Live data from Hacker News

Are we self-sovereign PKI yet?

buffrr.dev

51–60 of 92 posts

Re: Are we self-sovereign PKI yet?

#51
post #47
post #36

Earlier quoted context omitted.

Having a public graph is critical for trust in Linux distributions. All it means is a human met you and agreed you are human and signed your key. It does not imply you are friends. It is pretty useful for someone totally outside the trust graph to be able to prove the key that just signed the latest release of stagex is only a couple steps away from the keys that sign debian and the Linux kernel. Keys that long preda…

People are not Linux distributions.

But Linux distributions are made of people.

Re: Are we self-sovereign PKI yet?

#52
post #49
post #45

Earlier quoted context omitted.

Why do I trust the people who are putting their reputations on the line? If they either screwed up or are malicious, I guess I'm just out of luck?

If you can manipulate dozens of Linux maintainers to sign a key maliciously, we have bigger problems. Like a complete failure of the internet. Decentralized human trust, or centralized corporate trust. Pick one.

Again, this works when your userbase is a small group of highly technical people who already have social connections to each other. But then again, so would just swapping Signal security numbers.

It completely and totally collapses in the face of non-technical users or broad adoption, which is one of multiple reasons that PGP remains a thing that a small set of people use.

Re: Are we self-sovereign PKI yet?

#53
post #50
post #44

Earlier quoted context omitted.

This is a fun kind of paradox. Right now it wouldn't scale well because signing parties are a niche nerd activity and having your identities signed by other GPG users doesn't really help with anything you'd want to do with a bot. But if you were to actually succeed in making key signing parties a more common thing that people used to test for human-ness, and that test was tied to meaningful things online, it would bo…

When you sign a key you pick a trust level. If no one reputable has ever trusted a persons key with a higher level than "human", then that key should be subject to significantly higher scrutiny. If you look at my key, you will find it is heavily connected to the keys that sign most linux distributions, bitcoin, and commits to the Linux kernel today. If those 5444 linked identities that long pre-date AI are colluded t…

Yes, that would be the conundrum I was describing. If your plan were to work, the idea of a signer being "reputable" would be watered down into nothing.

Re: Are we self-sovereign PKI yet?

#54
post #52
post #49

Earlier quoted context omitted.

If you can manipulate dozens of Linux maintainers to sign a key maliciously, we have bigger problems. Like a complete failure of the internet. Decentralized human trust, or centralized corporate trust. Pick one.

Again, this works when your userbase is a small group of highly technical people who already have social connections to each other. But then again, so would just swapping Signal security numbers. It completely and totally collapses in the face of non-technical users or broad adoption, which is one of multiple reasons that PGP remains a thing that a small set of people use.

Just to be pedantic about this: it does not in fact work; PGP has failed those kinds of user groups and platforms over and over again over the last 3 decades.

Re: Are we self-sovereign PKI yet?

#55
post #6

> The same key, in every app, for every recipient. Not assignable to anyone else, not revocable, not subject to suspension. Yours forever. This is impractical and the opposite of what we want. It's a required ID to use the internet, monitored by governments, tracked by corporations, and forever unchanging. What we need is a system that allows people to easily create new IDs, that updates contacts that people choose.…

> It's a required ID to use the internet, monitored by governments, tracked by corporations, and forever unchanging.

There are clearly two opposing requirements.

One for anonymity, where people who need to be anonymous can create an identity that is verifiably the same person each time, but not a specific, identifiable, individual. The classic example is journalistic sources.

One for trust and verification, where the identity needs to be absolutely, permanently, associated with a specific individual. Online banking is the classic example here.

I don't think the same system can be used for both.

- If we can create multiple identities without verifying the human each time, as you say "flux and churn", then the second requirement is broken - there is no link between the identity and a verifiable person so the identity can't be trusted.

- If we can't create multiple identities without verifying the human each time, then the first requirement is broken - every identity can be associated with a specific human and there's no anonymity.

