Security Party in Switzerland this Week

On the evening of Friday, the 23rd of October 2009 will be held a somewhat end user-oriented conference on the theme of Cryptography, SSL/TLS and trust networks, with the opportunity to sign GPG keys and be assured by CAcert.org assurers. This conference will be held in Switzerland, at the University of Applied Science – HES-SO / HE-Arc Ingénierie in St-Imier (BE).

You can find details on Linux User Group – Neuchâtel

Registration is not required – if you want to participate in GPG key signing, please send your GPG key info and fingerprint until Monday 19 to: schaefer (at) alphanet (dot) ch – and Entrance is free.

This conference is co-organized by HE-Arc / ISIC, Linux User Group – Neuchâtel and by individual CAcert.org Assurers.

———————————————————————————————————————————————————————————-

Le soir du vendredi 23 octobre 2009 aura lieu à l’Institut des systèmes d’information et de communications de la Haute Ecole Arc ingénierie – HES-SO à St-Imier (BE) en Suisse une conférence sur le thème de la cryptographie, de SSL/TLS et des réseaux de confiance, avec l’opportunité de signer des clés GPG et d’être vérifié par des assureurs CAcert.

Détails ici, Groupe d’Utilisateurs Linux – Neuchâtel

Inscription non nécessaire – mais vous devez envoyer vos informations de clés publique GPG et empreinte à: schaefer (arobas) alphanet (point) ch, si vous voulez participer à la signature de votre clé. Entrée gratuite.

Cette conférence est co-organisée par la HE-Arc / ISIC, Groupe d’Utilisateurs Linux – Neuchâtel et des assureurs individuels de CAcert.org.

The Future Of Identity will not be found in Britain

Commentary, rants, not warnings of Downtime! Dave Birch runs a blog called Digital Identity to promote his consulting company (CHYP or Consult-Hyperion) which specialises in Money and Identity systems. His recent post on British experiences with Identity things is of interest to people here. Here’s a quick summary:

  • A French ID card can be used to get you a job at Sainsbury’s, but not to buy alcohol.
  • Banks can tell whether local passports are real, but foreign passports are just accepted. Because they can’t tell, they don’t.
  • Remember the Irish Police force’s search for their most wanted speedster: Mr Prawo Jazdy. Once they translated the term into “driving licence” in Polish … all became clear.
  • A car owner was arrested because his new form was a slightly different colour. The registration people thought it was a forgery and called the police…
  • You can call the UK Border hotline to confirm a national ID card. They will tell you “to ask [your] customer for a ‘second proof of identity’.”
  • It’s a smart card, and the smart way to check it is “to flick the card and listen for a distinctive sound, if they doubt the card’s authenticity.”
  • More here on how it is easier to get a bank account if you are a criminal or a foreigner than a poor unidentified person.

That’s all good fun! We know where all this is going … indeed, one of the strengths of the CAcert Assurance Process is just this. Working with the documents might be called a competence of CAcert, if we were into management-speak.

Read the whole article for the fuller picture; it’s fun. One thing I will disagree with Dave on is his recommendation that there be a digital solution that either works or it doesn’t. Although I frequently remind people that, in a well designed security system, “There is only one mode, and it is secure,” I think actually it is a hopeless goal to expect the British government to field such a system. They will create a pink elephant.

Far better for new identity systems to emerge from the marketplace. As suggested by Dave, this is likely to be the mobile phone. We are around 80% of the way there; and with things like Android, the other 20% is now on the marketplace. Soon enough…

planned Maintainance

The Admin-Team is going to implement a change to the main website tonight, that
will increase the speed of the website.
There is currently expected a downtime of parts of the website (login,
certificate issueing) for a few minutes during the implementation.

ITK Forum in Mühldorf

Das 2. ITK-Forum Mittelstand am 28. Oktober 2009 findet in Haberkasten Mühldorf (90km östlich von München) mit CAcert Beteiligung statt.

Die Veranstaltung findet am 28. Oktober 2009 von 13 bis 17:30 Uhr statt und der Eintritt ist frei – Reservierungen vorab sind gewünscht.

Weitere Infos sind unter http://wiki.cacert.org/events/ITK-Forum-Mühldorf2009 zu finden.

