Have you done the rest of the verification necessary to say this is legitimate?
* Wayback to some months ago for the download page [1]
* Confirm that the content presented matches the existing download content for the 0.12.1 release (or prior)
* Confirm that the content for the "0.11+ key" is the same [2]
* Confirm that the signed release for the 0.12.1 content is correct and valid
* Request that (full-length) key from a public GPG server
If you've done all of those things, it might be a good idea for you to sign that key and push it back up to a public GPG server - that help with web-of-trust, and somewhat legitimizes the key versus some arbitrary untrusted impostor. (I have done all of these steps, and signed with my key 9BB5251DE08569D4DEEA894C85D221C11DD01DF6)
>Shouldn't keys only be signed after meeting in person?
Keys should only be signed after establishing beyond resonable doubt that they belongs to the person indicated by the key. Since the userid of the key is usually a real name, checking the passport in person is one good way to accomplish that.
I would argue that by cross-referencing multiple sources I can establish beyond resonable doubt that a certain key indeed belongs to the person known to the community as Wladimir J. van der Laan. At the point where the person is sufficiently well known under a certain name it doesn't really matter if that's the name on their passport, since that's irrelevant for their public identity.
I can certify that this key is the same one that was used for the 0.12.1 release, and its content has been published on more than just the bitcoin.org website and more than just $TODAY.
I can see the same content on Reddit's /r/bitcoin wiki page or on Bitcoin Talk, with an identical signature. I would have to believe that either Bitcoin is already compromised, or that bitcoin.org, bitcointalk.org, reddit.com AND archive.org have all been hacked or coerced into changing content with accurate history intact.
I don't know, it feels like it poisons the web of trust. There's definitively something odd going on, and IF this was a coordinated attack, would it be too much to think the adversary has managed to post with some sock puppet accounts on a couple of forums - or even hack them? Or even hack your browser - a single compromised extension like an ad blocker could search&replace the key id in any web page rendered to you. I think that if you decide to sign keys just from an hour's worth of browsing around you are damaging the reputation of your own key to be honest.
I'll accept the "damage" to my own key - Realize what you're claiming:
Someone compromised the Bitcoin site > 4 months ago without it being discovered.
Someone continues to compromise the site today even after this public attention, since the same message is still there.
That same entity compromised my browser, curl, my Linux laptop, Windows desktop, Android phone and 3 different networks.
That same entity compromised Archive.org and Reddit 4+ months ago without being discovered.
That same entity created sockpuppet accounts to publicize the fact that this info was compromised and nobody discovered the discrepancy.
I don't believe that even the pre-Snowden NSA had all of those powers. If they did, fake signatures are probably the least of our problems.
It's no longer the original model of Person === Key that requires passport checks and face-to-face meetings. I would consider this better validation, in that it certifies real-world and historical usage.
Here's my alternate proposal: How difficult is it for the same attacker to create a fake passport and show up to a bitcoin meetup claiming to be this person?
I'm just saying that if you go out and verify all those things today (even looking at archive.org etc), then as long as you're using just one (type of) browser configuration, compromising a single extension could be enough to "blur your vision" when you decide to sign that key. A couple of regexes replacing a few variants of the real fingerprint with the fake fingerprint in all HTML documents - then every forum post you look at echoing the key might be a lie. Those scenarios are "OR", not "AND"... :)
Or, you know, for paranoia level 1000, your posts are the sockpuppet ;)
I'll agree this is all super unlikely and I'm not accusing you or anyone here of shenanigans. I'm just saying that signing keys shouldn't be taken lightly, because if people start getting sloppy then a lot of the trust in the web of trust is no longer water tight.
I don't run that kind of extension [0], but that's the reason I included this line:
> That same entity compromised my browser, curl, my Linux laptop, Windows desktop, Android phone and 3 different networks.
At least 3 platforms, potentially different 3 browsers, plus command-line.
If I want to do this "properly" it's a lot of work. I'd get 3 or more independent VPN providers and run the test while connected to each, independently or in series. I'd run everything in a VM that I created from a verified source 5+ years ago on hardware from 10+ years ago[1]. I would have to categorize and confirm that every vulnerability in all software was either fixable via configuration, or couldn't contribute to remote compromise of the box. I'd run the test with and without Tor, hard-resetting the VM to its initial state for every variation and comparing the results across every run to detect abnormalities. I'd confirm the content at Archive, CommonCrawl, Yahoo, Google and at least one foreign provider, Yandex or Baidu or whoever else I could track down. I'd look for that same string in all places I could find it (web, newsgroups, torrents, friends, friends-of-friends), and confirm that neither those pages nor any linked pages contain invalidations, or if any of them contain further evidence to support the identity of said key. By "linked" I mean both links from those pages, and anything I could discover via search engine pointing to those pages independently. I'd go find some old torrents or archives of older versions of the binaries and/or signatures, and confirm that their content matches the published content. I'd confirm that the old key was in use before 0.11, and that the new key is indeed the one that signed release 0.11+. I'm sure there are some further steps I could take to invalidate any known or theorized attacks from state-level agencies, but at this point it's probably more difficult to fake than a GPG signature.
And obviously I'm a sockpuppet - nobody should listen to random strangers on the internet without verifying their identity as well! You could look at my keybase profile, but A) that's easy to fake and B) that's not the key I used to sign above - clearly something hinkey is going on. ;)
When you sign a key, you can use the flag `--ask-cert-level` and it will prompt you to specify on a scale of 1-3 how careful you were. This would be a case when you could specify a lower number (namely, 1).
Personally, I save level 3 signatures for people I know personally, and only if they show my their fingerprint on a trusted device.
A lot of the developers have participated in key signing parties , and have keys with lots of history. Would be good if they could drop some signatures.
* Wayback to some months ago for the download page [1]
* Confirm that the content presented matches the existing download content for the 0.12.1 release (or prior)
* Confirm that the content for the "0.11+ key" is the same [2]
* Confirm that the signed release for the 0.12.1 content is correct and valid
* Request that (full-length) key from a public GPG server
If you've done all of those things, it might be a good idea for you to sign that key and push it back up to a public GPG server - that help with web-of-trust, and somewhat legitimizes the key versus some arbitrary untrusted impostor. (I have done all of these steps, and signed with my key 9BB5251DE08569D4DEEA894C85D221C11DD01DF6)
[1] http://web.archive.org/web/20160109193420/https://bitcoin.or... [2] http://web.archive.org/web/20160109193420/https://bitcoin.or...