Live data from Hacker News

Bruce Schneier has changed his PGP key to 4096 bits

news.ycombinator.com

1–10 of 144 posts

Bruce Schneier has changed his PGP key to 4096 bits

#1
He decided to change his 16-years old 2048-bit key on the same day he let the world know he was working on Snowden files. Possible reasons:

- he forgot his password

- he lost his private key

- he knows more than he can tell us

http://pgp.mit.edu:11371/pks/lookup?search=schneier&op=index

http://www.theguardian.com/world/2013/sep/05/nsa-how-to-remain-secure-surveillance

Re: Bruce Schneier has changed his PGP key to 4096 bits

#3
So I have a GPG key. I used it a couple of times. Currently, it's most useful to me to sign my own Debian package repository. However, I can't seem to figure out how to get into the whole Web of Trust thing. Nobody I know has their own GPG/PGP key that they use and have signed by others and tools like BigLumber and other places where I looked for key signing parties have not turned up any results. I not spending all my free time looking for GPG users, but I have spent what I feel is more than a casual amount of time looking for people to exchange key signatures with. What do y'all do for this? Any advice?

Edit: I am located in the North Eastern part of the US.

Edit 2: perhaps we need a geolocation aware social network a la Square but just for notifying you of other nearby PGP users...

Re: Bruce Schneier has changed his PGP key to 4096 bits

#4

Anyone know of a good tutorial for revoking and recreating your key as painlessly as possibly?

I'd imagine the process works something like this:

   * Generate the new key
   * Sign the new key with the old key
   * Generate the revocation cert for the old key
   * Push the revocation publicly with a reason of "Superseded by (fingerprint of new key)" or similar
   * Push the new key
   * Try to get your new key signed by everyone that signed your old key for authenticity's sake
I'm not too sure how the community of GPG users out there sees key revocation socially, so you may or may not want to bother with that bit. Perhaps hold off on pushing the revocation until the new key has been in use for a while?

Re: Bruce Schneier has changed his PGP key to 4096 bits

#5

Anyone know of a good tutorial for revoking and recreating your key as painlessly as possibly?

I'm sure the man page for gpg can tell you the command line incantation, but I use https://gpgtools.org/ for mac which just has "make key" and "revoke key" buttons.

The tricky bit is just to get your friends to sign your new one, you'll have to re-do all of that work

Re: Bruce Schneier has changed his PGP key to 4096 bits

#7

So I have a GPG key. I used it a couple of times. Currently, it's most useful to me to sign my own Debian package repository. However, I can't seem to figure out how to get into the whole Web of Trust thing. Nobody I know has their own GPG/PGP key that they use and have signed by others and tools like BigLumber and other places where I looked for key signing parties have not turned up any results. I not spending all…

You might be able to find a nearby willing Debian developer https://wiki.debian.org/Keysigning/Offers#US

If you're near a university or work somewhere in tech you'll probably be able to find a DD within a degree or two in your network.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#8
post #7

So I have a GPG key. I used it a couple of times. Currently, it's most useful to me to sign my own Debian package repository. However, I can't seem to figure out how to get into the whole Web of Trust thing. Nobody I know has their own GPG/PGP key that they use and have signed by others and tools like BigLumber and other places where I looked for key signing parties have not turned up any results. I not spending all…

You might be able to find a nearby willing Debian developer https://wiki.debian.org/Keysigning/Offers#US If you're near a university or work somewhere in tech you'll probably be able to find a DD within a degree or two in your network.

Looks like there is exactly one in my state. I will reach out to him. Thanks.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#10
post #9

Or: - he really doesn't use his PGP key all that often, had the same one for 16 years on god knows how many computers, and decided that if he's going to generate a new one, he might as well send a message with it.

Normally i'd let it go, but i actually would like some clarity on your intent here. Are you implying that Schneier doesn't use encrypted communications on a regular basis, that PGP is impractical, or both?

(and to be clear, my intent is not to bait, i'm actually curious)

Post reply on HN