keybase / keybase/client

Device Reauthentication

Open
#12,512 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
9.2k
Forks
1.3k
PR merge metrics
PR metrics pending

Description

I recently opened Keybase on my iOS device after not using it for a while, and found that I was logged out. I have access to my other devices, so that in and of itself is not a cause for concern.

However, I quickly found that I am unable to assert that my device is the same as the old one. While I could say this is a new device and revoke the old key, that could quickly make a mess if the issue recurs.

Is there a way to renew or rekey a device without leaving a trail of revoked devices? Perhaps by changing the way new keys are displayed, by grouping different keys that are meant to represent the same device (as designated by the user) within a node? My device graph will quickly become useless otherwise.

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or entry points are named. Start by reviewing the device reauthentication and device-graph questions in this issue; done would require an agreed design for renewing or rekeying a device without accumulating misleading revoked-device entries.

Written by the indexing model from the issue text.

Assessment

Tech stack
ios
Domain
authentication, mobile
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.