Thawte Web of Trust Shutting Down

Thawte’s Web Of Trust is to be Terminated by 16th November

Therefore the board is planning to run the Tverify program until that time, then terminate it completely (as the information will no longer be available).

Then, members who have come in via Tverify will have a year to get assured by other means. This includes members who have obtained points from Tverify in the past.

Tverify is now operating under the authority of board motion m20090928.1 and under the Assurance Policy. This latter means no issues of points over 50, and the earlier includes some restrictions.

However, note that all Tverify points (including ones previously obtained), will be deleted late 2010, so it is best to get assured by CAcert assurers anyway. If you can reach a few of them it may be easier all round if you do that instead of using the Tverify process.

See http://wiki.cacert.org/ThawteNotary for more details. (Disclaimer: that wiki page is not an official statement of the committee)

For the committee of management (board) of CAcert Incorporated,

Nicholas E. Bebout
President
CAcert Incorporated

Ask not what your country can do for you…

John F Kennedy inspired a nation by saying that. Then he said:

“ask what you can do for your country!”

What can you do for your community? Here’s one idea I’ve been playing around with. I call it Adopt-A-Page but I reckon there is a better title out there for it. It works like this:

  1. Identify your place inside the Community. Sysadm? Assurer? Coder? Arbitrator? Cert-user? There are lots of possibilities.
  2. Find your favourite CAcert.org web page that relates to your part in the Community.
  3. Link to that place from your many websites.
  4. Keep it live and relevant. Update your collection from time to time.

That was easy! Why is this so important? Another easy question with a simple answer: FUNDING. CAcert needs money to finance the current audit work programme and the next audit. We can get that by (a) being a source of advertising and (b) by being higher profile.

Both of those things can be helped by YOU linking into CAcert. That’s because a little help by you, multipled by the size of our community, equals a lot of help!

It really doesn’t matter where you link in to. You choose. What matters more is that you use diverse websites, if you have them to hand.

This is one thing you can do for your Community!. Point your website to us. Proclaim your ability as an Assurer. Tell the world which system you administer. Tell us you care. Loudly! Tell us you’re part of the community. Hell, tell us anything you like, as long as it includes a link 🙂

Linux Info Tag Landau 2009

Der Linux Info Tag am 10. Oktober 2009 in Landau (Rheinland-Pfalz) findet wie jedes Jahr auch dieses Jahr wieder mit einem kleinen aber feinen Programm im Kreuz+Quer in Landau statt. Auch dieses Jahr wird es die Möglichkeit geben sich über CAcet, Zertifikate und Sicherheit am Computer zu informieren, sowie eine Assurance durchführen zu lassen.
Weitere Infos und die Möglichkeit sich anzumelden gibt es im CAcert-wiki.

CAcert Blog is fully X.509 enabled

The CAcert-Blog is now fully X509 enabled.
From never visited the site before and using a named certificate you can, with one click (log in), register for the site and have author status ready to write your own contribution.

If you only have a WoT unnamed certificate you can write your article and it will be spam controlled by the PR people (aka editors).

If you had a contributor account and haven’t posted anything yet you have been downgraded to a subscriber (no comment or write a post access) with all the other spammers. The good news is once you log in with a certificate you get upgraded to the correct status just as if you’d registered.

There is no password authentication any more. The time taken to make sure both behaved reliably was not possible in the time the admins had available.

Please ignore the big blog upgrade notice – we are using Debian security maintained packages and don’t need a WordPress upgrade.

So get to it – write something interesting.
[Edits thanks to Henrik Heigl]

CAcert auf der 1. IT & Business Messe Stuttgart 6.-8.10.2009

CAcert wird auf der 1. IT & Business Messe Stuttgart vom 6. bis 8. Oktober 2009 mit einem Demo Point Neue Messe Stuttgart (Flughafen), Halle/Stand: 1H12-3 im Themenpark “Open Source Business Solutions” vertreten sein.
Continue reading

CAcert at NLUUG Fall Conference – The Open Web

On Oct 29, 2009 the NLUUG will keep its Fall Conference – The Open Web.
One of the speakers, Henk Klöpping, will mention CAcert in his talk The Shameless Plug.
As it is custom CAcert wil have a boot there.
If you want to help and have successfully passed the Assurer Challenge pleace add your name on the list at the CAcert wiki.