keybase / keybase/client

Auto-update UI messages are suspicious

Open
#11,317 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
9.2k
Forks
1.3k
Avg merge
12h 58m
Merged PRs (30d)
56

Description

I'm raising this issue as a UI/UX request to make auto-updating less suspicious. In the latest update, the attached dialog appears suddenly and notifies me I'm about to be asked for my password.

![screen shot](https://user-images.githubusercontent.com/644072/38513200-7003b3e4-3bfb-11e8-8737-2cb1f68290ec.jpeg)

I can't verify the source of this message, so it was unclear to me whether the dialog is legitimate. It's also not clear to me what the consequences are of not providing my password.

* I did not opt-in to Keybase auto-updates. It's not clear to me whether such an option exists.
* Keybase does not notify me when an update is in progress.
* Changelogs are available, but only after I run `keybase update check` and inspect the debug output for the JSON log. To make matters worse, I only know to do this *after* I notice an update (or in this case, a request for my password).

I understand the software likely needs elevated permissions to perform some system functions. However, I think Keybase could be substantially more transparent about what is happening and why.

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no source file, test, or entry point. Start by tracing the auto-update experience that produces the attached password dialog and document the existing opt-in, progress, consequence, and changelog behavior. Done means the UI/UX proposal clearly explains why an update is occurring, whether it was opted into, and what happens if the password is not provided.

Written by the indexing model from the issue text.

Assessment

Domain
desktop, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.