Re: tl26 pretest start
Norbert Preining <[email protected]> Mon, 23 Feb 2026 21:31:37 +0100
| Newsgroups | gmane.comp.tex.live |
|---|---|
| Message-ID | <aZy5KTCjcOKK-vkl@burischnitzel> |
Hi Robert, interesting discussion, indeed. I was reading up on alternative ways in recent weeks, like sigstore, signify, etc etc etc. > author of signify, put this: > > > There are no key servers for signify. No web of trust. Just > > keys. The good news is the keys are pretty small. As > > demonstrated. We can stick them just about everywhere, and we > > do. They're on the web site, they're on twitter, they're on the top > > side of CD. 56 base64 characters. You can read it out loud over the > > phone in under a minute. Wide dispersion makes it harder and harder > > to intercept all the ways you may get the key and increases the risk > > of detection should anybody try some funny business.[1] Not convinced. Most users will not go extra to the TUG web site and check a cryptic 56 base64 key. I don't think this is easier / more accessible. OTOH, I don't know how many check anyway ... > The idea behind signify is that of trust-path, instead of web of > trust. That's why I came up with the idea that a TeX Live > distribution N could include N+2 keys. No more. The chain is I like the idea - independent of signify and gpg. But as of now, we just extend the validity of the TeX Live signing key once a year. > obviously not as robust, I completely agree with you. But it's much > simpler, so it's all about accurately assessing what is really lost in What is simpler? I mean, from a user perspective? Users don't have to type in gpg commands, right? I do expect only very few to actually be able to verify say the installer package - independent from whether it is gpg or signify that signs the release. So what would become simpler? Best regards Norbert -- DI Dr Norbert Preining https://www.preining.info arXiv / Cornell University + IFMGA Guide + TU Wien + TeX Live GPG: 0x860CDC13 fp: F7D8 A928 26E3 16A1 9FA0 ACF0 6CAC A448 860C DC13