User Tools

Site Tools


blug-canary-1

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
blug-canary-1 [2019/04/15 07:37]
Tom Li
blug-canary-1 [2024/04/30 16:36]
BLUG Admin
Line 15: Line 15:
 ==================================== ====================================
  
-Issued for March 2019.+Issued for April 2024.
  
 Don't just trust the contents of this file blindly! Verify the Don't just trust the contents of this file blindly! Verify the
Line 23: Line 23:
 ~~~~~~~~~~~~~ ~~~~~~~~~~~~~
  
-* biergaizi: 0xFAD3EB05E88E8D6D +* biergaizi: 0x255211B2395A5A3E0E48A0F1FAD3EB05E88E8D6D 
-* persmule : 0x2987A25DAC8454A5 +* persmule : 0xEDFFE248ECFACDE3C805906804A40D21DBB89B60 
-wnereiz  0xFDFF2E13AA25BE72+vimacs   0x7079B481F04B5D8B65A0ECDEEA2DB82FE04A9403
  
 THREE DOCUMENTS IN TOTAL. THREE DOCUMENTS IN TOTAL.
Line 62: Line 62:
 8. Our personal safety and security is not threatened. 8. Our personal safety and security is not threatened.
  
-9. We plan to publish the next of these canary statements in the first three +9. To avoid security breaches and emphasize the clarity of the warrant canary 
-weeks of April 2019. Special note should be taken if no new canary is +documents, if a signer is temporarily unavailable, only existing signers in the 
-published by that time or if the list of statements changes without plausible explanation.+"Signer" list SHALL sign a special placeholder notice (this notice itself SHOULD 
 +NOT be considered a valid canary document) until the signer becomes available 
 +again and signs the missed documents. A new signer SHOULD NOT sign a warrant 
 +canary document only due to the temporary unavailability of a existing signer. 
 + 
 +10. We plan to publish the next of these canary statements in the first three 
 +weeks of May 2024. Special note should be taken if no new canary is published 
 +by that time or if the list of statements changes without plausible explanation
 + 
 +11. Due to the ongoing security issues of OpenPGP keyservers, it makes signature 
 +verification an issue and somewhat a challenge. For completeness, complete 
 +procedures for canary verification is included here.
  
 Special Announcements Special Announcements
 ~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~
  
-None.+1. We've found a workaround for importing keys on https://keys.openpgp.org 
 +without User-ID. The instructions for verifying persmule's signatures have 
 +been added. 
 + 
 +Canary Verification Procedures 
 +~~~~~~~~~~~~~~~~~~~~~~~~ 
 + 
 +1. To verify biergaizi's signature... 
 + 
 +    a. Obtain the public key from any traditional OpenPGP Keyserver, such as 
 +    https://keyserver.ubuntu.com, and import the public key. The fingerprint 
 +    is 0x255211B2395A5A3E0E48A0F1FAD3EB05E88E8D6D. 
 + 
 +    b. Use the latest GnuPG in any operating system. 
 + 
 +2. To verify persmule's signature... 
 + 
 +    a. Due to the previous attacks on OpenPGP keyservers, persmule has published 
