-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 2017-05-13 16:01, Felipe Dau wrote:
> On Sat, May 13, 2017 at 03:18:39PM -0500, Andrew David Wong wrote:
>> There are many other methods you could use to attempt to verify the
>> master key fingerprint aside from relying on the Qubes website. Here's
>> a brief, non-exhaustive list:
>>
>>  * Use different search engines to search for the fingerprint.
>>  * Use Tor to view and search for the fingerprint on various websites.
>>  * Use various VPNs and proxy servers.
>>  * Use different Wi-Fi networks (work, school, internet cafe, etc.).
>>  * Ask people to post the fingerprint in various forums and chat rooms.
>>  * Check against PDFs and photographs in which the fingerprint appears
>>    (e.g., slides from a talk or on a T-shirt).
>>  * Repeat all of the above from different computers and devices.
> 
> Good examples! It would be nice if these were also on the verification
> page [0].
> 
> I would like suggest an additional approach that might be useful as
> well, which is using the debian-keyring. Assuming that the system
> which you are using to download Qubes is running a legitimate Debian
> (oh well), then you can easily verify Qubes' master key, as most of
> the ones that signed it are either in that keyring or were signed by
> others that are. This is what Tails instructs users to verify their
> key in one of their guides [1].
> 
> Thanks,
> -Felipe
> 
> [0]: https://www.qubes-os.org/security/verifying-signatures/
> [1]: https://tails.boum.org/install/expert/usb/index.en.html#verify-key
> 

Thanks. I've added this information to the document.

- -- 
Andrew David Wong (Axon)
Community Manager, Qubes OS
https://www.qubes-os.org
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJZF3wUAAoJENtN07w5UDAwX9UQAKbGZgP1G4u0OX7l5BBPtwW6
aCe2xzFQOoXXg9ux8sGyrrEDtkcEiYABv6lCocnb1cAwW+rCOnX8k8y1xonwbtRH
Z216wgAo1Pnlme8HKkEFR/TXAY3k5+9ABSDLv3Q613knzJFm3yj37hOQkotNHGjV
RLWfRsC4GbC5gAPTryZEbcsea4EPjKxo7549WH9p9OYjP7Sz1KxtMISmHtH9WaBe
qH+9zlL/JzV+Ivmt7QMA3aTMNhla4rOFLrZGLWGNer6WyEryd6CQkoL1AwtOJcek
cisMzclf30CtLmqUiTfbMT3vm4uIjavElgFiCww8AwC/TRrBtPHtuRTlOHunaCZj
oIRnd2lV1ztutPwILMbB9r8p1WL5mPfjY3uedigdwPhX1ML/hrqgx3e6YuwelkFV
O4jSJrzdEspyzknqz7evSGweoKc3HGpbwICFwk2Fm+C8R1NbYufUem/5fMC2XQEV
CZPDsYaO5oJITrJNfFi9PAeZQZpApUA2q33MEqJVK+Pwa20jwZyLplHLBg/CTVBE
nv1TVPpT/1Znd7ASXGhJsAtvbOqyUFjGkB/2NXwkuCIg7Gb9MyvQJAm01L4OOMgY
Ag/lgCNaPOqnk26OTnyrK5UODk8Zcy41YioEJvNSx1OkBLpM8CEeD+4/+tN5yFZt
es56EhrkF5JoGUPlKUCe
=S0N0
-----END PGP SIGNATURE-----

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-devel" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-devel+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-devel@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-devel/16745b77-4840-ab31-3e91-868878940aab%40qubes-os.org.
For more options, visit https://groups.google.com/d/optout.

Reply via email to