Re: GnuPG Web-of-Trust calculations based on trust-signatures don't add up (T7611)

Simon Josefsson via Gnupg-devel <[email protected]>
Newsgroups gmane.comp.encryption.gpg.devel
Message-ID <[email protected]>
Daniel Kahn Gillmor via Gnupg-devel <[email protected]> writes:

>> So I don't think identity trust calculations must generally always be
>> additive when given more information.
>
> Right, i can see how that is an interesting counter-point: two mutually
> conflicting identity assertions about the same underlying principal
> should make either identity assertion *less* confident than it was
> before.

No, I didn't mean that the two IDs provide assertions that conflict, and
I see now that my example was unclear and gave that impression.  While
it may appear that way, I don't believe one passport for a person with
name X and a drivers license for the same person with name Y is
necessarily asserting anything that conflicts.  A person can have
multiple names at different points in time, and it is common for people
to have multiple valid names at the same point in time too.  When
mapping this to a digital world, I think it is reasonable to give full
confidence to a simple chain of assertion claims, but less confidence to
a more complex chain.  Which seems somewhat similar to the example you
gave.  And more in line with common human trust confidence behaviour --
if you only have one person available for trust, you have no choice than
to trust 100% but if another person comes along you could trust 99%/1%
or 50%/50% depending on properties.  Mapping human trust calculations
into anything digital seems hard, though, and my head hurts when I try
to map any of this into PGP WoT principles.  But I'm not certain that
finding surprising examples is always a bug.

/Simon

_______________________________________________
Gnupg-devel mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-devel
signature.asc (application/pgp-signature, 1.2 KB)
-----BEGIN PGP SIGNATURE-----

iQNoBAEWCAMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmgbH8MUHHNpbW9uQGpv
c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f
V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z
ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh
BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA
/iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx
+3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx
I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0
+MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R
cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE
8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J
ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6
qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB
BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA
JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF
PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh
is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdFoqJhAQCcPgwYW8Hk
V8tadckAk3GeCNOqGwJtfdrWKQkYgIoCWwD+OCrybpXYRAU/qcI/i5nTwQ9UchAB
c9BGMHx9Rqn9LwQ=
=G5Ru
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.