Re: Are TOFU statistics used for validity or conflict resolution?

2017-07-06 Thread Neal H. Walfield
At Fri, 23 Jun 2017 13:45:39 +0300, Teemu Likonen wrote: > I don't know whether my thinking is common but perhaps it would be > helpful if gpg's man page made clear that on conflict situation both > keys go to "ask" mode. A quote from my gpg 2.1.18 manual: I tried to improve the documentation in 2

Re: Are TOFU statistics used for validity or conflict resolution?

2017-06-23 Thread Neal H. Walfield
At Fri, 23 Jun 2017 13:22:23 +0200, Peter Lebbing wrote: > On 23/06/17 12:56, Neal H. Walfield wrote: > > It's up to the GPG client to interpret it. This document (authored by > > Andre and me) has some recommendations for MUAs: > > Ah! Thanks for the information. > > I was thinking about how Gn

Re: Are TOFU statistics used for validity or conflict resolution?

2017-06-23 Thread Peter Lebbing
On 23/06/17 12:56, Neal H. Walfield wrote: > It's up to the GPG client to interpret it. This document (authored by > Andre and me) has some recommendations for MUAs: Ah! Thanks for the information. I was thinking about how GnuPG handled it, i.e., on the gpg command line or as a backend for some

Re: Are TOFU statistics used for validity or conflict resolution?

2017-06-23 Thread Neal H. Walfield
At Fri, 23 Jun 2017 12:52:48 +0200, Peter Lebbing wrote: > > [1 ] > On 23/06/17 11:14, Neal H. Walfield wrote: > > No, both keys are set to ask. The key with a lot of observed > > signatures could be bad. This could occur, if there is a MitM, but > > the MitM has a small lapse, because, perhaps

Re: Are TOFU statistics used for validity or conflict resolution?

2017-06-23 Thread Peter Lebbing
On 23/06/17 11:14, Neal H. Walfield wrote: > No, both keys are set to ask. The key with a lot of observed > signatures could be bad. This could occur, if there is a MitM, but > the MitM has a small lapse, because, perhaps, you've used an > unintercepted network path to retreive the "new" signatur

Re: Are TOFU statistics used for validity or conflict resolution?

2017-06-23 Thread Teemu Likonen
Neal H. Walfield [2017-06-23 11:14:31+02] wrote: > At Thu, 22 Jun 2017 20:32:48 +0300, Teemu Likonen wrote: >> Then let's say I have a key which has been used to verify hundred or >> so signatures. In --status-fd's TOFU_STATS it gets higher >> value, say 4. Then the keyring gets a new key with co

Re: Are TOFU statistics used for validity or conflict resolution?

2017-06-23 Thread Neal H. Walfield
At Thu, 22 Jun 2017 20:32:48 +0300, Teemu Likonen wrote: > Teemu Likonen [2017-06-22 09:42:50+03] wrote: > > Does the SUMMARY field's value (0-4) have effect on how key's validity > > is calculated or how TOFU conflicts are resolved or presented to a > > user? > > I didn't get answers yet but I'll

Re: Are TOFU statistics used for validity or conflict resolution?

2017-06-22 Thread Neal H. Walfield
At Thu, 22 Jun 2017 09:42:50 +0300, Teemu Likonen wrote: > It _seems_ to me that > > - Field 3 :: validity - A number with validity code. > > is the same thing as SUMMARY in TOFU_STATS. Am I right? > > And here's my question again: Does the SUMMARY field's value (0-4) have > effect on how

Re: Are TOFU statistics used for validity or conflict resolution?

2017-06-22 Thread Teemu Likonen
Teemu Likonen [2017-06-22 09:42:50+03] wrote: > Does the SUMMARY field's value (0-4) have effect on how key's validity > is calculated or how TOFU conflicts are resolved or presented to a > user? I didn't get answers yet but I'll speculate a bit on the subject. This is all about "trust-model tofu

Are TOFU statistics used for validity or conflict resolution?

2017-06-21 Thread Teemu Likonen
Are TOFU statistics used for key's validity calculations or TOFU conflict resolution? Some background: The TOFU system keeps statistics about key's use. I'll quote some lines from the DETAILS document. About --with-colons --witt-tofu-info --list-keys: *** TFS - TOFU statistics This