XSF Discussion - 2020-11-09

  1. vanitasvitae

    Hm, regarding XEP-0373 (OpenPGP for XMPP), it is not possible to retreive the Fingerprint of the key contained in a secret key backup without decrypting it first.

  2. vanitasvitae

    That's probably both a good and a bad thing.

  3. vanitasvitae

    UX-wise I'd like to show the user the fingerprint of the key they are about to restore

  4. vanitasvitae

    Hm, are there any benefits of having the fingerprint hidden in the backup? In the end, the public key gets published anyways

  5. vanitasvitae

    Ah I see this is adressed in https://wiki.xmpp.org/web/XEP-Remarks/XEP-0373:_OpenPGP_for_XMPP

  6. lovetox

    but what for vanitasvitae do you need this before?

  7. lovetox

    this is an operation which is carried out very very rarley

  8. vanitasvitae


  9. lovetox

    just download the key, decrypt it and show the user the fingerprints

  10. vanitasvitae

    but still if would be nice to tell the user "hey, we found a backup of key XYZ, would you like to restore that backup or maybe generate a new key instead?"

  11. lovetox

    ok, but is it not enough to say "we found a backup"

  12. vanitasvitae

    I agree that this is a minor issue

  13. lovetox

    also whats problematic i guess is

  14. lovetox

    if you dont have the fingerprint encrypted

  15. vanitasvitae

    The remarks page mentions some nice proposals to improve the situation

  16. lovetox

    this means its not sure that they belong together

  17. vanitasvitae


  18. vanitasvitae

    but I mean, that could be mitigated by verifying the fingerprint after decryption

  19. vanitasvitae

    still would present implementations with a possible pitfall though

  20. Alex

    Memberbot is online now for our 2020 elections. Great applicants again this year

  21. Ge0rG

    uh-oh, somebody failed to apply for membership renewal

  22. Ge0rG

    oh, still two weeks time for that one

  23. Alex

    Ge0rG, ya, still open. Will remind them soon

  24. jonas’


  25. jonas’

    thanks Alex

  26. Ge0rG

    Alex: 👍

  27. Ge0rG

    dwd: it looks like you are still applying for both B & C

  28. dwd

    It does, doesn't it? I should make a decision as to whether and which to drop.

  29. MattJ

    People have run for both before, I don't believe anyone has been elected for both during my time at least

  30. Seve

    Let's see :)

  31. dwd

    Well, actually, they have. I'm pretty sure Peter did, several times, but I did in 2015.

  32. Ge0rG

    dwd: do you intend to run both positions if elected?

  33. dwd

    Yes, though I'll explicitly avoid chairing either (not that I think I'd win if I tried), or acting as liaison (which is properly the job of the council chair).

  34. dwd

    I did act as liaison in 2015, and it was a bit difficult to keep the hats separate.

  35. Ge0rG

    dwd: you might want to update the last statement in your Board application then, > I'll review the state of applications, and if I feel I can I'll withdraw from one or other.

  36. Ge0rG

    (in both applications, actually)

  37. dwd

    Yes. Although there's context - there's stuff I'd like to get done in both, so it depends if I think most of that stuff would get done. I haven't yet reviewed the state of applications, though.

  38. Ge0rG

    dwd: there are five for Board and seven for Council, if that is what you meant by "review"

  39. dwd

    Well, my hope was that I could do more than just count. Sadly, doesn't seem to be the case for Board.

  40. jonas’

    dwd, fwiw, I’ll be happy to chair council again should I be reelected

  41. dwd

    Thank you! I'm amazed you find the time, given you've the editor role as well, but you've consistently done a better job than I did, so I wouldn't be standing anyway.

  42. jonas’

    dwd, thank you :)

  43. dwd

    I mean, of course, supposing we both get elected. I have some thinking to do on that front about whether to withdraw, of course.

  44. jonas’

    yeah, let’s not call any election results before it’s done ........

  45. Ge0rG

    jonas’: well, we can go to the Supreme Court if the results aren't favorable, right?

  46. dwd

    Luckily, the Supreme Court of the XSF is basically whoever shows up to the AGM in "person".

  47. dwd

    So at least that's quick.