] I think the key... [39:59.510 --> 40:02.190] Just for the record, I've got 17 minutes left, so... [40:02.190 --> 40:03.490] Can you take us all 17 minutes, Miles? [40:04.750 --> 40:05.670] Let's keep moving. [40:05.930 --> 40:12.030] The key signing parties are different than the signing of someone like Emanuel or the signing of somebody who talked at a conference. [40:12.330 --> 40:20.690] Because the rules of key signing parties are designed to deal with this strange situation that you're signing strangers' keys, which is different than signing this guy's key. [40:20.690 --> 40:21.990] The point I'm trying to make... [40:21.990 --> 40:26.790] If you use the non-key signing type of signing, then you can have more than one web of trust. [40:26.990 --> 40:32.510] The point I'm trying to make is that this is a function of social networking. [40:32.510 --> 40:45.870] And key signing parties are an artificial construct within that where things like photo ID and whatever are introduced as a way of handling situations where you don't know the person. [40:46.190 --> 40:48.430] But people are taking it too far. [40:48.690 --> 40:56.790] They are saying things like, I will not sign your key even if I've known you for the last 20 years unless you produce photo ID. [40:56.790 --> 41:02.510] And I'm saying that is completely unnecessary because the key identity binding is there for you and you alone. [41:02.810 --> 41:06.230] And if other people don't like it, well then they can just not sign your key. [41:07.290 --> 41:15.130] But if I came up with a new key and I handed you the private key and I asked you to sign it, I lived with you for a year. [41:15.490 --> 41:18.890] Would you ask me to see my driver's license before signing the key? [41:19.170 --> 41:20.230] I don't think you would. [41:20.810 --> 41:24.890] And a lot of these people are starting to say, well, we're security professionals. [41:24.890 --> 41:27.690] This is proper operating procedure. [41:27.950 --> 41:29.170] We need to do this. [41:29.630 --> 41:41.490] And it is causing a lot of problems, unnecessary exclusion of people from the web of trust and problems in certain situations when it is not an individual behind the key. [41:42.130 --> 41:45.450] So that's the point I'm trying to make. [41:45.670 --> 41:46.490] You have 12 minutes now. [41:46.590 --> 41:49.230] I'm all for letting you continue your flawed and thoroughly debunked talk. [41:50.810 --> 41:52.830] I think these people are supporting me. [41:53.930 --> 41:55.310] So, are there any... [41:55.690 --> 41:57.750] Do you want to add anything before I continue? [41:58.150 --> 42:03.030] Actually, I'm just thinking that we're more in agreement than I thought 24 hours ago, probably, if anything. [42:05.730 --> 42:09.890] So, going back to the slides, a person only has one unique identity. [42:10.170 --> 42:11.770] I'm just going to skip through these really quickly. [42:11.930 --> 42:14.150] They're not going to be as funny as they were in Germany, unfortunately. [42:14.910 --> 42:15.410] But... [42:16.830 --> 42:19.930] We've already covered pseudonyms, so... [42:20.670 --> 42:21.170] Yeah. [42:21.670 --> 42:22.690] You know, would you sign her key? [42:23.070 --> 42:23.810] Probably not. [42:24.410 --> 42:25.770] Would you sign her key? [42:26.870 --> 42:27.370] Maybe. [42:29.230 --> 42:30.470] Would you sign her key? [42:30.630 --> 42:31.170] You wish. [42:33.490 --> 42:42.550] You know, it's all a matter of key to the identity binding, not key to name, not to even situation. [42:42.650 --> 42:53.530] It's just, you're sending messages to that guy, or in that case, that chick that Emmanuel was going on and on about, about how she came to a 2600 meeting, so now she's been mentioned twice at the conference. [42:54.070 --> 42:56.470] She should be a keynote speaker next time or something. [42:58.670 --> 42:59.530] Sorry, Jello. [43:01.910 --> 43:08.870] It's just a matter of figuring out what you accept as a name, or are you really going for the