User Tools

Site Tools


blug-canary-3

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
blug-canary-3 [2019/11/19 19:21]
wnereiz
blug-canary-3 [2019/11/23 08:57] (current)
wnereiz
Line 16: Line 16:
 ~~~~~~~~~~~~~ ~~~~~~~~~~~~~
  
-* biergaizi: ​0xFAD3EB05E88E8D6D +* biergaizi: ​0x255211B2395A5A3E0E48A0F1FAD3EB05E88E8D6D 
-* persmule : 0x2987A25DAC8454A5 +* persmule : 0xEDFFE248ECFACDE3C805906804A40D21DBB89B60 
-* wnereiz ​ : 0xFDFF2E13AA25BE72+* wnereiz ​ : 0x0A6A91990AC98712274AA18DFDFF2E13AA25BE72
  
 THREE DOCUMENTS IN TOTAL. THREE DOCUMENTS IN TOTAL.
Line 55: Line 55:
 8. Our personal safety and security is not threatened. 8. Our personal safety and security is not threatened.
  
-9. To avoid security breaches and emphasize the clarity of the warrent ​canary+9. To avoid security breaches and emphasize the clarity of the warrant ​canary
 documents, if a signer is temporarily unavailable,​ only existing signers in the documents, if a signer is temporarily unavailable,​ only existing signers in the
 "​Signer"​ list SHALL sign a special placeholder notice (this notice itself SHOULD "​Signer"​ list SHALL sign a special placeholder notice (this notice itself SHOULD
 NOT be considered a valid canary document) until the signer becomes available NOT be considered a valid canary document) until the signer becomes available
-again and signs the missed documents. A new signer SHOULD NOT sign a warrent+again and signs the missed documents. A new signer SHOULD NOT sign a warrant
 canary document only due to the temporary unavailability of a existing signer. canary document only due to the temporary unavailability of a existing signer.
  
Line 69: Line 69:
 ~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~
  
-None.+1. Since mid-October,​ persmule'​s old signing key 0x2987A25DAC8454A5 has 
 +expired. A new key, 0xEDFFE248ECFACDE3C805906804A40D21DBB89B60,​ has been 
 +created and uploaded to https://​keys.openpgp.org/,​ it can be obtained from 
 +this keyserver. 
 + 
 +2. The new key will be used by persmule to sign future warrant canary 
 +documents. You can verify the signature by crosschecking the other two 
 +documents signed by biergaizi and wnereiz for consistency. 
 + 
 +3. Due to this key rollover, the October message was not signed by persmule. 
 +This did/does not indicate a security incident, all of the statements above 
 +were valid, and are still valid. 
 + 
 +4. Recent attacks on OpenPGP keyservers have raised great security concerns 
 +within the community, as a countermeasure,​ persmule'​s personal User-ID has 
 +not published to the https://​keys.openpgp.org/​ keyserver. Instead, only 
 +cryptographic information can be obtained from the keyserver, without any 
 +User-ID. Currently, it's impossible to import a OpenPGP public key without 
 +User-ID to a standard GnuPG installation,​ as a result, it's not possible 
 +for a 3rd-party to verify the canary document signed by persmule. 
 + 
 +5. We are looking for a solution. But for now, we decided that the best 
 +option is starting publishing new canary documents using the new key. 
 +As a temporary measure, you can check the canary documents signed by 
 +biergaizi and wnereiz to decide the validity of the Statements. By signing 
 +their own copies, it indicates that the new key has been verified privately 
 +by them as valid. 
 + 
 +6. This effectively reduced the number of signers to two people. It reduces 
 +the level of confidence, but currently there is no alternative option yet. 
 + 
 +7. Once the technical problem of OpenPGP public key without User-ID is 
 +resolved, you can check the previous signatures retroactively,​ and this 
 +would effectively restore the level of confidence. You can archive 
 +persmule'​s signature as soon as it's published to your own machine to 
 +ensure no data tampering has occured. 
 + 
 +8. Unlike persmule, biergaizi and wnereiz'​s signing keys are unchanged,​ 
