My understanding of this is that anyone with a copy of anything you've ever signed can revoke your key. I hope I'm misunderstanding.
My understanding of this is that anyone with a copy of anything you've ever signed can revoke your key. I hope I'm misunderstanding.
> If a user can prove that a key belongs to them (by signing a message with their private key) then they are able to remove their public key with no interaction needed from the server operator. Once a key is removed, it is removed from all servers in the pool.
This is a pretty fucking awesome idea.
Alice sends an email to Bob and clearsigns the message. Bob, or anyone else who intercepts the email is now able to paste that message into the form and remove Alice's key from the keyserver.
This could be mitigated by requiring it to be a specific message.
Reading the code, it does indeed allow any signed message: https://github.com/tdjsnelling/dat-keyserver/blob/12fa3e8389...