[Israel.pm] Keysigning @ YAPC

Yuval Kogman lists at woobling.org
Thu Jan 22 17:13:47 PST 2004

On Thu, Jan 22, 2004 at 09:32:00PM +0200, Ran Eilam wrote:

> I did not even know this involves attachments. Now that I do, I still
> don't find it bothering.

Inline PGP can be annoying to weed out of your replies, if you don't
feel like writing fancy RC files. And even then, it's just backwards.

> I just did not know what keysigning means, except that it is somehow
> related to cryptography.

What i would like is for one of the recesses, or if it's fun, all of
them, to host a keysigning party.

To sign someone's key is to actually sign a meaningfull (to PGP
implementations) message stating the owner of key so and so, the one
used to sign the message, claims that she has verified the identity of
the owner of key such and such.

You get a page, filled with some key meta data. You then go through
the conference, looking for others with that form. You then exchange
key fingerprints, verifying that the key on the list is really the key
you think of as yours, and then you give your IDs to each other, so
that you can be certain the person in front of you has the same name
as her key UID states.

When you get back home you download all the keys you verified from a
keyserver, and then sign them if their fingerprints and UIDs are the
ones on the list. Moreover, if you remember the people, and some have
photo uids, you can sign more UIDs than the ones corresponding to the
entity you've verified.

See also:

> Neither can I. Look at earlier messages on the list concerning mocking
> Perl builtins for the context of this attempt at humor. Or maybe the 3
> periods signify that you understood the joke, and are building on top of
> it. Who cares...

Oh, that mock. I'm new to the list, so I didn't get it.

Mock is also laugh at, in an arrogant manner, and i thought you were
saying i was mocking people.

