User Tools

Site Tools


blug-canary-1

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision Both sides next revision
blug-canary-1 [2019/10/30 16:29]
BLUG Admin
blug-canary-1 [2019/11/30 15:50]
Tom Li
Line 15: Line 15:
 ==================================== ====================================
  
-Issued for October 2019.+Issued for November 2019.
  
 Don't just trust the contents of this file blindly! Verify the Don't just trust the contents of this file blindly! Verify the
Line 23: Line 23:
 ~~~~~~~~~~~~~ ~~~~~~~~~~~~~
  
-* biergaizi: 0xFAD3EB05E88E8D6D +* biergaizi: 0x255211B2395A5A3E0E48A0F1FAD3EB05E88E8D6D 
-* persmule : 0x2987A25DAC8454A5 +* persmule : 0xEDFFE248ECFACDE3C805906804A40D21DBB89B60 
-* wnereiz 0xFDFF2E13AA25BE72+* wnereiz 0x0A6A91990AC98712274AA18DFDFF2E13AA25BE72
  
 THREE DOCUMENTS IN TOTAL. THREE DOCUMENTS IN TOTAL.
Line 62: Line 62:
 8. Our personal safety and security is not threatened. 8. Our personal safety and security is not threatened.
  
-9. To avoid security breaches and emphasize the clarity of the warrent canary+9. To avoid security breaches and emphasize the clarity of the warrant canary
 documents, if a signer is temporarily unavailable, only existing signers in the documents, if a signer is temporarily unavailable, only existing signers in the
 "Signer" list SHALL sign a special placeholder notice (this notice itself SHOULD "Signer" list SHALL sign a special placeholder notice (this notice itself SHOULD
 NOT be considered a valid canary document) until the signer becomes available NOT be considered a valid canary document) until the signer becomes available
-again and signs the missed documents. A new signer SHOULD NOT sign a warrent+again and signs the missed documents. A new signer SHOULD NOT sign a warrant
 canary document only due to the temporary unavailability of a existing signer. canary document only due to the temporary unavailability of a existing signer.
  
Line 76: Line 76:
 ~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~
  
-None.+1. Since mid-October, persmule's old signing key 0x2987A25DAC8454A5 has 
 +expired. A new key, 0xEDFFE248ECFACDE3C805906804A40D21DBB89B60, has been 
 +created and uploaded to https://keys.openpgp.org/, it can be obtained from 
 +this keyserver. 
 + 
 +2. The new key will be used by persmule to sign future warrant canary 
 +documents. You can verify the signature by crosschecking the other two 
 +documents signed by biergaizi and wnereiz for consistency. 
 + 
 +3. Due to this key rollover, the October message was not signed by persmule. 
 +This did/does not indicate a security incident, all of the statements above 
 +were valid, and are still valid. 
 + 
 +4. Recent attacks on OpenPGP keyservers have raised great security concerns 
 +within the community, as a countermeasure, persmule's personal User-ID has 
 +not published to the https://keys.openpgp.org/ keyserver. Instead, only 
 +cryptographic information can be obtained from the keyserver, without any 
 +User-ID. Currently, it's impossible to import a OpenPGP public key without 
 +User-ID to a standard GnuPG installation, as a result, it's not possible 
 +for a 3rd-party to verify the canary document signed by persmule. 
 + 
 +5. We are looking for a solution. But for now, we decided that the best 
 +option is starting publishing new canary documents using the new key. 
 +As a temporary measure, you can check the canary documents signed by 
 +biergaizi and wnereiz to decide the validity of the Statements. By signing 
 +their own copies, it indicates that the new key has been verified privately 
 +by them as valid. 
 + 
 +6. This effectively reduced the number of signers to two people. It reduces 
 +the level of confidence, but currently there is no alternative option yet. 
 + 
 +7. Once the technical problem of OpenPGP public key without User-ID is 
 +resolved, you can check the previous signatures retroactively, and this 
 +would effectively restore the level of confidence. You can archive 
 +persmule's signature as soon as it's published to your own machine to 
 +ensure no data tampering has occured. 
 + 
 +8. Unlike persmule, biergaizi and wnereiz's signing keys are unchanged, 
