This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
|
blug-canary-3 [2019/10/17 08:05] Wu Delin |
blug-canary-3 [2025/10/29 11:39] (current) vimacs |
||
|---|---|---|---|
| Line 7: | Line 7: | ||
| ==================================== | ==================================== | ||
| - | Issued for October | + | Issued for October |
| Don't just trust the contents of this file blindly! Verify the | Don't just trust the contents of this file blindly! Verify the | ||
| Line 15: | Line 15: | ||
| ~~~~~~~~~~~~~ | ~~~~~~~~~~~~~ | ||
| - | * biergaizi: | + | * biergaizi: |
| - | * persmule : 0x2987A25DAC8454A5 | + | * persmule : 0x7636112A33805777A0646B1BFA7C50B699AC61D2 |
| - | * wnereiz | + | * vimacs |
| THREE DOCUMENTS IN TOTAL. | THREE DOCUMENTS IN TOTAL. | ||
| Line 54: | Line 54: | ||
| 8. Our personal safety and security is not threatened. | 8. Our personal safety and security is not threatened. | ||
| - | 9. To avoid security breaches and emphasize the clarity of the warrent | + | 9. To avoid security breaches and emphasize the clarity of the warrant |
| documents, if a signer is temporarily unavailable, | documents, if a signer is temporarily unavailable, | ||
| " | " | ||
| NOT be considered a valid canary document) until the signer becomes available | NOT be considered a valid canary document) until the signer becomes available | ||
| - | again and signs the missed documents. A new signer SHOULD NOT sign a warrent | + | again and signs the missed documents. A new signer SHOULD NOT sign a warrant |
| canary document only due to the temporary unavailability of a existing signer. | canary document only due to the temporary unavailability of a existing signer. | ||
| 10. We plan to publish the next of these canary statements in the first three | 10. We plan to publish the next of these canary statements in the first three | ||
| - | weeks of November | + | weeks of November |
| by that time or if the list of statements changes without plausible explanation. | by that time or if the list of statements changes without plausible explanation. | ||
| + | |||
| + | 11. Due to the ongoing security issues of OpenPGP keyservers, it makes signature | ||
| + | verification an issue and somewhat a challenge. For completeness, | ||
| + | procedures for canary verification is included here. | ||
| Special Announcements | Special Announcements | ||
| Line 69: | Line 73: | ||
| None. | None. | ||
| + | |||
| + | Canary Verification Procedures | ||
| + | ~~~~~~~~~~~~~~~~~~~~~~~~ | ||
| + | |||
| + | 1. To verify biergaizi' | ||
| + | |||
| + | a. Obtain the public key from any traditional OpenPGP Keyserver, such as | ||
| + | https:// | ||
| + | is 0x255211B2395A5A3E0E48A0F1FAD3EB05E88E8D6D. | ||
| + | |||
| + | b. Use the latest GnuPG in any operating system. | ||
| + | |||
| + | 2. To verify persmule' | ||
| + | |||
| + | a. Due to the previous attacks on OpenPGP keyservers, persmule has published | ||
| + | the OpenPGP public key to https:// | ||
| + | the standard method, it's impossible to import a OpenPGP public key without | ||
| + | User-ID. But since April 2013, we have developed a workaround, described | ||
| + | below. | ||
| + | |||
| + | b. Obtain the dummy public key from any traditional OpenPGP Keyserver, | ||
| + | such as https:// | ||
