Building a PGP web of trust that people will actually use
bitcoinism.blogspot.nl
bitcoinism.blogspot.nl
Why would we assume that? I can think of a few other use-cases:
* I want to verify the PGP keys used to sign packages in some GNU/Linux distribution
* I want to verify the keys used by anonymous remailers (or at least a PGP key used to sign a mixmaster / mixminion pub key)
* I want to verify the PGP key used by a business to sign official messages (such businesses do exist, as I found out a few months back)
It is also wrong to think that the purpose of the web-of-trust is to unambiguously or unimpeachably map public keys to anything. The web-of-trust is a heuristic that makes a particular kind of impersonation more difficult, so that PGP is more convenient to use. If you need something unambiguous you need to manually verify keys (which most people do anyway).
Personally I think this has been a problem with many security systems so far. You can't be 100% confident about anything, so building a system in which that is a fundamental element is doomed to fail. See also the SSL/TLS cert system, in which it is assumed that you 100% trust all the cert vendors in your key store, absurd even before we consider the default key store inflation over the years. If WoT is going to work, it's going to have to have some concept of levels of trust. I'm willing to sign my wife's key with the highest authority I can give. I'm willing to sign the dev I meet at some meetup and who definitely seems to have the same personality and knowledge as the guy I know online with a medium degree of trust. I'm willing to sign other people with low degrees of trust.
Sure, dealing with the consequences of partial trust are difficult. But since you can't have full trust, it is in less difficult than our current systems based on it, inasmuch as a thing that is possible is less difficult than a thing that is not possible.
I don't really think the PGP WoT can "unambiguously and unimpeachably" provide that mapping, or is even intended to. At best, I think that the WoT documents trust relationships between entities with keypairs.
I actually really like this feature of the WoT, because I think it does a good job of simulating the actual trust relationships between people in real life. In a private conversation, I might imagine a friend vouching for someone another person as trustworthy; a key signature from my friend does something similar, in a secure fashion. This is good because I don't want my web of trust or social network to be able to say "this key is certain to be trustworthy": after all, it can't actually guarantee that. But I don't mind seeing trust opinions from my friends, and their friends' friends.
If anything, I think the trust relationships in GPG ("unknown", "marginal", "full") are too unclear, and I know that these numbers mean different things to different people. I'd prefer the ability to add a short note to the signature so I could say something like,
"I know this person well and you can be confident that this key is theirs, but I don't think they're careful enough to trust their signatures."
If someone sends you an email and you partially trust the key, how does that map to the contents of the email? How does it map to executable code? Source code? Images? Digital signatures?
It's like saying some people's trust is a square circle. It's a correct sentence but it doesn't map to any meaning usefully.
Different purposes: "Do I trust that this key correctly identifies this person?" is a separate question from "Do I trust this person to do proper verification before signing others' keys?" (i.e., trusted link in the Web of Trust)
Different validity: "I've met this person and verified they own the key", is different from, "They've identified themselves with two forms of government ID", is different from "I've known them all my life".
Trust grows organically as your interact with others. Our computational model of "trust" needs to work the same way.
Part of the problem with existing web-of-trust usability is that it makes "trust" too explicit and coarse. It would make more sense to tell the user "this message is signed by the same person you've had 70 conversations with before, and who has liked 40 of your photos" or "this message is signed by someone you've never interacted with before, but they have a long history of interacting with your friends X, Y, and Z".
A possible solution to this could be to use "partial disclosure" of attributes associated with an identity. In an authentication scenario, the server learns the attributes I disclose (or a function there of), and nothing else. I think this is called a "zero knowledge proof". If I have to prove to an authority that the I am over 18, I could reveal only the answer to ((me.date_born - time.now()) > 18 yrs) and not my actual birth day.
This idea was invented and developed by Prof. Stefan Brands who was at McGill at some point, but then started a company around the technology. Later Microsoft bought them.
http://arstechnica.com/information-technology/2010/03/micros...
http://en.wikipedia.org/wiki/U-Prove
Now the tech is open sourced under an Apache License:
https://uprovecsharp.codeplex.com/SourceControl/latest#UProv...
It seems they've just released a web interface for it:
https://retroshareteam.wordpress.com/2013/08/29/retroshares-...
What makes you say that?
Personally, I found it to be very user friendly. You just exchange your public keys with your friends and your all set.
As with many problems, the tech isn't the issue, it's the social side of things.
On the positive side the guardian project is working on a full port of gpg, and see to be making good progress, https://guardianproject.info/code/gnupg/.
"We also need to take advantage of mobile computing technology. Secure key exchange has to occur through tamperproof channels... The rest of this proposal assumes that we can trust the hardware we own. This is a known-false assumption, and an urgent problem, but solving it is something that will have to be handled via other efforts."
But wait, the smartphone is not a tamperproof channel, and this borks the proposed scheme. Unless you've rooted your mobile, it is subject to remote control by the vendor. The attack mode would be swapping a public key, then you're talking to someone other than whom you think you're talking to.
A desktop or mobile, running "Free" software, can be in practice secure enough for reasonable trust, but not a captive phone.
Kudos on the effort to get WoT going, tho - we really need it as the CA scheme has been a house of cards.
"Unless you've rooted your mobile, it is subject to remote control by the vendor."
... in fact, even if you have rooted your mobile, depending on the baseband processor and how it is implemented, the carrier may still have complete control - as in, DMA control - of your device.
Yeah, but there's a reason why rms uses a MIPS laptop; it's extremely difficult to find a full machine that can run completely on Free Software, and the non-free parts are often critical (kernel-level drivers and firmware).
First naive thought for a fix (if it is indeed a problem):
- Keys managed by phone (assuming phone is trustable)
- phone displays some signed fact as, for example, a QR code, for the 1st person 'exchanging' keys.
- 2nd person in the WoT transaction takes a photo of 1st person holding QR display up next to face.
- <insert CV/Facial Recognition/Mapping/Whatever Magic + QR code analysis>
- repeat for 2nd party, with roles reversed.
that and being misunderstood, both design and some functionalities
And I say this as somebody who uses PGP many times a day.
WoT does feel a bit like tying all the metadata to a cryptographically strong identity.
Of course, this reduces the utility of the web of trust, but within the current design of PGP this tradeoff is inevitable.