keybase / keybase/client

Is the gist clone vulnerability fixed?

Open
#17,228 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
9.2k
Forks
1.3k
PR merge metrics
PR metrics pending

Description

User @tomnomnom raised some vulnerabilities related to proofs on github in this article:
https://dev.to/edoverflow/an-analysis-of-logic-flaws-in-web-of-trust-services--3bhj

Particularly the possibility to clone a gist and claim another user's identity. Has this been fixed? If so where? What PR or commit?

What about the namespace attack? His article says:

> Keybase remain vulnerable to attack vectors 2 and 3 — as far as I can tell they do not plan on resolving those issues.

Is this true? If so it is concerning.

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or entry points are named. Start with the linked dev.to analysis and the issue history, then trace any referenced Keybase changes; done means identifying whether the gist-clone and namespace attacks are fixed and citing the relevant PR or commit, or documenting that they remain unresolved.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, go
Domain
authentication, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.