 +    the OpenPGP public key to https://keys.openpgp.org without a User-ID. Using 
 +    the standard method, it's impossible to import a OpenPGP public key without 
 +    User-ID. But since April 2013, we have developed a workaround, described 
 +    below. 
 + 
 +    b. Obtain the dummy public key from any traditional OpenPGP Keyserver, 
 +    such as https://keyserver.ubuntu.com, and import the public key. The 
 +    fingerprint is 0xEDFFE248ECFACDE3C805906804A40D21DBB89B60. Note that, to 
 +    import this key, one must copy and paste the key in ASCII from the Keyserver 
 +    website to a file or console and use the command "gpg --import". Due to a 
 +    technical problem, Using "gpg --recv-key" or "gpg --search-keys" does not 
 +    work. 
 + 
 +    c. This is a special dummy public key with its User-IDs and subkeys stripped 
 +    that we specifically created, leaving only a "stub" User-ID (with an invalid 
 +    E-mail address, "glahamm <yiam5Od@gliwrad.invalid>"). Its sole purpose is 
 +    allowing the subsequent import of additional subkeys. 
 + 
 +    d. Next, with the stub key already imported, obtain the public key from 
 +    https://keys.openpgp.org using the same fingerprint, and import this key. 
 +    Because the dummy key with its stub User-ID is already in presence, it's 
 +    now possible to import the https://keys.openpgp.org public key directly. 
 + 
 +    e. Use the latest GnuPG in most operating system, the signatures made by 
 +    persmule's key can now be verified as usual. Debian is known to work, most 
 +    other systems should work just fine, but not Fedora. The subkeys contains 
 +    signatures made with Brainpool curves, which are disabled on Fedora due to 
 +    potential patent-licensing problems, causing a "Unknown elliptic curve" 
 +    error. 
 + 
 +3. To verify vimacs' signature... 
 + 
 +    a. Obtain the public key from any traditional OpenPGP Keyserver, such as 
 +    https://keyserver.ubuntu.com, and import the public key. The fingerprint 
 +    is 0x7079B481F04B5D8B65A0ECDEEA2DB82FE04A9403. 
 + 
 +    b. Use the latest GnuPG in any operating system.
  
 Proof of Freshness Proof of Freshness
Line 75: Line 140:
  
 $ rsstail -1 -n5 -N -u https://www.telegraph.co.uk/news/rss.xml $ rsstail -1 -n5 -N -u https://www.telegraph.co.uk/news/rss.xml
- Israel launches Gaza strikes after rockets fired at Tel Aviv + Introducing Latest  a new section of your Telegraph app 
- Maternal deaths from C-sections 50 times higher in Africa than UK + Monday evening news briefing: Kate Forbes seriously mulling run to replace Yousaf as SNP leader 
- Lord Steel suspended following admission about Cyril Smith + Friday evening news: King to resume public duties as doctors pleased with cancer treatment briefing 
- Matt Hancock mocked after saying that some nurses still stand up when a doctor enters a room, as NHS worker quips 'it isn't Downton Abbey' + Thursday evening news briefing: Yousafs political future could lie in Alex Salmonds hands 
