FSF Events: Free Software Directory meeting on IRC: Friday, August 04, starting at 12:00 EDT (16:00 UTC)
to 15:00 EDT (16:00 to 19:00 UTC)
to help improve the Free Software Directory.
Seven core contributors and one board member met in Scotland, the birthplace
of F-Droid, for the first in-person F-Droid team meeting. One of the most
pressing tasks we needed to take care of was setting up a
contributor-controlled backup of all of our signing keys. The requirements
made it necessary to have a lengthy, in-person, consensus-driven planning
session. We found no good documentation of such a procedure, so we’re going
out on a limb here and publishing the general outline of our process. This
process was informally audited by multiple people with varying expertise
before the public key was used to encrypt anything.

F-Droid manages secret signing keys for thousands of apps. Someone who has
control over those keys could create malicious app releases that could be
transparently installed as updates. On top of that,
Android
does
not
make it
easy
to rotate to new signing keys, unlike TLS or Signal. So these keys are very important to protect. They are also very
important to backup, since the Android OS uses the signing key combined with
the Application ID as the unique identifier to represent each installed
app. This meeting gave us the perfect opportunity to create a new backup
process that ensures that at least 4 trusted community members must be
physically present in order to decrypt the backup of all the keys. First,
we started with the requirements:
Then we mapped out who was present:
From that, we built the process:
One important factor in reliable backups is regular updates. New apps are
constantly being added, and those usually get a new signing key assigned.
So we needed a system where it was easy to update the backup data while
involving as few people as possible. An operator of the signing server
receives the public key to encrypt the backups via in-person exchange with a
holder of the backups. The holders of the backup data receives the
encrypted backups from an operator of the signing server via in-person
exchange.
Holding such important secrets also brings some unavoidable stresses to the
people holding them. One key design goal was to create a protocol that did
not add to the stress of any existing operators. Furthermore, we aimed to
keep the individual stress as low as possible for all roles in this
protocol. That makes it possible to empower volunteer contributors without
overburdening them.
For restoring, we agreed that it should happen in an in-person meeting. The
process requires three shard holders meet with one encrypted backup holder,
then the results need be given to a signing server operator. Requiring an
in-person meeting could delay the restore process, but the added trust
seemed worth it. So this is the default process. We could still switch to
partially online process if the need arises. That would require the
agreement of five participants.
We believe this is a secure and reliable backup procedure for very sensitive
data. We welcome further scrutiny and plan to update the procedure as
needed in a future meeting.
(This meeting was paid for by the FFDW-DVD grant.)
Video by via Dailymotion Source Glumac/GlumicaSerhat TutumluerCeyda DüvenciÖzge ÖzderHale AkınlıBennu YıldırımlarBatuhan KaracakayaSongül ÖdenMelda AratCenk Ertanİlker Kurtİncilay ŞahinMetin BüktelEvrim SolmazServer MutluEce HakimDevrim ÖzderErdal BilingenFurkan Andıç Go to Source
Video by via Dailymotion Source Technical Learning Color Balance | Photoshop Color Balance | Color Balance Photoshop | Photo Editing In this Photoshop tutorial i will show you the best way to color balance and color correction in Photoshop in Hindi. This is amazing trick to make portrait photo awesome. In this video i have … Read more
Video by via Dailymotion Source Tips and advice on growing Cosmos flowers this season. Go to Source
Video by via Dailymotion Source Quran Suniye Aur Sunaiye – Surah e Hijr (15) – Ayat 71-72 Topic: Auliya Allah ki Alamat Host: Mufti Muhammad Sohail Raza Amjadi #QuranSuniyeAurSunaiye #MuftiSuhailRazaAmjadi #ARYQtv Watch All Episodes || https://bit.ly/3oNubLx Subscribe Here: https://bit.ly/3dh3Yj1 In this program Mufti Suhail Raza Amjadi teaches how the Quran is recited correctly along with … Read more
Video by via Dailymotion Source Luiz Inácio Lula da Silva (PT) lamentou os ataques ao ministro do Supremo Tribunal Federal (STF), Alexandre de Moraes, e se referiu aos apoiadores radicais de Jair Bolsonaro (PL) como ”malucos” Go to Source
Video by via Dailymotion Source That’s exciting news! It sounds like the “Mysterious Building” has been shrouded in curiosity and speculation for quite some time. With its recent opening, people must be eager to explore and discover what secrets it holds. As an AI language model, I don’t have access to real-time information beyond my … Read more
#ShaneBabaFareedRA #TalkShow #ARYQtv
Official Facebook: https://www.facebook.com/ARYQTV/
Official Website: https://aryqtv.tv/
Watch ARY Qtv Live: http://live.aryqtv.tv/
Programs Schedule: https://aryqtv.tv/schedule/
Islamic Information: https://bit.ly/2MfIF4P
Android App: https://bit.ly/33wgto4
Ios App: https://apple.co/2v3zoXW