 +but the Key-IDs have been changed to its full fingerprint format in the 
 +canary document for clarity. 
 + 
 +9. When new information is available, it will be published in the "​Special 
 +Announcements"​ section in future warrant canary documents.
  
 Proof of Freshness Proof of Freshness
Line 75: Line 117:
  
 $ rsstail -1 -n5 -N -u https://​www.telegraph.co.uk/​news/​rss.xml $ rsstail -1 -n5 -N -u https://​www.telegraph.co.uk/​news/​rss.xml
- RSPCA use CSI-style bone marrow test for first time to prove dog owner drowned petcourt hears + Iran's internet blackout: What is happeningand why did the government turn it off? 
- Sweden drops rape investigation into Wikileaks founder Julian Assange + Pictures of the Day: 23 November 2019 
- Chip shop owner accused of killing wife by covering her in boiling oil is cleared of murder + Colombia protests: President Duque imposes curfew ​in Bogota to shut down unrest 
- Mike Ashley accused of overturning a fur ban at House of Fraser + Strictly Come Dancing'​s Anton du Beke says he would welcome same-sex pairings 
- Donald Trump impeachment hearing: Witness speaks of alarm at 'demand' ​issued to Ukraine president+ Sacha Baron Cohen hits out at social media 'propaganda'
  
 $ rsstail -1 -n5 -N -u https://​rss.nytimes.com/​services/​xml/​rss/​nyt/​World.xml $ rsstail -1 -n5 -N -u https://​rss.nytimes.com/​services/​xml/​rss/​nyt/​World.xml
- Parents ​of Besieged ​Hong Kong Protesters Come to the Front Lines + The Jungle Prince ​of Delhi 
- On Israeli SettlementsU.S. Cant Rewrite International Law, Palestinians Say + The Broken Promise of a Panda: How Pragues Relations With Beijing Soured 
- Two Western Hostages ​Are Freed in Afghanistan in Deal With Taliban + ​Would-Be Chinese Defector Details Covert Campaigns in Hong Kong and Taiwan 
- ​Sweden Drops Julian Assange Rape Inquiry + Israelis Call Netanyahu Indictment an Earthquakebut Agree on Little Else 
- ​Israel Intercepts Four Rockets Launched From Syria+ The World Burns All Year. Are There Enough Planes to Douse the Flames?
  
 $ date -R -u $ date -R -u
-Tue19 Nov 2019 19:21:16 +0000+Sat23 Nov 2019 08:55:34 +0000
  
 -----BEGIN PGP SIGNATURE----- -----BEGIN PGP SIGNATURE-----
  
-iQIzBAEBCgAdFiEE3n2KYOSW/​nkFgy0Or5D/​NPDHQYQFAl3UQLYACgkQr5D/NPDH +iQIzBAEBCgAdFiEE3n2KYOSW/​nkFgy0Or5D/​NPDHQYQFAl3Y9C4ACgkQr5D/NPDH 
-QYTlJw//​Q5HIDV5RedESdJzT/​rw2jeZKwu9H19K0uIZqUOLR2ucoYSqJDzLSGeaJ +QYSCUBAAkNAoyik1JwUhiqWHZppGfXjK381EJS8xFvxPGn+UN+wsHKfq/jw8yO6i 
-WAOk3VbXFzuJzWC38iNrp1jLY/​Ph/​E/​6jEutdIJaQNWK3Q1tarGMpxM/JbAVea0d +IQ3eoYp6n5/L1mEXYgnAs8YlCxOd4ofaNZi0pfw9HSgSee1zbOUPNjraKS9oZrDC 
-qu73a9V2ly6tAnWaWhOxmM0qTKDFHPweAYyVwUAtVh5+cZp4sGhei+PO+KQTnevR +zkz5wTVe1kuwm3dsusoatsPli9c2XhOaGmD0zDA6sfL5jNN+Zhf91m9RQs79nSy7 
-kZdCOZWSNtD2JB6Ghm7a1CgZpoDAhiegO9Y2dPzkZqYtpCGXhJZFQaBZVL5FVtiS +GsX+8qylhuYuEmJTkBW070tL2njNIcpjt4VA5rlxvz2fvjaIiyG03UVJ3NIAfecV 
-LgjpV8/​RdElMAfAJerx7Jj0ebCxDA+Vivi9FDEdcBq6behbiujbX6bYGZU+FoaTp +NFIuEXEi0IdogQ3SqmEFwSa8cK/z34mS9D2apc7x3gkBc9Bw+/SRJ5HSULsLEMtZ 
-J4njgwhsb0ErakrU4G9CDzJLAIziDCdrNWLFO82b0XK9xidMXIxQWfu84NpydHhS +/JK85YblrS4IlioBe8czqbgw9GWMfFgaTEov3M0s4gYVkXx+JAnMxtxtzfkvKWwO 
-i7/​ecepHLJONZ/​80Ht8/kcpyo2l4YscuoWGcYgV0BjJgBR6U6HjGg+/5GQzC3dmE +64LMglIcsk58V9s6b4H3EFojafBWCf6mJP8tvU3HVsVzN1CeRXTOgEBR9mrCFCy3 
-WJwVOLWdxFLjNv2fzm/euhMuy4WxaNAk0dMoIQykAz5+8pWhivrrMsCnD8WN0c0a +XuQkvtsBGAMhyXd7aez2n5MEgWg0fn67hwauhVFxbmIJxW6gwtaqQP5SyfjUscoN 
-HUzX5MwpiF2ERrhR/​5eavfuAcm8qfs9IxHJDD/N7sOYR8Kl8r71dlm1jh+RYVNuG +E8/LZxSNQlgoEljl92QzjBxBHhbrWh6ntsAkGxVzpZlWqAaLE3hZb3tHPI+bpnQL 
-HNIvpyhwuCMcsziipLKgGBHIaERio65GTi9SDhL8alSfGJCOUPgjgxPQd4ap7dYu +a1tsBy9skLR3ALVq618zVY0dCBANrsjN4id0u1dRZNFvBBOy/​fkbMrTZ84tFq74r 
-E+qcMI4qXqkmoWBkA8rOJMu2NwM1+zP1nOm3VVvlhicMmtzuc5E+aDXGBklgZC4akOpbqGg9qO14Jer0c3jCcUtkDaTidCjNHdsQN8k
-=yokA+=Myog
 -----END PGP SIGNATURE----- -----END PGP SIGNATURE-----
 </​code>​ </​code>​
  
blug-canary-3.txt · Last modified: 2019/11/23 08:57 by wnereiz