name or the identity? [43:11.230 --> 43:12.850] Here's the serious example. [43:13.350 --> 43:19.330] Does anybody in this room know who security-officer at netbsd.org is other than Miles? [43:22.770 --> 43:24.570] Do we need to know this question? [43:24.950 --> 43:25.850] Well, yes. [43:27.210 --> 43:44.870] Because what if this person, or this key, who has 24 signatures, who's signed three other keys, who is only three hops from my key, what if this is a team of 20 people, and one of them has signed the key and the other 19 are ignorant of that fact? [43:46.770 --> 43:47.390] Uh-oh. [43:51.130 --> 43:53.650] But I don't even need to know if it's an individual. [43:53.870 --> 43:54.430] It's a role. [43:54.790 --> 44:02.370] If there's a bug in netbsd that I need to report to, I'm reporting it to the role of the security officer, and I don't care whether it's one or 20 people. [44:03.390 --> 44:04.190] Okay, but... [44:04.990 --> 44:06.450] But the proof of... [44:08.830 --> 44:16.990] Proof of ownership here is tricky, because what if one person leaves on bad terms, and they say, well, we'll just change the passphrase on the key? [44:17.130 --> 44:27.890] And that person who leaves on bad terms says, I'm going to release, like, the next copy of Windows, signed by the netbsd key, saying, this is netbsd 3.0 alpha, this is the future. [44:30.890 --> 44:39.770] If netbsd people are handing out the private key to everybody and thinking that changing the passphrase will actually protect the key, then I think the whole netbsd project should disband. [44:39.770 --> 44:45.870] Well, at the talk I gave in Germany, there was somebody from Sweden there who said... [44:45.870 --> 44:56.790] We were talking about government... or keys in a corporation, and he was of the opinion that if somebody was fired from their job, the key for the corporation should change. [44:57.370 --> 45:00.970] And I said, I don't think... or no, he said that it shouldn't change. [45:01.150 --> 45:05.910] I said that it should, and he said, well, why should you change the key because of one person? [45:05.910 --> 45:08.990] You're not changing the role, it's just one person cycling through. [45:08.990 --> 45:16.930] And my statement is, you know, if one person leaves on bad terms, you can't just change the passphrase and make everything okay. [45:17.370 --> 45:23.270] And if one person leaves from netbsd on bad terms, do you think they're going to cycle the entire key or not? [45:23.630 --> 45:24.170] They might. [45:25.710 --> 45:29.650] Chances are netbsd probably will, but this company in Sweden doesn't. [45:30.550 --> 45:35.470] Well, then people should know how to use like a master key and have people sign that. [45:35.550 --> 45:43.050] You'll have the master key, sign the individual people, and then you can revoke individual people when they leave, and individual people can sign releases for that. [45:43.190 --> 45:45.530] Right, but how do you know that this is actually the case? [45:48.410 --> 45:49.850] Do you trust that... [45:49.850 --> 45:50.710] Well, that's the other problem. [45:50.830 --> 45:57.010] If I see this email address on their website, I have to trust that their website's not hacked, that other things are not there. [45:57.150 --> 45:58.290] Yes, it is up to them to solve the problem. [45:58.290 --> 45:59.930] Or that the signatures of this key are okay. [46:00.370 --> 46:03.170] It's up to netbsd in this example to solve the problem. [46:03.170 --> 46:05.910] What I'm saying is I don't think they will if there is a problem. [46:06.050 --> 46:07.870] All right, so we've identified the area. [46:08.210 --> 46:11.130] I mean, we can do specific examples to death at this point, right? [46:12.970 --> 46:13.370] So... [46:13.890 --> 46:14.290] So... [46:14.290 --> 46:14.490] Yeah? [46:15.030 --> 46:15.430] Sure. [46:18.030 --> 46:18.830] This is just... [46:18.830 --> 46:22.830] This is the relationship between my key and the netbsd key. [46:24.570 --> 46:25.150] Photo