Device Reauthentication
- Dominant language
- Go
- Stars
- 9.2k
- Forks
- 1.3k
- PR merge metrics
- PR metrics pending
Description
I recently opened Keybase on my iOS device after not using it for a while, and found that I was logged out. I have access to my other devices, so that in and of itself is not a cause for concern.
However, I quickly found that I am unable to assert that my device is the same as the old one. While I could say this is a new device and revoke the old key, that could quickly make a mess if the issue recurs.
Is there a way to renew or rekey a device without leaving a trail of revoked devices? Perhaps by changing the way new keys are displayed, by grouping different keys that are meant to represent the same device (as designated by the user) within a node? My device graph will quickly become useless otherwise.
Contributor guide
No contributing guide indexed for this repository
Research direction
No files, tests, or entry points are named. Start by reviewing the device reauthentication and device-graph questions in this issue; done would require an agreed design for renewing or rekeying a device without accumulating misleading revoked-device entries.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- ios
- Domain
- authentication, mobile
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100