Debian Bug report logs - #668347
ITP: d0-blind-id -- library for user identification using RSA blind signatures

Package: wnpp; Maintainer for wnpp is wnpp@debian.org;

Reported by: Simon McVittie <smcv@debian.org>

Date: Wed, 11 Apr 2012 08:39:01 UTC

Owned by: David Bate <david@bate.org.uk>

Severity: wishlist

Blocking fix for 646377: ITP: xonotic -- a fast-paced first-person shooter, 652837: ITP: xonotic -- a fast-paced first-person shooter, 660636: ITP: xonotic -- a fast-paced first-person shooter

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, debian-devel-games@lists.debian.org, wnpp@debian.org:
Bug#668347; Package wnpp. (Wed, 11 Apr 2012 08:39:04 GMT) Full text and rfc822 format available.

Acknowledgement sent to Simon McVittie <smcv@debian.org>:
New Bug report received and forwarded. Copy sent to debian-devel-games@lists.debian.org, wnpp@debian.org. (Wed, 11 Apr 2012 08:39:04 GMT) Full text and rfc822 format available.

Message #5 received at submit@bugs.debian.org (full text, mbox):

From: Simon McVittie <smcv@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: RFP: d0-blind-id -- library for user identification using RSA blind signatures
Date: Wed, 11 Apr 2012 09:35:01 +0100
Package: wnpp
Severity: wishlist
X-Debbugs-Cc: debian-devel-games@lists.debian.org

* Package name    : d0-blind-id (upstream name: d0_blind_id)
  Version         : 0.5
  Upstream Author : Rudolf Polzer <divverent@xonotic.org>
* URL             : https://github.com/divVerent/d0_blind_id
* License         : 3-clause BSD
  Programming Lang: C
  Description     : library for user identification using RSA blind
signatures

d0_blind_id is an implementation of RSA "blind signatures",
Diffie-Hellmann key exchange and Schnorr identification. It can be used
by the DarkPlaces game engine (as used in Xonotic) to perform anonymous
 registration with a central server, providing cryptographic identities
which are used in Xonotic for access control on individual game servers.

This implementation has not been audited independently, and is not
currently recommended for non-game uses.

---

Xonotic upstream tell me that they would prefer Xonotic to not be
packaged at all than to be packaged without d0-blind-id support.

I'm happy to co-maintain/provide advice (I maintain other libraries),
but as with Xonotic itself, I'm not willing to be the only maintainer
for something I don't use myself.

Suggested binary packages: libd0-rijndael0 (AES implementation),
libd0-blind-id0 (the rest), libd0-blind-id-dev.

Privacy implications:

According to the Xonotic developers I spoke to, registration is normally
carried out automatically, once per user of Xonotic. The centralized
Xonotic server performs a "blind signature" on a public key generated by
the user, so it knows the IP address used for registration, but not the
public key or anything else about the user's identity. Individual game
servers receive the user's public key, the blind signature, and the
"blinding factor" necessary to check that the blind signature is valid.

The use of signatures and a centralized server (rather than just having
users present an unsigned public key) seems to be intended to allow
users to be banned from a game server, in the same way server admins for
proprietary games can ban users by an identity corresponding to their
purchase (Steam ID, battle.net ID, Quake III Arena, CD-key, or
whatever). Creation of identities is rate-limited by the server.




Added indication that bug 668347 blocks 646377,652837,660636 Request was from Simon McVittie <smcv@debian.org> to control@bugs.debian.org. (Wed, 11 Apr 2012 08:57:06 GMT) Full text and rfc822 format available.

Changed Bug title to 'ITP: d0-blind-id -- library for user identification using RSA blind signatures' from 'RFP: d0-blind-id -- library for user identification using RSA blind signatures' Request was from David Bate <davebate@gmail.com> to control@bugs.debian.org. (Thu, 12 Apr 2012 16:04:19 GMT) Full text and rfc822 format available.

Owner recorded as David Bate <davebate@gmail.com>. Request was from David Bate <davebate@gmail.com> to control@bugs.debian.org. (Thu, 12 Apr 2012 16:04:25 GMT) Full text and rfc822 format available.

Added blocking bug(s) of 668347: 675035 Request was from Bart Martens <bartm@quantz.debian.org> to control@bugs.debian.org. (Fri, 22 Jun 2012 15:39:52 GMT) Full text and rfc822 format available.

Owner changed from David Bate <davebate@gmail.com> to David Bate <david@bate.org.uk>. Request was from David Bate <david@bate.org.uk> to control@bugs.debian.org. (Thu, 13 Jun 2013 09:21:09 GMT) Full text and rfc822 format available.

Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Apr 23 15:02:03 2014; Machine Name: beach.debian.org

Debian Bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.