ID. [46:25.330 --> 46:37.150] You can always trust a photo ID, I guess, is a good thing, because the first person to tell me what's wrong with this ID, and I don't give a shit about the expiration date, but the first person who can tell me what's wrong with this ID gets a free T-shirt. [46:37.150 --> 46:38.170] She's smiling. [46:43.230 --> 46:44.690] All right, who said that? [46:46.570 --> 46:47.430] Who said that? [46:47.610 --> 46:48.650] I've got two T-shirts. [46:52.390 --> 46:54.110] What is wrong with this ID? [46:56.110 --> 46:57.490] Just shout it out. [46:58.310 --> 46:59.530] It's not the eye color. [46:59.870 --> 47:00.770] She's smiling. [47:01.010 --> 47:02.490] It's not that she's smiling. [47:02.730 --> 47:03.950] What is wrong with this ID? [47:13.330 --> 47:15.830] I told you the expiration doesn't matter. [47:16.190 --> 47:17.410] What is wrong with this ID? [47:17.590 --> 47:18.290] It's out of date. [47:19.630 --> 47:21.070] She's only four years old? [47:23.330 --> 47:25.070] She's pretty hot for a four-year-old. [47:27.810 --> 47:28.470] I'm sorry? [47:29.930 --> 47:30.950] What about her name? [47:32.750 --> 47:33.610] Have a T-shirt. [47:33.610 --> 47:34.590] It's Elaine, yeah. [47:35.130 --> 47:40.990] So this picture I found online while doing a Google Images search for fake ID. [47:41.310 --> 47:51.210] This was a post in her blog saying, I can't believe this ID got me into clubs all the time because they f*cked up my last name. [47:51.410 --> 47:55.990] Her last name is Lane, and they abbreviated it LN, period. [47:57.850 --> 47:59.390] Hooray, South Carolina. [48:00.150 --> 48:07.470] So this is a problem that I have with people who rely on government-issued photo IDs. [48:10.660 --> 48:15.870] You are placing trust arbitrarily on a third party that is not necessarily to be trusted. [48:15.870 --> 48:19.890] And a lot of security professionals swear by this method. [48:20.050 --> 48:24.350] They will not sign your key unless they see a driver's license or a passport. [48:24.350 --> 48:25.870] Even if it's... [48:25.870 --> 48:30.570] I was reading up on this a while ago and somebody mentioned a Tasmanian passport. [48:31.050 --> 48:36.470] And despite the fact that there are no Tasmanian passports, you have an Australian passport. [48:39.310 --> 48:46.730] If people see something that looks vaguely official, then they'll go, oh, okay, and smile and nod, and it's all good. [48:47.510 --> 49:00.710] Why are you placing trust in a third party arbitrarily when you won't trust social networking, like recognizing somebody's name, like I put up a picture of Emmanuel and everybody goes, hey, that's Emmanuel Goldstein. [49:01.490 --> 49:03.490] This is one of the main points I'm trying to make. [49:04.110 --> 49:09.170] The trusting of verifying somebody's identity is up to you and you alone. [49:09.390 --> 49:19.270] And it doesn't matter whether they have a piece of plastic with some crappy holograms laid over for an extra $10 on Canal Street or whether they are, you know... [49:20.470 --> 49:32.690] You have to make this decision for yourself, and the piece of plastic isn't gonna or shouldn't help you make that decision for yourself over knowing somebody in person or by reputation over a period of time. [49:36.290 --> 49:44.670] If anything, I'd just like to add to that, that, I mean, most of us in this room are hackers and inherently we distrust government agencies. [49:45.310 --> 49:51.370] So, why would we trust government agencies to ensure the identification of other hackers? [49:51.590 --> 49:54.770] And after all, who is it except other hackers that are using PGP? [50:00.870 --> 50:12.130] All right, so I guess because I'm just about out of time, I'm not gonna get to finish the talk, but I would like to show the perils of identity verification through photo ID. [50:12.790 --> 50:20.050] This is somebody who should be fairly well-known or just another average person. [50:20.470 --> 50:22.870] You know, she's kind of cute maybe, I