Re: GnuPG Web-of-Trust calculations based on trust-signatures don't add up (T7611)
Simon Josefsson via Gnupg-devel <[email protected]>
| Newsgroups | gmane.comp.encryption.gpg.devel |
|---|---|
| Message-ID | <[email protected]> |
Daniel Kahn Gillmor via Gnupg-devel <[email protected]> writes: >> So I don't think identity trust calculations must generally always be >> additive when given more information. > > Right, i can see how that is an interesting counter-point: two mutually > conflicting identity assertions about the same underlying principal > should make either identity assertion *less* confident than it was > before. No, I didn't mean that the two IDs provide assertions that conflict, and I see now that my example was unclear and gave that impression. While it may appear that way, I don't believe one passport for a person with name X and a drivers license for the same person with name Y is necessarily asserting anything that conflicts. A person can have multiple names at different points in time, and it is common for people to have multiple valid names at the same point in time too. When mapping this to a digital world, I think it is reasonable to give full confidence to a simple chain of assertion claims, but less confidence to a more complex chain. Which seems somewhat similar to the example you gave. And more in line with common human trust confidence behaviour -- if you only have one person available for trust, you have no choice than to trust 100% but if another person comes along you could trust 99%/1% or 50%/50% depending on properties. Mapping human trust calculations into anything digital seems hard, though, and my head hurts when I try to map any of this into PGP WoT principles. But I'm not certain that finding surprising examples is always a bug. /Simon _______________________________________________ Gnupg-devel mailing list [email protected] https://lists.gnupg.org/mailman/listinfo/gnupg-devel
signature.asc
(application/pgp-signature, 1.2 KB)
-----BEGIN PGP SIGNATURE----- iQNoBAEWCAMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmgbH8MUHHNpbW9uQGpv c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA /iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx +3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0 +MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE 8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6 qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdFoqJhAQCcPgwYW8Hk V8tadckAk3GeCNOqGwJtfdrWKQkYgIoCWwD+OCrybpXYRAU/qcI/i5nTwQ9UchAB c9BGMHx9Rqn9LwQ= =G5Ru -----END PGP SIGNATURE-----