keybase / keybase/client

[Android] POTENTIAL VULNERABILITY: Paper key proofs use normal TextView, not Password

Open
#7,173 15 comments 3 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
9.2k
Forks
1.3k
Avg merge
12h 58m
Merged PRs (30d)
56

Description

The TextView used for entering a paper key to prove a device should be configured as a password field to prevent non-malicious keyboard applications from including the pattern of words in their completion history and statistics. This poses a potential compromise of the paper key, especially with the remote storage of patterns that many keyboards do.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the Android device-proofing screen that uses a TextView for paper-key entry and trace how that field is configured. Verify the field uses password-style input that prevents keyboard completion history and statistics from recording the words, then test the paper-key flow on Android.

Written by the indexing model from the issue text.

Assessment

Tech stack
android
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.