Is the gist clone vulnerability fixed?
- Dominant language
- Go
- Stars
- 9.2k
- Forks
- 1.3k
- PR merge metrics
- PR metrics pending
Description
User @tomnomnom raised some vulnerabilities related to proofs on github in this article:
https://dev.to/edoverflow/an-analysis-of-logic-flaws-in-web-of-trust-services--3bhj
Particularly the possibility to clone a gist and claim another user's identity. Has this been fixed? If so where? What PR or commit?
What about the namespace attack? His article says:
> Keybase remain vulnerable to attack vectors 2 and 3 — as far as I can tell they do not plan on resolving those issues.
Is this true? If so it is concerning.
Contributor guide
No contributing guide indexed for this repository
Research direction
No files, tests, or entry points are named. Start with the linked dev.to analysis and the issue history, then trace any referenced Keybase changes; done means identifying whether the gist-clone and namespace attacks are fixed and citing the relevant PR or commit, or documenting that they remain unresolved.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github, go
- Domain
- authentication, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100