-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 I, "Etaoin" Wu , maintain a PGP key. The following is my signing policy, and it applies to any signatures that point to this document as the policy URL. Permanent URL: https://etaoinwu.com/pgp/policy-2025.07.txt My current public key, available at , has the following summary: pub ed25519 2023-07-27 [C] E92890319B42A0646DDB3B351145533998244353 uid Etaoin Wu uid Etaoin Wu (backup) sub ed25519 2024-09-28 [S] [expires: 2027-01-05] sub ed25519 2024-08-07 [A] [expires: 2027-01-05] sub cv25519 2024-06-16 [ER] [expires: 2027-01-05] General policy ============== (on e-mail address.) Email verification is required. My certification will only be sent to the UID in the key. Consequently, my certification implies that its holder owns the email inbox. (on preferred names.) I aggressively believe that preferred names shall be respected, and understand that they often differ from legal names. I therefore accept preferred name UIDs. They are harder to verify than legal name UIDs, and I require multiple of the following to accept a preferred-name UID: * Everyday usage. The people around you shall address you with such a name. The bearer shall respond if this name is shouted aloud. * Self-identification usage. The bearer shall use this name in non-cryptographic self-identifying or attributing materials, such as business cards, conference badges, publication bylines, copyright notices, etc.. * Communication usage. The bearer shall use this name in signatures (of letters) and "From" fields in e-mails. This also includes usernames or handles in online IMs and forums. The bearer shall consistently use this name in most, if not all, of such places. Signature levels ================ * Level 1 (persona): I will use this level for online pseudonyms that does not fit the preferred name requirement above, but that I can verify is associated with the holder through multiple online channels. I have made a reasonable attempts to reach this pseudo- nym in different platforms and they all confirm this identity. * Level 0 (generic): I will use this signature level for a group, a project, an organization, or a "key for technical usage". This type of signature indicates that I have reasonable belief that the key is associated with the claimed group. * Level 2 (casual): I will use this level of signature to indicate that I have met the holder of this key in person, AND [(1) a government-issued identity document is verified, OR (2) the aforementioned preferred-name condition is passed]. In addition, the holder must have physically shown me their public key fingerprint, either (preferably) on paper or on on a device in a non-interactive way (e.g. showing a photo on a phone, but not a terminal with `gpg` outputs). * Level 3 (careful): I will only issue this level of signature if, in addition to the level 2 condition, I also personally know the holder in real life, and feel comfortable that you are who you claim to be. The order of levels above is NOT wrong. It's intentionally NOT numerically monotonic, because GnuPG thinks by default that level 1 is not trusted. Remarks ======= This is the first version of this document. This document is signed: -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQTTI5EvOG7OwW1nI56Dvsq+mZmZiQUCaIZtzQAKCRCDvsq+mZmZ ieiMAP9cvXWLIkniVc+lvFBvJXRb400sX9NpsGt7iRdVxcXYmgEA36ylRFbfOPgo l6Oo1qvBRG3AXdty2EkrqaiRcCipXg0= =aghk -----END PGP SIGNATURE-----