Bitcoin Forum

Other => Meta => Topic started by: Kluge on September 08, 2013, 07:59:37 PM



Title: PGP key forum?
Post by: Kluge on September 08, 2013, 07:59:37 PM
I was wondering if we could have an automatically locked subforum somewhere just for PGP key lookups. Putting it in a sig is largely worthless if an account is compromised.

If someone, say, asks for a loan, I may trust the person I knew the account-holder as, but I no longer automatically trust the person posting is the poster I knew.

Though, then the risk is the unpublished sale of an account along with PGP privkey and email account... but it's still a solid extra bit of defense, I'd think.

Ideally, we'd be able to post and lock a PGP key to our account, similar to how Skype, IRC handles, and email addresses can be tied to an account and show as a little button on forum posts (though there'd need to be some type of significant time lock for a change of displayed key to go through, or maybe some type of 2FA).


Title: Re: PGP key forum?
Post by: tysat on September 08, 2013, 10:17:53 PM
I'm a big fan of this idea, with account selling this would help to make sure the person is who you think it is.


Title: Re: PGP key forum?
Post by: grue on September 08, 2013, 11:42:36 PM
well there's this: https://bitcointalk.org/index.php?board=129.0 I post my gpg keys there.


Title: Re: PGP key forum?
Post by: Kluge on September 09, 2013, 02:28:11 AM
well there's this: https://bitcointalk.org/index.php?board=129.0 I post my gpg keys there.
Sounds reasonable. Will post and lock. Maybe will start a trend.


Title: Re: PGP key forum?
Post by: 01BTC10 on September 09, 2013, 02:31:41 AM
well there's this: https://bitcointalk.org/index.php?board=129.0 I post my gpg keys there.
Sounds reasonable. Will post and lock. Maybe will start a trend.
Could still be altered if account is compromised.


Title: Re: PGP key forum?
Post by: Kluge on September 09, 2013, 02:38:56 AM
well there's this: https://bitcointalk.org/index.php?board=129.0 I post my gpg keys there.
Sounds reasonable. Will post and lock. Maybe will start a trend.
Could still be altered if account is compromised.
Not if locked. Users also don't have the right to delete their own threads in that subforum. The best they could do is ask a mod to delete.


Title: Re: PGP key forum?
Post by: 01BTC10 on September 09, 2013, 02:40:38 AM
Good to know.


Title: Re: PGP key forum?
Post by: Kluge on September 09, 2013, 02:45:41 AM
Can an account be recovered if we've posted a PGP key and can sign a message stating it's been compromised?


Title: Re: PGP key forum?
Post by: justusranvier on September 09, 2013, 03:06:10 AM
Before this, can we get the forum software to start encrypting email notifications it sends out?


Title: Re: PGP key forum?
Post by: theymos on September 09, 2013, 05:30:55 AM
Not if locked.

But they can unlock it. The edit will be visible, though.

Can an account be recovered if we've posted a PGP key and can sign a message stating it's been compromised?

Yes.


Title: Re: PGP key forum?
Post by: Kluge on September 09, 2013, 05:35:31 AM
Not if locked.

But they can unlock it. The edit will be visible, though.
I tried adding msg # and topic # to locked thread (https://bitcointalk.org/index.php?action=post;msg=3111069;topic=290554.0) since there's no displayed edit button but received "Topic is locked..." message. Is there an unlock button I'm missing?

& if PGP can be used to recover an account, does that technically count as 2FA? I know a lot of people were asking for it. :P


Title: Re: PGP key forum?
Post by: favdesu on September 09, 2013, 05:48:57 AM
Good idea! I'd like to see an extra sub for it, reputation is not really fit for pgp keys in my opinion.


Title: Re: PGP key forum?
Post by: theymos on September 09, 2013, 06:14:46 AM
I tried adding msg # and topic # to locked thread (https://bitcointalk.org/index.php?action=post;msg=3111069;topic=290554.0) since there's no displayed edit button but received "Topic is locked..." message. Is there an unlock button I'm missing?

It's at the bottom of the topic page.