We could try some hybrid system where some identities are known people, and others are pseudonymns. But that feels like two systems wedged into the same box. The hard problems of absolutely correctly identifying a human so the second system works is still not solved, and irrelevant to the first system.

You are absolutely correct that the system that identifies individuals is incredibly attractive for states and large corporations, and so incredibly dangerous for actual humans. We need to be very, very, careful with this.

Re: Are we self-sovereign PKI yet?

#57
post #54
post #52

Earlier quoted context omitted.

Again, this works when your userbase is a small group of highly technical people who already have social connections to each other. But then again, so would just swapping Signal security numbers. It completely and totally collapses in the face of non-technical users or broad adoption, which is one of multiple reasons that PGP remains a thing that a small set of people use.

Just to be pedantic about this: it does not in fact work; PGP has failed those kinds of user groups and platforms over and over again over the last 3 decades.

And yet many of the highest risk systems that exist, the whole foundation of the internet, several governments, major corporations, and thousands of high risk individuals rely on it because centralized options will never be agreed to by all parties, for good reason.

I have lost count of the orgs I have personally trained to use PGP properly in recent years.

In spite of your claims, PGP solves the problem it was designed to solve for the groups that need it most and the tooling is getting rapidly more accessible to a wider audience with more development energy today than it has ever had.

This is not 2016 PGP we are talking about anymore.

Re: Are we self-sovereign PKI yet?

#58
post #53
post #50

Earlier quoted context omitted.

When you sign a key you pick a trust level. If no one reputable has ever trusted a persons key with a higher level than "human", then that key should be subject to significantly higher scrutiny. If you look at my key, you will find it is heavily connected to the keys that sign most linux distributions, bitcoin, and commits to the Linux kernel today. If those 5444 linked identities that long pre-date AI are colluded t…

Yes, that would be the conundrum I was describing. If your plan were to work, the idea of a signer being "reputable" would be watered down into nothing.

Well, it is working as intended, right now, and the binaries running on the servers we are communicating with right now were likely signed and validated with Linux maintainer PGP keys because it is the only standard and decentralized option.

PGP does not need mass adoption to function, but with solutions like keyoxide offering a more accessible trust onramp, it is there for anyone that wants to self certify and take control of their own identity today, and get signed by trusted community members tomorrow at a conference.

Re: Are we self-sovereign PKI yet?

#59
post #33
post #2

Great concise description of the problem. As for the solution, it seems to explicitly not address recovery of lost keys/identities, which is however exactly the part that makes this hard for regular users. That, and general name confusion attacks, I suppose: "I'm lxgr17@key, yeah, don't ask about the first 16. Oh also make sure 'key' is not the one with the Georgian lowercase e in the middle, that one's an impostor.…

It's not "hard" for regular users; it's a complete non-starter for regular users. Every "non-custodial" or "self-sovereign" system of trusted identities founders on this issue: account recovery is the hardest problem in identity, and if you don't have a solution for it, your system is going to be a niche at best. People have been coming up with these schemes for decades, and for that entire time, the near-universal d…

Yes, the UI/UX of decentralized systems is so difficult for users that it creates demand for centralized systems to manage it for them, Coinbase, Gmail, Github, Twitter, The Pirate Bay.

Re: Are we self-sovereign PKI yet?

#60
post #57
post #54

Earlier quoted context omitted.

Just to be pedantic about this: it does not in fact work; PGP has failed those kinds of user groups and platforms over and over again over the last 3 decades.

And yet many of the highest risk systems that exist, the whole foundation of the internet, several governments, major corporations, and thousands of high risk individuals rely on it because centralized options will never be agreed to by all parties, for good reason. I have lost count of the orgs I have personally trained to use PGP properly in recent years. In spite of your claims, PGP solves the problem it was desig…

That's a weird thing to say. Yes, it is? What are you claiming is different about it? In fact, there are ways in which it has regressed from 2016's incarnation.
Post reply on HN