-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Hi Radoslaw, thank you very much for your reply!
Radoslaw Szkodzinski:
> Easy to answer: The proof of freshness is simply to show these
> were not made ahead of time and then released later after a
> compromise to fool everyone.
Could you please tell me "these were not made ahead of time" by whom?
If it is used to prove "these were not made ahead of time" by Qubes
developers, then it is assuming that we do not trust the Qubes
developers who made and signed the warrant.
1. But if we do not trust them not signing the warrant in advance, why
can we trust what they said in the warrant? Won't the whole warrant
become meaningless?
2. Besides, if we do not trust them, we can even assume they are just
using a script that can generate, sign and publish the warrant
automatically every certain length of time.
If we trust the Qubes developers who made and signed the warrant,
shouldn't the system date included in the signed message blocks be
enough to prove the freshness?
If it is used to prove "these were not made ahead of time" by an
adversary, then it may make a little bit more sense.
Thank you very much! I am Looking forward to a further discussion!
Best,
iry
-----BEGIN PGP SIGNATURE-----
iQIcBAEBCgAGBQJY3+W0AAoJEKFLTbxtzdU8QUAP/0zHrM8xyyZ8TngQsDvXMFed
wKG1Fsg1t0gOM6sZKPtR2hmpEQ6f4Hx5hqhySP0r5dZBRAhLKoUdn0h318tdwA0y
f84utL49PY+wkqWteb80daoI1EcUw5s/2xNewbtmw5Xa6VYCrB4jxNAtvt9sZzu6
JbbyZtsSO+ir0xOyLnB2dqREbvo5D1jJ8r10YixafToc5WLKUAQWQ51LXViHk6Sa
dh5Cgc7OvjL3OSA+mxfn2uWPra80EBAGDmZiAFMrHj1p1mk9K9JIqske51e15jKO
W253tjrZA+QoBIDwpcYRDbzoCfqJ3cHIwThPkemu9KU/AWLKQJ1JsrqKLdLi95zF
Glqy7Ae7Nghb3FntQ0zDQRK0nTXAcmshKQfk4CQ9qMCQOIM0czScUT6DK8UMyaZi
1X9wPa9+ZkF3ur6GVKYGo9HYp6+DvQ+jtoqs5TC620PqnPdN7Wt+Fh5t4cCq0vlD
jjvZEEQJSn1ZSX7A5wGgEyQgrU5z7HcRsZQ20LnqEM3D3dUJWtIamg+RjavVi0zB
CSC5LvS1VrFMLhxBKdVBMvOHep22V48uypv9t+QZR5JLieNiAlBbXoXwCqnhVj6R
ZSAQXfjy2ghCfhkJEMfeCYvDBIrVa4iOf4oXDkmT8icl1R2zxS4Lt0zrqvZ2eRqU
MmGh7sVzMx02hOjyZibu
=NMVC
-----END PGP SIGNATURE-----