 +but the Key-IDs have been changed to its full fingerprint format in the 
 +canary document for clarity. 
 + 
 +9. When new information is available, it will be published in the "Special 
 +Announcements" section in future warrant canary documents.
  
 Proof of Freshness Proof of Freshness
Line 82: Line 124:
  
 $ rsstail -1 -n5 -N -u https://www.telegraph.co.uk/news/rss.xml $ rsstail -1 -n5 -N -u https://www.telegraph.co.uk/news/rss.xml
- Grenfell TowerDany Cotton refuses to resign after damning report demands 'urgent actionagainst London Fire Brigade + London Bridge attackUsman Khan was studentand personal friend of Anjem Choudary 
- Halloween 2019: How Celtic trick-or-treating and Gaelic turnip-carving led to the American celebration + 'A beautiful spirit who always took the side of the underdog'London Bridge victim named as Jack Merritt 
- Clutha helicopter crash caused by pilot taking 'a chance' low fuel warnings were wronginquiry finds + Cyprus farmers warn of halloumi shortages over EU protection plans 
- Grenfell Tower report: Fire union chief hits back at 'back-to-frontcriticism saying ministers are 'evading scrutiny' + Europe becomes cocaine exporter as countries overflow with drug 
- Grenfell Tower report section by section: the 1,000 pages of damning criticism on failures that compounded tragedy+ Crossbow killer51, who shot his heavily pregnant ex-wife in 'evilrevenge attack jailed for 33 years
  
 $ rsstail -1 -n5 -N -u https://rss.nytimes.com/services/xml/rss/nyt/World.xml $ rsstail -1 -n5 -N -u https://rss.nytimes.com/services/xml/rss/nyt/World.xml
- Vietnamese Migrants Sought Brighter Future in Britain. Now, Their Families Mourn Them + Students Fainting From Hunger in Venezuelas Failing School System 
- Grenfell Tower Inquiry Criticized for Faulting Fire Brigade + For Filipino Seafarers, Lonely Life Celebrated in Song 
- Militants Kill 5 Laborers in Kashmir, Expanding Threat to Civilians + How an Anti-Brexit London District Could Help Boris Johnson Triumph 
- An H.I.V. Outbreak Puts Spotlight on Pakistans Health Care System + Spains Leftist Outsiders Are on the Verge of Getting Inside 
- Britain to Hold Election in December, Opening New Phase in Brexit Odyssey+ Stabbings Around London Bridge Kill 2 in Terrorist Incident
  
 $ date -R -u $ date -R -u
-Wed, 30 Oct 2019 16:28:27 +0000+Sat, 30 Nov 2019 15:48:22 +0000
  
 -----BEGIN PGP SIGNATURE----- -----BEGIN PGP SIGNATURE-----
 Version: GnuPG v2 Version: GnuPG v2
  
-iQIzBAEBCgAdFiEEJVIRsjlaWj4OSKDx+tPrBeiOjW0FAl25ulEACgkQ+tPrBeiO +iQIzBAEBCgAdFiEEJVIRsjlaWj4OSKDx+tPrBeiOjW0FAl3ij1UACgkQ+tPrBeiO 
-jW3mVw/9F1LMoODRWmEIQeD5VPIWJwwp33Rt53WuYIBCA2yK1dtLKWj+fO8tBkq8 +jW1ePA/7B0KjWXQU6bMlzrh9HggghVmRMju6d0Ox43UYa2jAKkG/XfxWk6h33kH1 
-rLAwBcL4JFgAcdqJT6SpB/GC8XukKgXFiIJjvHfRhXt6ZefMvAbaJDJ44dRKQx5k +EZQu6HCTvUTJ3sygxWzJDapTM/8+lOhJ+SE1qCWYheeDuY9auvJaqXLDHMJ3ey7X 
-eokxlbsLhvBqksa3BP0EF+1wRwMZghe09YXY64wm+ebEb+SjWkFblYEhk4KvVBoO +ABPWJFWgEnJK42E/BTqHPirOPOaD1XOcbsqw8NCrKmqt4ijR8SD3JsTJRZS6EtKw 
-cNDdK7rsGLoh1B4qt2N2W4WES9NJaFqHqy+iafYRbZya9pa/zHBFSK+cRDxioZsi +sYjSvwdFOv3SBza0nrCiOxisb2Pq48S5jk0LVCcod8i1hvVG1v9kSupzQJGMuswp 
-X51U60Ntt50rq+nEtoH4qqIQYcSZ1PMPkmkkF7M/VQ3lhzQownv6fYRhq/jeyz0a +SItYWz9JogO7s1V3GTn2rTp8kNtzo3QBINXU0dMv8o++rz1dwP1K9jh3E1LP3kNX 
-fW7Bmfl9SaJTeTcegPjrh/v+yUL5PC7ZjjsXIEVNS0L3SaNatVnxuVC0HvcXziZa +dbEMC8FRUFbKi9psL+LVHkchrdWJ9lIOUJy/6mUKc9+xlNkqyBLQHZI930qF4hYZ 
-BPsWjv6qBbQBCVjSkv0yU6zfXlNAzGRhJLXXTSulraEs0hUoeIsdC8IbQ2KkvXSt +nY6KF0UsBlEan8BJEF2CjJ8pM9JkuQH33Ek9jtNDZoC1OAH0YUJSDyhkCthW6NDT 
-cySvJw85UZSyCJCJ+AQdJ8Hbg+4OvhRB2trT1skmRUZeKL9aM0XEB3ByXIBmBf+q +o1DcFPZ/BaaBOooGtg9i/Hb81o0Rsft8atzPOyJH8DaNp2MD2dA7Sz2yWJG6yDAL 
-+zsDLTylDwSLRIaoGHFTXJRKUzV1AAr6KWfq0WitX5aAILKEBm/0vAlVlc6pnhh8 +kAi7ZOMSndxthpvvNbBobCKU9brCQzkNeL/0ZJS+nBkhqWwNilnp/WsxKcrwwF7s 
-7B4SmUM4Ame6CdVDcOjjPD8FZkRxvTzcsFB7jGEMMrQMVQJCdJr/o6oJ3keTeu9L +7SFkXX7ZBY8qhQsDr7QHx0IWJitpwABFqfVZ1Wy8RCz9LGaEa1U84bu3cdaUVNjC 
-5abIthywfFa3mIWL2GDcc8inYFPOGFUbaiaPUBrjuqTYPdpV1H8+qmc89M6GblgJXSQOeTCaspcuWR+x4VGuOX8mOzBs65tmmsm4YY0
-=RMwa+=7+YM
 -----END PGP SIGNATURE----- -----END PGP SIGNATURE-----
 </code> </code>
blug-canary-1.txt · Last modified: 2024/02/29 07:33 by BLUG Admin