fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

8.8K
active users

#keyserver

0 posts0 participants0 posts today

News from the coalface:

Upgrading the #Hockeypuck #openpgp #keyserver in-place has historically not been a smooth experience. In particular, the search indexes are only updated on write during normal operation, and the database schema is not updated at all. When major changes are made to the back end code, the dataset therefore has to be dumped and reloaded. This requires double the disk space and adds to the burden of maintaining a keyserver.

In preparation for #rfc9580 and #pqc keys, we have been working on in-place migrations for the search indexes and database schemas. The hockeypuck master branch now reindexes search terms transparently on startup, which will ensure consistent search results after any changes to the indexing policy. We are also testing a feature to reload the full dataset in-place after an upgrade, which must be run in offline mode due to concurrency limitations, but should otherwise be seamless and does not affect resource usage. Together these changes will reduce the maintenance burden for keyserver operators, and smooth the path for future upgrades.

In-place post-upgrade migrations, plus improved sync resilience, and hopefully a few additional improvements (watch this space!), will be available in the forthcoming 2.3 release, which is generously supported by @NGIZero Core.

Ah, yes, the Linux Kernel's #PGP Web of Trust—because nothing screams "cutting-edge technology" like a system built on the tattered remains of #keyserver networks 🤦‍♂️. Who needs simplicity when you can have a Byzantine key repository maintained by a single guy named Konstantin? 🔐🔑
blog.kleine-koenig.org/ukl/the #LinuxKernel #WebOfTrust #Security #Technology #Humor #HackerNews #ngated

blog.kleine-koenig.orgThe Linux kernel's PGP Web of Trust

We are pleased to announce the release of Hockeypuck 2.2.

Hockeypuck is a modern synchronising keyserver that is optimised for ease of deployment, particularly in containerised environments via docker-compose.

Hockeypuck 2.2 is a significant upgrade that includes the following changes:

# Features

• Fully stable sync
• Improved multithreading safety
• Deletion of personal data from hard-revoked keys
• Admin deletion of keys via signed submissions
• Detached revocation certificate support

# Bugfixes

• Missing direct key signature validation
• Missing subkeys with v3 sbinds
• Missing CORS headers
• HTTPS binding errors
• Many cosmetic improvements

# Deprecations

• SKS-keyserver recon compatibility
• UAT image packets
• User deletion and replacement of keys via `/pks/delete` and `/pks/replace` endpoints

More information: github.com/hockeypuck/hockeypu

GitHubHomeOpenPGP Key Server. Contribute to hockeypuck/hockeypuck development by creating an account on GitHub.

Anyone familiar with writing database queries and want to help #mailvelope #openpgp #keyserver work with #ferretdb instead of non-free #mongodb ?

github.com/mailvelope/keyserve

Background: mailvelope keyserver is the only openpgp keyserver software I found that supports key removals and GDPR-compliant/abuse resistant (the commonly used keys.openpgp.org software hagrid is not supported for outside deployments).

All older key server software don't do email verification and cannot remove keys.

GitHubSupport ferretdb to replace mongodb · Issue #142 · mailvelope/keyserverBy pravi

## Two Dixie Cups and a piece of string

### Oh my goodness\!

Okay first of all, I use #Matrix and #Jabber - #XMPP w/ #OMEMO, primarily.

I typically don't even regularly give out my email address nowadays, and more and more over the past four years or so, find myself publishing a #Fediverse address for myself too as a contact point.

Most often, if you ask me for my #email address I'll give you my Matrix address.

If someone wants to email me then I figure they can get that from my #PGP fingerprint or #Keyoxide.

If they don't know what a #keyserver is or where any of them are located then I just figure they're to dumb to use email.

Yes. As a technologist, I'm at times, rather arrogant, opinionated, discriminatory, and condescending... But only sometimes. The rest of the time I'm patient, attentive, empathetic, and accommodating.

Basically, if i know you don't know shit I'm a nice guy, yet if you pretend to be an all that jazz hipster know it all, then it's quite likely you'll find that I'm pretty much a full on dikhed. Spelled just like that too.

Beginning in the later eighties I think, and then the nineties they called us #BOFH. That's an acronym for someone who might already have forgotten more than you will ever know. I knew a few old Mainframe engineers with Honeywell and IBM when I was a young programmer - those guys were Gods and could tell you how many wraps of copper to make around a toroid if you had an emergency and needed to make an in the field replacement of your memory - Gods. #SuperFreakyGeeks, having already, back then, forgotten more than you or I will ever know.

They called me #Whizkid, coz I was learning shit that they were never gonna bother with - they're gonna retire soon in Mexico with boats, babes, and beers.

But I digress. I do that.

### Back to secure communications...

When it comes to Signal, I know a lot of you really like it. I have little use for it. It bleeds my DID and farms everyone's contact databases - "bing! Ex stalker bitch girlfriend just joined signal. Say hello!" What the fuck?

Well I guess she's still got me in her contacts lolz. Fuckin' bitch.

### Ummm... Yeah I'll pass.

I actually only use Signal with people who already have my #DID (phone number) anyway.

Recently, a colleague flew a cray cray route to Thailand, via #LAX to #NYC, then #Qatar. Signal works on jetliner's #WiFi too, and isn't dependant on cellular services.

Good choice, but I'm still wondering why his "safety number" changed after he departed #New_York and before arriving in #Thailand - he neither reinstalled nor switched to a new device. But that's another matter.

Sounds a little cloak & dagger fishy to me.

