keybase / keybase/keybase-issues

Ability to create a Keybase profile for a website as a whole

Open
#1,061 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

Keybase is currently for _individuals,_ and can be used to send encrypted messages & verify that messages are from known recipients. But another important security problem in email is phishing, i.e. messages that appear to come from people or groups which actually don't. Why don't we allow non-individual entities, e.g. a website, to create its own Keybase profile? Then they can send signed email messages for newsletters and individual updates which recipients will know came from the website. So for example if OKCupid had a keybase account, e.g. keybase.io/okcupid, which can have a public key verified with the website domain. Then when the website sends a password reset email, for example, which is one potential vector for a phishing attack, they can sign the message and recipients who have PGP set up will know that it was actually sent from the right site.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the issue's proposal for non-individual Keybase profiles, website-domain verification, and signed email. Determine the required product and trust-model changes for a site-wide profile, then document a concrete design and acceptance criteria for recipients to verify messages from the website.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.