| + | fingerprint is 0x7636112A33805777A0646B1BFA7C50B699AC61D2. Note that, to | ||
| + | import this key, one must copy and paste the key in ASCII from the Keyserver | ||
| + | website to a file or console and use the command "gpg --import" | ||
| + | technical problem, Using "gpg --recv-key" | ||
| + | work. | ||
| + | |||
| + | c. This is a special dummy public key with its User-IDs and subkeys stripped | ||
| + | that we specifically created, leaving only a " | ||
| + | E-mail address, "Kikek < | ||
| + | allowing the subsequent import of additional subkeys. | ||
| + | |||
| + | d. Next, with the stub key already imported, obtain the public key from | ||
| + | https:// | ||
| + | Because the dummy key with its stub User-ID is already in presence, it's | ||
| + | now possible to import the https:// | ||
| + | |||
| + | e. Use the latest GnuPG in most operating system, the signatures made by | ||
| + | persmule' | ||
| + | |||
| + | 3. To verify vimacs' | ||
| + | |||
| + | a. Obtain the public key from any traditional OpenPGP Keyserver, such as | ||
| + | https:// | ||
| + | is 0x7079B481F04B5D8B65A0ECDEEA2DB82FE04A9403. | ||
| + | |||
| + | b. Use the latest GnuPG in any operating system. | ||
| Proof of Freshness | Proof of Freshness | ||
| Line 74: | Line 126: | ||
| $ rsstail -1 -n5 -N -u https:// | $ rsstail -1 -n5 -N -u https:// | ||
| - | Commuters drag Extinction Rebellion protester from roof of train as activists target Tube | + | Ukraine: The Latest - the worlds most trusted |
| - | | + | Teenagers arrested after nursery cyber attack |
| - | | + | Blizzard traps nearly 1,000 hikers on slopes |
| - | ' | + | BBC Breakfast boss cleared of bullying allegations |
| - | Pictures | + | |
| $ rsstail -1 -n5 -N -u https:// | $ rsstail -1 -n5 -N -u https:// | ||
| - | Blow to Boris Johnsons Brexit Plan as He Heads to Brussels | + | Live Updates: Hurricane Melissa Makes Landfall in Cuba After Lashing Jamaica |
| - | | + | |
| - | Japan Spent Mightily to Soften Natures Wrath, but Can It Ever Be Enough? | + | |
| - | Moroccos King Pardons Journalist Sentenced on Abortion Charge | + | As the Dutch Vote, One Issue Carries the Day: Affordable Housing |
| - | Where Pugs Rule the Racetrack | + | How the Opium War Still Shapes Xi Jinpings Trade Clash With Trump |
| $ date -R -u | $ date -R -u | ||
| - | Thu, 17 Oct 2019 08:03:49 +0000 | + | Wed, 29 Oct 2025 11:38:36 +0000 |
| -----BEGIN PGP SIGNATURE----- | -----BEGIN PGP SIGNATURE----- | ||
| - | iQIzBAEBCgAdFiEE3n2KYOSW/ | + | iHUEARYKAB0WIQRlsdhNDMVQSujfnGCovW2B2flWVAUCaQH8zQAKCRCovW2B2flW |
| - | QYQ0MA/ | + | VMCuAQCd1n+wRINm2wuv9B7KEPXEMrzurbZdQSPK7Lqup85NKQD+I2XMM9Atsw7N |
| - | BnA2wv2t4Ewfl2nRm3wADzw57otvOOPof61hwO3f5JPP/ | + | ClV3HfGuTR2S8Cy7C72v+B8vo1yFMAY= |
| - | wYXwWPIz7ejPaPw4iUtHN6OKcRDcuzUxAzR5FN/ | + | =JtMJ |
| - | A5OK0yq021xcwQ3yy0cbSjOsbgTJndCVbmO3bOPpvJHo6BLRxG39IdA4uckHkG4W | + | |
| - | no/ | + | |
| - | p+LUmJaPMsJt/ | + | |
| - | 2x4F5anW68XKD+wl8ltg/ | + | |
| - | HUWvupK6HGVhOPDRSO/ | + | |
| - | 5DuefmZOZtMMiq+JsAF047KeFt1jf/ | + | |
| - | io5uktGLfNLOguZLTlorwR4Iit1ElE6Y+HkUm7nFUAxaD9WMZ37Cp9iBKNfo3SOz | + | |
| - | RHyciGwLxa2idSc1qU3OzYUSXF/ | + | |
| - | =25rr | + | |
| -----END PGP SIGNATURE----- | -----END PGP SIGNATURE----- | ||
| </ | </ | ||