Anyway, I hadn't actually used #Signal in a while, and left it muted for a few months.

To my surprise... #Stories! Yay! Stories!

Wait, what are Stories? You mean like #YouTube or #InstaSPAM? And I'm assuming like they have in #Whaaaasup (never used it, never will)?

Ummm... I just tucked that little nugget of, I guess, good news away, not really knowing even how to process news of the introduction of such a useless fucking feature.

Until now.

Without further adieu, I defer to @how , one of our more prominently distinguished members in the Fediverse community, for his novel, clever, and appropriate recommendation:

https://ps.s10y.eu/@how/109308591992363124

#tallship #FOSS #communications #privacy #shenanigans

⛵

.

public.mitra.socialMitraFederated social network
## Two Dixie Cups and a piece of string

### Oh my goodness!

Okay first of all, I use #Matrix and #Jabber - #XMPP w/ #OMEMO, primarily.

I typically don't even regularly give out my email address nowadays, and more and more over the past four years or so, find myself publishing a #Fediverse address for myself too as a contact point.

Most often, if you ask me for my #email address I'll give you my Matrix address.

If someone wants to email me then I figure they can get that from my #PGP fingerprint or #Keyoxide.

If they don't know what a #keyserver is or where any of them are located then I just figure they're to dumb to use email.

Yes. As a technologist, I'm at times, rather arrogant, opinionated, discriminatory, and condescending... But only sometimes. The rest of the time I'm patient, attentive, empathetic, and accommodating.

Basically, if i know you don't know shit I'm a nice guy, yet if you pretend to be an all that jazz hipster know it all, then it's quite likely you'll find that I'm pretty much a full on dikhed. Spelled just like that too.

Beginning in the later eighties I think, and then the nineties they called us #BOFH. That's an acronym for someone who might already have forgotten more than you will ever know. I knew a few old Mainframe engineers with Honeywell and IBM when I was a young programmer - those guys were Gods and could tell you how many wraps of copper to make around a toroid if you had an emergency and needed to make an in the field replacement of your memory - Gods. #SuperFreakyGeeks, having already, back then, forgotten more than you or I will ever know.

They called me #Whizkid, coz I was learning shit that they were never gonna bother with - they're gonna retire soon in Mexico with boats, babes, and beers.

But I digress. I do that.

### Back to secure communications...

When it comes to Signal, I know a lot of you really like it. I have little use for it. It bleeds my DID and farms everyone's contact databases - "bing! Ex stalker bitch girlfriend just joined Signal. Say hello!" What the fuck?

Well I guess she's still got me in her contacts lolz. Fuckin' bitch.

### Ummm... Yeah I'll pass.

I actually only use Signal with people who already have my #DID (phone number) anyway.

Recently, a colleague flew a cray cray route to Thailand, via #LAX to #NYC, then #Qatar. Signal works on a jetliner's #WiFi too, and isn't dependant on cellular services.

Good choice, but I'm still wondering why his "safety number" changed after he departed #New_York and before arriving in #Thailand - he neither reinstalled nor switched to a new device. But that's another matter.

Sounds a little cloak & dagger fishy to me.

Anyway, I hadn't actually used #Signal in a while, and left it muted for a few months.

To my surprise... #Stories! Yay! Stories!

Wait, what are Stories? You mean like #YouTube or #InstaSPAM? And I'm assuming like they have in #Whaaaasup (never used it, never will)?

Ummm... I just tucked that little nugget of, I guess, good news away, not really knowing even how to process news of the introduction of such a useless fucking feature.

Until now.

Without further adieu, I defer to @how , one of our more prominently distinguished members in the Fediverse community, for his novel, clever, and appropriate recommendation:

RT: https://ps.s10y.eu/users/how/statuses/109308591992363124
Une fois pour TOOT! A Mastodon in Brussels( hellekin ) (@how@s10y.eu)Content warning: How to use Signal Stories
Replied in thread
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

@nsa @Jain You can also validate it with the public key which is also in the #KeyServer :blobcatgendou:

keys.open...

-----BEGIN PGP SIGNATURE-----

iLMEAQEKAB0WIQT3b7sqZuPnD91mL6CESxETh1VGHgUCY4jhKgAKCRCESxETh1VG
HjEWBACcVsQ7H/mzENbH8OuANXaKIK/9WqquSfhRpSIekjKrs50at13CwIlcusd9
fS7sBwAlh6betsqGfBtw+/4Z6VBS1EjEU84ANc7JkGu8hTuhp1LIgsqwBWlrdEtJ
7MnouJrZGVcD7v/c0+vxnG7zpJ3eRiDczz50uILICmcLry7lzA==
=GtbW
-----END PGP SIGNATURE-----
keys.openpgp.orgkeys.openpgp.org

question; after figuring out why I couldn't connect to my server the other day I'm looking for a solution. Like a responsible person I've installed my server with but that means manual intervention after a reboot (namely entering the decryption password).

Automatic updating also means regular reboots, but I don't want to deal with the password. I've heard a might be a solution, but I hope there are other solutions available?

@dcent
We are not seeing the other half? Only this post.

1) Sounds good.

2) There's no point talking to a bank about investments and loans if communications are leaky. Imagine communicating re a possible #homeLoan and Google/M$/Blackrock, seeing that an using that info against you.

We need secure comms. Therefore banks should use/store ppl's public encryption keys. They need to act as a #keyserver also, because a) there's not enough good #keyservers, b) also stops ppl knowing where yu #bank.