keybase / keybase/client

I looked for a mailing list and I can't find one. I have a bunch of securtiy process questions.

Open
#10,411 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
9.2k
Forks
1.3k
Avg merge
12h 58m
Merged PRs (30d)
56

Description

I looked pretty hard for a mailing list. There doesn't seem to be one, so I'll post my questions here. They do have some overlap; so I think it is appropriate that they all be posted in a single place. Plus, tbh I don't want to monitor a bunch of separate issues for what in a way amounts to one question: does Keybase support aliases (note the plural) in a way that is consistent with modern best practices for opsec?

1. What sort of fingerprinting does the app do, for either the desktop or the phone? How does keybase see each app install? Note that I am not asking how keybase sees each _user_; I'm asking if keybase gets any kind of unique id from a client _aside from the overtly user-entered user info_.

2. To what degree are each of the apps and addons isolated from the browser, the OS, and, most importantly, _other identities the apps and addons may be used with_?

3. Is using all of the apps and addons possible with multiple identities? Or are all of the apps and addons one identity only?

4. If the apps and addons allow multiple identities, what, if anything, makes it possible for an observer to correlate different identities used with the same app or addon? What are the vantages from which the identities are more or less likely to be correlated?

5. Is there now or will there be proxy settings? Where are they? I installed the mobile app and there were no proxy settings provided (or, if they were there, they were unavailable before signing in, which makes them useless for anonymity purposes).

6. For the browser addons, what is the relationship between the apps and the addons? If, for instance, using the addons with a browser set up to use i2p, Tor, or some other proxy, what do the apps do? Do they respect the addon's environments or do they escape entirely?

Bonus question: Are there plans to get the mobile apps up on F-Droid, either with your own repository or otherwise?

I know this isn't the intended way to use an issue entry. But, again, I couldn't find a mailing list and I wanted to make sure these questions were posed where other users could consider them.

Contributor guide

No contributing guide indexed for this repository

Research direction

No source file, test, or implementation entry point is identified. Start by locating the project’s documented security, identity, proxy, mobile, desktop, and browser-addon behavior, then determine which questions can be answered from existing materials. Done means the questions have authoritative, consolidated answers or are redirected to the appropriate support channel.

Written by the indexing model from the issue text.

Assessment

Domain
desktop-dev, documentation, mobile-dev, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.