Does Keybase use Android App Bundles?
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 9.2k
- Forks
- 1.3k
- Avg merge
- 12h 58m
- Merged PRs (30d)
- 56
Description
It was speculated in another issue that Keybase may be building APKs using Android App Bundles.
The implication of this would be that Google posses the private keys that the Keybase APK is signed with. Some users may be okay with this, while others would consider this a reason to steer clear from Keybase (depending on their threat/adversary models).
Could someone from the Keybase team please let us know whether this is the case? Thanks! 😄
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No source file, test, or entry point is identified in the issue. Start by checking the Android release and signing configuration referenced by the project, then document whether Android App Bundles are used and who controls the APK signing keys.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- android
- Domain
- mobile, security
- Issue type
- Documentation
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100