guess. [50:23.290 --> 50:25.110] But, you know, people... [50:26.550 --> 50:28.510] With a bag over her head. [50:30.210 --> 50:31.230] Here's her ID. [50:31.510 --> 50:32.710] Her name is Barbara Pierce. [50:33.010 --> 50:35.090] She lives on 160 Madison Avenue in Baltimore. [50:35.630 --> 50:38.790] Please ignore the rotten.com URL on the bottom right. [50:40.130 --> 50:42.050] A photo ID gives out many details. [50:42.210 --> 50:47.310] A lot of hackers do not want to show photo ID because they don't want their docs dropped. [50:47.310 --> 50:51.070] They don't want people to know what their real name is or where they live. [50:51.790 --> 50:54.630] So they will not show photo ID for that reason. [50:54.910 --> 50:57.650] And they'll be insistent on using a handle instead. [50:58.030 --> 51:07.130] And a photo ID will never have, or usually won't have, with certain exceptions, the same handle that people give out at cons like this. [51:07.430 --> 51:10.310] So, why does this woman look familiar? [51:10.710 --> 51:13.850] It's Barbara Bush who lives in 1600 Pennsylvania. [51:13.850 --> 51:15.630] Yeah, here's a picture of her and her dad. [51:21.430 --> 51:23.570] So, that's her photo ID. [51:25.710 --> 51:26.830] That's her father. [51:27.390 --> 51:29.170] Does this match up? [51:29.750 --> 51:30.430] No? [51:30.910 --> 51:31.010] No? [51:31.590 --> 51:33.610] It got her into bars. [51:35.970 --> 51:38.210] With Secret Service Escort. [51:38.490 --> 51:40.370] With her Secret Service Escort. [51:40.410 --> 51:44.750] But it did get her into bars, or supposedly got her into bars. [51:45.390 --> 51:46.050] I'm sorry? [51:46.330 --> 51:47.910] Secret Service math department? [51:48.250 --> 51:50.030] I don't... I wasn't there. [51:50.170 --> 51:51.370] I don't know her personally. [51:51.890 --> 51:53.270] I don't know... What's up, Nick? [51:53.610 --> 51:57.910] The Secret Service is authorized by federal statute to do two things in that situation. [51:58.110 --> 52:11.750] One, they're not actually technically authorized to verify the validity of the ID, but then at the same time, they're also not authorized to force themselves upon the establishment of the business if they decide to decline their client. [52:11.750 --> 52:13.430] Can you repeat that into the microphone? [52:13.690 --> 52:14.010] Okay. [52:14.650 --> 52:15.730] We'll take your marks, Nick. [52:17.010 --> 52:24.050] Under federal statute, the Secret Service is the only federal agency that is allowed to... [52:24.630 --> 52:45.950] One, I'm sorry, they're not allowed to break the law in this case and say that she is who the ID says she is, but at the same time, they're not allowed to use their authority to enter a place or to force their client entry into a place in a private establishment unless they're authorizing some kind of warrant or suspect that there's a crime going on or they fear for the safety of their client. [52:45.950 --> 52:49.250] So they're not specifically allowed to do anything. [52:49.750 --> 52:50.190] Okay. [52:50.670 --> 52:53.530] Well, that's very good to know and that is all we have time for today. [52:53.550 --> 52:54.830] I want to spot that guy as a fed. [52:54.970 --> 52:59.170] So, Nick is a fed and we're done. [52:59.490 --> 53:03.390] So, I guess if you guys have any more questions on this, just find me later. [53:04.390 --> 53:14.790] The key signing party, there is a key signing party where there will be more of this kind of stuff, shenanigans even, going on tomorrow. [53:14.790 --> 53:17.350] One o'clock in the workshop area. [53:17.750 --> 53:22.850] And I've also been told to advertise the party at the Hacker Halfway House in Brooklyn tonight. [53:23.990 --> 53:29.310] So, you guys should all go to the party at the Hacker Halfway House in Brooklyn even though I don't live there anymore. [53:29.650 --> 53:29.790] So... [53:30.690 --> 53:32.170] It's even better this time. [53:32.430 --> 53:32.770] Yes. [53:32.770 --> 53:32.790] Yes. [53:33.290 --> 53:33.950] What...