Title: Re: PGP key forum?
Post by: Kluge on September 09, 2013, 06:19:39 AM
I tried adding msg # and topic # to locked thread (https://bitcointalk.org/index.php?action=post;msg=3111069;topic=290554.0) since there's no displayed edit button but received "Topic is locked..." message. Is there an unlock button I'm missing?

It's at the bottom of the topic page.
Whoa. I never knew that - never looked that far down. I never knew I could move my own threads, either (or change the title of the thread for all replies).  :o Oh well, there goes that idea.


Title: Re: PGP key forum?
Post by: 🏰 TradeFortress 🏰 on September 09, 2013, 06:25:47 AM
Made a post with a yellow tamper evident sticker.


Title: Re: PGP key forum?
Post by: 🏰 TradeFortress 🏰 on September 09, 2013, 06:41:20 AM
Made a post with a yellow tamper evident sticker.
Ooo boy, a day full of learning and excitement! How does one choose a yellow square topic icon?

ETA: And is there any board where I *can* delete topics. I noticed I can move threads in the Reputation subforum to somewhere obscure, even though I can't delete it entirely.
It's a bug that lets you choose icons you shouldn't have access to. Editing a post without performing that bug will reset the icon, thus creating a 'tamper evident sticker' - unless the person editing has access to the icons or is aware of the bug.


Title: Re: PGP key forum?
Post by: dserrano5 on September 09, 2013, 06:42:19 AM
How should we deal with key expiration? I always set my key to expire in 12 months and have to edit it on a yearly basis. Would it be ok to unlock my thread, post a followup and lock it again?


Title: Re: PGP key forum?
Post by: Kluge on September 09, 2013, 07:16:23 AM
Made a post with a yellow tamper evident sticker.
Ooo boy, a day full of learning and excitement! How does one choose a yellow square topic icon?

ETA: And is there any board where I *can* delete topics. I noticed I can move threads in the Reputation subforum to somewhere obscure, even though I can't delete it entirely.
It's a bug that lets you choose icons you shouldn't have access to. Editing a post without performing that bug will reset the icon, thus creating a 'tamper evident sticker' - unless the person editing has access to the icons or is aware of the bug.
I am winrar?  ;D

(took a lot more trial and error than I expected)


Title: Re: PGP key forum?
Post by: jackjack on September 09, 2013, 09:01:27 AM
Can an account be recovered if we've posted a PGP key and can sign a message stating it's been compromised?

Yes.

That's great


Title: Re: PGP key forum?
Post by: b!z on September 09, 2013, 11:08:05 AM
Can an account be recovered if we've posted a PGP key and can sign a message stating it's been compromised?

Yes.

That's great

Now when can we expect to have the PGP key forum?


Title: Re: PGP key forum?
Post by: favdesu on September 09, 2013, 12:35:10 PM
or maybe an actual function to pgp sign your posts?

and an info at the bottom "positive PGP signed" ?

edit: something like [PGP]TEXT | PGP SIG[/PGP] tags, the PGP Code is hidden and > info at the bottom "positive PGP signed"


Title: Re: PGP key forum?
Post by: Bitsky on September 09, 2013, 06:45:32 PM
Maybe it's a good time to bring up my other thread: https://bitcointalk.org/index.php?topic=235794 [GnuPG signed postings and PMs for download]



Title: Re: PGP key forum?
Post by: whiskers75 on September 09, 2013, 06:52:33 PM
Can a mod please place the tamper-evident sticker on https://bitcointalk.org/index.php?topic=291161.0?


Title: Re: PGP key forum?
Post by: tysat on September 09, 2013, 07:06:34 PM
Can a mod please place the tamper-evident sticker on https://bitcointalk.org/index.php?topic=291161.0?

There's nothing to be placed, if the post is edited it will show.  The only way that it could be changed without showing that is if someone had direct database access, or if it was edited by you within 5 minutes of it being posted.


Title: Re: PGP key forum?
Post by: live627 on September 09, 2013, 10:44:23 PM
Not if locked.

But they can unlock it.
Not if a moderator locks it.