-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 On 2017-05-13 16:01, Felipe Dau wrote: > On Sat, May 13, 2017 at 03:18:39PM -0500, Andrew David Wong wrote: >> There are many other methods you could use to attempt to verify the >> master key fingerprint aside from relying on the Qubes website. Here's >> a brief, non-exhaustive list: >> >> * Use different search engines to search for the fingerprint. >> * Use Tor to view and search for the fingerprint on various websites. >> * Use various VPNs and proxy servers. >> * Use different Wi-Fi networks (work, school, internet cafe, etc.). >> * Ask people to post the fingerprint in various forums and chat rooms. >> * Check against PDFs and photographs in which the fingerprint appears >> (e.g., slides from a talk or on a T-shirt). >> * Repeat all of the above from different computers and devices. > > Good examples! It would be nice if these were also on the verification > page [0]. > > I would like suggest an additional approach that might be useful as > well, which is using the debian-keyring. Assuming that the system > which you are using to download Qubes is running a legitimate Debian > (oh well), then you can easily verify Qubes' master key, as most of > the ones that signed it are either in that keyring or were signed by > others that are. This is what Tails instructs users to verify their > key in one of their guides [1]. > > Thanks, > -Felipe > > [0]: https://www.qubes-os.org/security/verifying-signatures/ > [1]: https://tails.boum.org/install/expert/usb/index.en.html#verify-key >
Thanks. I've added this information to the document. - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -----BEGIN PGP SIGNATURE----- iQIcBAEBCgAGBQJZF3wUAAoJENtN07w5UDAwX9UQAKbGZgP1G4u0OX7l5BBPtwW6 aCe2xzFQOoXXg9ux8sGyrrEDtkcEiYABv6lCocnb1cAwW+rCOnX8k8y1xonwbtRH Z216wgAo1Pnlme8HKkEFR/TXAY3k5+9ABSDLv3Q613knzJFm3yj37hOQkotNHGjV RLWfRsC4GbC5gAPTryZEbcsea4EPjKxo7549WH9p9OYjP7Sz1KxtMISmHtH9WaBe qH+9zlL/JzV+Ivmt7QMA3aTMNhla4rOFLrZGLWGNer6WyEryd6CQkoL1AwtOJcek cisMzclf30CtLmqUiTfbMT3vm4uIjavElgFiCww8AwC/TRrBtPHtuRTlOHunaCZj oIRnd2lV1ztutPwILMbB9r8p1WL5mPfjY3uedigdwPhX1ML/hrqgx3e6YuwelkFV O4jSJrzdEspyzknqz7evSGweoKc3HGpbwICFwk2Fm+C8R1NbYufUem/5fMC2XQEV CZPDsYaO5oJITrJNfFi9PAeZQZpApUA2q33MEqJVK+Pwa20jwZyLplHLBg/CTVBE nv1TVPpT/1Znd7ASXGhJsAtvbOqyUFjGkB/2NXwkuCIg7Gb9MyvQJAm01L4OOMgY Ag/lgCNaPOqnk26OTnyrK5UODk8Zcy41YioEJvNSx1OkBLpM8CEeD+4/+tN5yFZt es56EhrkF5JoGUPlKUCe =S0N0 -----END PGP SIGNATURE----- -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-devel+unsubscr...@googlegroups.com. To post to this group, send email to qubes-devel@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-devel/16745b77-4840-ab31-3e91-868878940aab%40qubes-os.org. For more options, visit https://groups.google.com/d/optout.