Facebook and OpenPGP

Melvin Carvalho melvincarvalho at gmail.com
Thu Oct 1 22:35:02 CEST 2015


On 1 October 2015 at 22:30, Kristian Fiskerstrand <
kristian.fiskerstrand at sumptuouscapital.com> wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA512
>
> On 10/01/2015 10:28 PM, Melvin Carvalho wrote:
> >
> >
>
> ...
>
> >
> > Reference:
> > https://developers.facebook.com/docs/graph-api/reference/user
> >
> >
> > Quick question:  I just uploaded my key and the dropdown said
> > "public" ... does this mean I can get at it without an access
> > token?  That would be super cool!
> >
> >
>
> I was actually looking into the same thing myself by trying something
> as simplistic as curl queries for the API :) Another thing that
> strikes me, but granted I haven't done much research, is that the key
> can't be requested by username, only by user id. So if anyone were to
> want to using it as a keyserver / CA of sorts to establish identity
> for a user profile they believe to be genuine, they couldn't do so
> from outside of FB.
>

It works!  I found how:

curl  https://www.facebook.com/melvo/publickey/download/

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.4.11 (GNU/Linux)

mQENBE3ZoEcBCADXmHWK/QhE82aPiOco5zWzTpRwbbzcerhYMUArsEOohQin18Tr
Ri2v2Rfm0wWPWVl8VHOfgwu/+f9ddAyQasSA7+PhydCo5X3oGph6f9DBtotLTKHk
NK7AfE9DzQSKhuCF0o9ps+l8hE067bdJwnNjnwq/7z1YKf6FZ3s0NkcBEy5EWbla
zDNHBPgMTePg558hrPKCxAHnPn5Xf7vBlakRMuIVxBEZG648Z+0cPRKTSpqFE7vo
qvxuAkcBoVlbhIwf5bX2rJOJHjOePRgdSLOleuhitQCWpAVw3eez+p8UmnL1vH1d
wgCZzSYBXiD389xhG2byx4SZfZk7mJnHr9JfABEBAAG0Kk1lbHZpbiBDYXJ2YWxo
byA8bWVsdmluY2FydmFsaG9AZ21haWwuY29tPokBOAQTAQIAIgUCTdmgRwIbAwYL
CQgHAwIGFQgCCQoLBBYCAwECHgECF4AACgkQEU73vJRgRYPfBwf+O2uf1fKenDQh
qnrlMGC2n2XU/JRX5dhiRtKYkoYi8dFELMFJg/ng2FOc7DalQw/PGIaXIiuxg23r
K3Eq6hCzx+cYiSTKjnqD/QkhYAfjdD8PsIatGwu+/OF53NXA6hjveOHyo5c/Lq51
Jh7cZRd5AJko8Kk3toCqZKJhfbZ9+e49HsIj0i0qrtyD/7hR9UYl2wEJQ91H6fZg
7DvfrlA9aywAx6cvo0p9BBvX4hLMd9dPfL35UjVq4xJUBsgpf9By70Yw6SRgPGyz
9vyM6Ka0lXm65BvIsalgvhkR72E5Zi7M+lfO0HgZa2DgeObEi7yx2NfwGrJkIYyD
33Xw5xh017kBDQRN2aBHAQgArxEdGGZCNPAPjLf0bdi6rILv2seRiggU6f7SC8+G
hAFjPnBAUV+ccC/1NIUr10HHOWDKWLqdBqLk7rJoDdjFGeoS18auISgk+h3kTsSY
dMi/o3TmHFmVPX6dMjSL2rac7GrNKL70Dg8gZ3ku7VmaueoG+H592sYxc32cr+MM
MFRFP5sai2hClug4qCgnt2pFtcvmlT2yk5YXNpgnjXHjUcEzn6FwonKcjISezTE8
I1RYltFef/7R40rF/h+6JQSO2eOdMtlKv3cfdxd08CpynMjtN3YTGW709hwW3/J/
lGenSTDF8OLEIhvm4sELUCpCaL6WTf7xdQNWkShPgX2HOwARAQABiQEfBBgBAgAJ
BQJN2aBHAhsMAAoJEBFO97yUYEWD2E0H/idszAlTu5WhjSjYZL79qNwWuA0qjJtf
4Bm5BOYEItGAhNt8vpweGw+KRvn3+KdfvYXe49fShY3TFvgTjloR6yKY1SKvYbUu
TojGAI798vh68dLoBJGWHfh0fmcSYE0O6SaBiBWRHnszBfsOTSiF3FKE3NxKsC6u
zXYBuT8sgFn8RLILRiWeBZZXkzq4CYjNNnuxWqv9tW0NkRvjwQUR32L3o7sEYHiE
UDi6nCOUeG3rXfpzITHB+TvIGCG7ZPjkyfqRGxb9c6Je3pm76UtGOkLCYJwoeD38
aWWdvQyNlhT4sq5U9KDZifaQ0gVsW+PKuU8TCXECJ0SJVPaKAwauhfw=
=QoVU
-----END PGP PUBLIC KEY BLOCK-----

curl -I  https://www.facebook.com/melvo/publickey/download/
HTTP/1.1 200 OK
Content-Disposition: attachment; filename="melvo.asc"
X-Content-Type-Options: nosniff
Content-Type: application/pgp-keys


First class work!



>
> - --
> - ----------------------------
> Kristian Fiskerstrand
> Blog: http://blog.sumptuouscapital.com
> Twitter: @krifisk
> - ----------------------------
> Public OpenPGP key 0xE3EDFAE3 at hkp://pool.sks-keyservers.net
> fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3
> - ----------------------------
> Aut disce aut discede
> Either learn or leave
> -----BEGIN PGP SIGNATURE-----
>
> iQEcBAEBCgAGBQJWDZf9AAoJECULev7WN52FFpsH/jbC5TZCvJxQSZVmNt6ENQal
> k0GWRjzQ5wuwju3QxKr8fCSSK6HV6jzn9Jd3WGY6BmxaIlQPJPz1YmP/IbDp+lsk
> WR6LQUDp5boje6vFprK6nM87wQU6qEPpw56rDJN6IBhYRHCQYbM7IPOYYXltLTa5
> OuuP4KxBhWVJz3Yytq8u1ZHY+RTuO0S3Oy/jz6lFQ9/OFOUvovub9FkFqTwHtOyy
> ndkEb26g8e2A1yt13c0Eu8gufWeG3H+AkZiN6+yb34XOFcemrP3SpWkNWLUKeiqj
> OoKRfJMR4XKEdUaJmdP0ZjuN2HBc9xsnYoln561wM+qwJsmPZFvUZH4G5H+vbUc=
> =yw8Q
> -----END PGP SIGNATURE-----
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: </pipermail/attachments/20151001/48f5aa29/attachment.html>


More information about the Gnupg-users mailing list