- he forgot his password
- he lost his private key
- he knows more than he can tell us
http://pgp.mit.edu:11371/pks/lookup?search=schneier&op=index
http://www.theguardian.com/world/2013/sep/05/nsa-how-to-remain-secure-surveillance
1–10 of 144 posts
- he forgot his password
- he lost his private key
- he knows more than he can tell us
http://pgp.mit.edu:11371/pks/lookup?search=schneier&op=index
http://www.theguardian.com/world/2013/sep/05/nsa-how-to-remain-secure-surveillance
Edit: I am located in the North Eastern part of the US.
Edit 2: perhaps we need a geolocation aware social network a la Square but just for notifying you of other nearby PGP users...
Anyone know of a good tutorial for revoking and recreating your key as painlessly as possibly?
* Generate the new key
* Sign the new key with the old key
* Generate the revocation cert for the old key
* Push the revocation publicly with a reason of "Superseded by (fingerprint of new key)" or similar
* Push the new key
* Try to get your new key signed by everyone that signed your old key for authenticity's sake
I'm not too sure how the community of GPG users out there sees key revocation socially, so you may or may not want to bother with that bit. Perhaps hold off on pushing the revocation until the new key has been in use for a while?Anyone know of a good tutorial for revoking and recreating your key as painlessly as possibly?
The tricky bit is just to get your friends to sign your new one, you'll have to re-do all of that work
So I have a GPG key. I used it a couple of times. Currently, it's most useful to me to sign my own Debian package repository. However, I can't seem to figure out how to get into the whole Web of Trust thing. Nobody I know has their own GPG/PGP key that they use and have signed by others and tools like BigLumber and other places where I looked for key signing parties have not turned up any results. I not spending all…
If you're near a university or work somewhere in tech you'll probably be able to find a DD within a degree or two in your network.
So I have a GPG key. I used it a couple of times. Currently, it's most useful to me to sign my own Debian package repository. However, I can't seem to figure out how to get into the whole Web of Trust thing. Nobody I know has their own GPG/PGP key that they use and have signed by others and tools like BigLumber and other places where I looked for key signing parties have not turned up any results. I not spending all…
You might be able to find a nearby willing Debian developer https://wiki.debian.org/Keysigning/Offers#US If you're near a university or work somewhere in tech you'll probably be able to find a DD within a degree or two in your network.
- he really doesn't use his PGP key all that often, had the same one for 16 years on god knows how many computers, and decided that if he's going to generate a new one, he might as well send a message with it.
Or: - he really doesn't use his PGP key all that often, had the same one for 16 years on god knows how many computers, and decided that if he's going to generate a new one, he might as well send a message with it.
(and to be clear, my intent is not to bait, i'm actually curious)