pmlaw / The-Bitcoin-Foundation-Legal-Repo

A public repo for legal documents related to The Bitcoin Foundation
22 stars 33 forks source link

Reference Satoshi's PGP key by full fingerprint #3

Closed petertodd closed 11 years ago

petertodd commented 11 years ago

32-bit key ID's are too short to be secure.

One or more people who are trusted in the community who have actually had correspondence with Satoshi directly will need to ACK this first to make sure I really did get the right fingerprint.

You know, there is an argument to be made for those people signing Satoshi's PGP key too.

vessenes commented 11 years ago

Gavin can check the long-form fingerprint.

Thanks Peter.

On Fri, Apr 26, 2013 at 4:11 PM, Peter Todd notifications@github.comwrote:

32-bit key ID's are too short to be secure.

One or more people who are trusted in the community who have actually had correspondence with Satoshi directly will need to ACK this first to make sure I really did get the right fingerprint.

You know, there is an argument to be made for those people signing

Satoshi's PGP key too.

You can merge this Pull Request by running

git pull https://github.com/petertodd/The-Bitcoin-Foundation-Legal-Repo master

Or view, comment on, or merge it at:

https://github.com/pmlaw/The-Bitcoin-Foundation-Legal-Repo/pull/3 Commit Summary

  • Reference Satoshi's PGP key by full fingerprint

File Changes

  • M Bylaws/Bylaws_of_The_Bitcoin_Foundation.mdhttps://github.com/pmlaw/The-Bitcoin-Foundation-Legal-Repo/pull/3/files#diff-0(2)

Patch Links:

- https://github.com/pmlaw/The-Bitcoin-Foundation-Legal-Repo/pull/3.patch

https://github.com/pmlaw/The-Bitcoin-Foundation-Legal-Repo/pull/3.diff

Are you coming to Bitcoin2013 http://bitcoin2013.com in San Jose In May?

[image: CoinLab Logo]PETER VESSENES CEO

peter@coinlab.com \ / 206.486.6856 / SKYPE: vessenes 71 COLUMBIA ST / SUITE 300 / SEATTLE, WA 98104

pmlaw commented 11 years ago

Thanks, I will add this to the agenda for our next board meeting so we can vote on this change. My sense is that we want to get it right and if Gavin and others can confirm we will merge.

petertodd commented 11 years ago

Sounds good.

It's not a big issue, but I'd hate to see some silly hoax be pulled by someone making a fake PGP key with the same 32-bit keyid - why I also increasingly think Gavin and some others should sign Satoshi's key too as part of the process.

gavinandresen commented 11 years ago

ACK, that is the correct full fingerprint.