- President of European Parliament apologises for praising Benito Mussolini's fascist regime+ Wednesday evening news briefing: Teenage girl arrested after two teachers and pupil stabbed
  
 $ rsstail -1 -n5 -N -u https://rss.nytimes.com/services/xml/rss/nyt/World.xml $ rsstail -1 -n5 -N -u https://rss.nytimes.com/services/xml/rss/nyt/World.xml
- Boeing 737 Max Hit Trouble Right Away, Pilots Tense Radio Messages Show + Middle East Crisis: Netanyahu Again Vows to Invade Rafah With or Without Cease-Fire Deal 
- Britains Parliament Votes to Delay Brexit, but Not to Control It + Georgia Bill Targeting Foreign Interests Draws Protests 
- Japan Dispatch: Japans Enchanting Ice Monsters, Claimed by Climate Change + Surrounded by Fighters and Haunted by FamineSudan City Fears Worst 
- Rockets Fired on Tel Aviv From Gazaand Israel Strikes Back + How Capitalists in Communist Cuba Are an Economic Lifeline 
- A Taliban LeaderEyeing U.S. Peace Deal, Speaks to Afghans Fears+ Mali Claims Death of Abu HuzeifaTerrorist Who Helped Lead Fatal Ambush in Niger
  
 $ date -R -u $ date -R -u
-Fri15 Mar 2019 07:35:50 +0000+Tue30 Apr 2024 16:34:02 +0000
  
 -----BEGIN PGP SIGNATURE----- -----BEGIN PGP SIGNATURE-----
-Version: GnuPG v2 
  
-iQIzBAEBCgAdFiEEJVIRsjlaWj4OSKDx+tPrBeiOjW0FAly0NIgACgkQ+tPrBeiO +iQIzBAEBCgAdFiEEJVIRsjlaWj4OSKDx+tPrBeiOjW0FAmYxHZQACgkQ+tPrBeiO 
-jW1WZRAAhwk/SOrR6KJfPcLRKy+ZTN7vmcxk2X52vAtGhUyaUXqc38fhwEuvV9m4 +jW1i1Q/9Exd6Er9/1Kuau3YNnARce6tmrlbSNwK/TOl8Qm22rtXPxqsbtdWccHHQ 
-LDEX4k8r2YyMCvZsa4ApBM7MdiXkk8fNAeg8V7EU0/Py7vpl46KmxgGNht9sk/eR +uz2NuDmIk5ygnxjhy1leGb8XRRimbMKgKL/K6/tdGKUqYXDm+dm/I+g8pwhKmSTe 
-cbmXni4ko8qHMJsRqMcOE1CSWe1biWqMTAo20SFQFgK58fFs/dBjhr5lBxpWS4a1 +8GY/GYPCl52VtG7kwLYw9HzvlwGZrTFWeOuSBqvETZhesxWmXWxEJH4is9vXHLIv 
-qFIBXxIqsrU/RvERQ6km8BaM/8tv3peVYHfKDtb17x4ZIpL/UsEQLX7NiEAvskan +4PPmBZIqscJStKHlo52xJWEb1zd/JGrE1XcPlIoWz4xDGc1c5qC6pcYV5SBADPd5 
-SffS69Hk8DmLGuvp55YQeZgxa05LW1oxMoyq9P+B1dkAxb+RAeupa+oEBWJBLsLl +OT60xdVqvuTKShlyENwQqIR2oCjTBBXIdyMZyrXKxHqPKk4UKyrcQI2L5S4CX9xk 
-9wZRyvKvoxabI2Qcin7+2V1u1I7O5lowd/4hz6elYXPebw52gdi8osA1wiMm/cT1 +pnLqn3vrr7RMLkwo7wFLQQfKfKmp5Z83BdXdcagS9miLOXFi82OOxGKLSzq+KZ/t 
-fyvzdxXjTrU5OW8rWxyhy/RFY4Pkhu1jc7OmJ7chGOEj1o/AMpsS5gnl1d4GyoGV +YWQzYozCFC6uvXNc8WY5EV46Z0E/vUsY5oqZC90aLhS1TDwl/7Bh2u/jVtlsdpSQ 
-ssUGEA1Ka2oY8NNr7jyaN+ltMcqDN+9yMKwgZcdCK4Cdk/8KAvK59c1kOQWd4mzF +rBtZPyHkywguwFfL/+Cb4XGN7OapdyBscrC6VmyPXb37txEZpqYFMz6duwukJXO4 
-EMO0lU+4sAtosDCpWw3s7IT1xlWbukRh/oc8Sk7rsAmZE95jfXmV0z22I5Xz7IkB +s9WTgX/61DWCusrZLo9RuIIiyGprfGfzb0MOrAU78ePDOZng2CCnXnwT4ErN6pw1 
-qn/R1UZc7YGcdTuRzhpKObSKQoqWnl9kVAI3EqNY6OJbO7bV+EmSANaXV5BnNARV +4xiALByAwvYFPLzuJRlhSxzZPILXSmFrG4zQ6MgbmFX8lcRc1M9dMT23IeO4ZpIg 
-Ek3k6YKnLGndVtrXWQyCctZwqBMOMrEqrdzSQzVgx1wutgmxIMk+FHsfe3tRW87N8PkjJ4hAjbmf9V4206HIEzWPPrpniAxgzAkrp+c
-=LWIQ+=YG7W
 -----END PGP SIGNATURE----- -----END PGP SIGNATURE-----
 </code> </code>
blug-canary-1.txt · Last modified: 2024/04/30 16:36 by BLUG Admin