PGP
Verify our PGP signatures.
Encrypt what is sensitive.
One key, used for two things: signing our warrant canary and statements, and encrypting anything sensitive you paste in a ticket. Check the fingerprint through a second channel before you trust it.
Fingerprint
9115B17ECE0944BCC461285FF3826B4FF2F38213
Our public key
-----BEGIN PGP PUBLIC KEY BLOCK----- mDMEaraw2xYJKwYBBAHaRw8BAQdA8vWWUL9ODHRPAFEMjadkHMykbZ+6SqwsCK4W 7QfZ2IS0H09mZnNob3JlU2VydiAob2Zmc2hvcmVzZXJ2LmNvbSmImQQTFgoAQQIb AwUJA8JnAAULCQgHAgYVCgkICwIEFgIDAQIeAQIXgBYhBJEVsX7OCUS8xGEoX/OC a0/y84ITBQJqtvUXAhkBAAoJEPOCa0/y84ITXtEA/0EPBuGuKHotrp141ECD2w+z J0BNSrfZi/oGHoykCqpFAQCYy1plvK8cFF5SIpylNFwiYgtFIj8vK/r19x+Ap1uF ALg4BGq2sNwSCisGAQQBl1UBBQEBB0AtNCJ4kQDU5APJ25362qxFw3sjki0cfyt1 jYDVotFrbAMBCAeIfgQYFgoAJhYhBJEVsX7OCUS8xGEoX/OCa0/y84ITBQJqtrDc AhsMBQkDwmcAAAoJEPOCa0/y84IToewA/2dngPZ0m0GNH7OuEmNHSFNo3nsGJbBL oZDNvxrbuN3JAP9Pux8kSiWajKZDeONtRuIUSvZxilteDs8kIJoVIGpnCQ== =U9wv -----END PGP PUBLIC KEY BLOCK-----
What to use it for
- Checking what we sign. Every quarterly warrant canary and our public statements are signed with this key; see how to verify the canary.
- Sensitive messages. Encrypt them with this key and paste the armored text in your ticket: security reports, legal matters, anything you would not send in clear text.
- Encrypted replies. Add your own public key to your message and we encrypt our answer to it.
Import and verify
Import the key, then compare the fingerprint that gpg prints with the one above, character by character:
curl -sO https://offshoreserv.com/pgp/security.asc
gpg --import security.asc
gpg --fingerprint 9115B17ECE0944BCC461285FF3826B4FF2F38213
A fingerprint you read on the same page as the key only proves that the page was not altered in transit. For stronger assurance, compare it with the fingerprint quoted in a signed canary you verified earlier, or load this page again over another network, such as Tor, and compare.
Encrypt a message
gpg --encrypt --armor --recipient 9115B17ECE0944BCC461285FF3826B4FF2F38213 message.txt
Paste the content of the resulting message.txt.asc
Key rotation
The key has an expiry date and is extended or replaced before it lapses. A replacement key is announced here and in the next canary, signed with the old key, so the chain of trust is never broken.