Assignment 4 — Web of Trust
Assignment 4 is due 10/21/19 on or before 11:59:59pm MST.
Who do you trust? How do you know they are who they say they are?
Your goal in this project is to learn about public key cryptography, gpg, verifying identities, and the web of trust.
You’ll need to: create a gpg public/private keypair, register your public key with the submission server, get your key signed by 20 of your fellow students in this class, and avoid signing any fake keys (you will need to verify your classmate’s identity).
1. Generate a gpg key
Create a public/private keypair for this project that has a name that is exactly what your name is in ASU’s system, has an email (doesn’t matter what the email address is, and does not have a comment.
Other students will need to verify your identity, so the name part must be exact. You can reuse an existing gpg keypair only if the names match, otherwise you’ll need to create a new key for this assignment.
DO NOT LOSE YOUR KEYPAIR
I cannot stress this enough, due to the nature of the assignment, we cannot and will not sign multiple keys for you.
Backup your keypair, if you lose the key once you’ve uploaded it to the server then you will not be able to finish the assignment. Every ASU student has a Dropbox account, so use that or some other mechanism to backup your keypair (including your secret key).
First step is to, once your key is generated, backup your public and private key. Seriously, you’ve been warned.
2. Upload your public key
The server will then check to see if your public key is valid, and only if
it is the server will sign your public key with
the course’s keypair, which has a fingerprint of
710F5B2F13C270CCE5EA7F8E9A28CD9335EF2A2C (you should download this
key, verify the fingerprint, and import it into your gpg keyring).
The server will also generate an adversarial keypair with a random name but with the same email as your key. You will be able to download this adversarial keypair, (both the public and private key).
3. Have your public key signed by at least 20 fellow students (45 points)
Use the Internet to search for great information on signing public keys.
The signatures must be from a valid key in this class: How will you know?
4. Sign at least 20 of your fellow students public keys (45 points)
Using what you learned from the above, you must sign at least 20 of your fellow students' public keys.
Sign more, only valid public keys count.
5. Do not sign invalid keys (10 points)
Of course, the only way that the web of trust works is if keys are signed only when the identify is validated.
If you do not sign any invalid keys that are not your own, you will receive 10 points.
The amount of (negative) points that signing an adversarial key is worth will be determined at the end (along with the positive amount of extra credit for tricking people).
If you trick people to sign your adversarial key, you will earn extra credit (and hacker cred). The amount of extra credit will be determined at the end.
6. Submit your public key and public adversarial key
Finally, submit your public key (with the 20 signatures) and your public adversarial key (if you received any signatures).
You will need to submit your final public key, along with 20 valid signatures (this is included by default when you export your key), and your adversarial public key (if you tricked people into signing the adversarial key).
Your README file must contain your name, ASU ID, and your thoughts on the usability of GPG and key signing, and how you tricked people to sign your adversarial key.
When you submit, you will see how many valid (i.e., signed by the course key) signatures are on your key. Again, this could be adversarial keys, which don’t count for points. Final grading will be done after the assignment is over.
Please don’t forget your password.