keybase / keybase/keybase-issues
Ability to create a Keybase profile for a website as a whole
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
Keybase is currently for _individuals,_ and can be used to send encrypted messages & verify that messages are from known recipients. But another important security problem in email is phishing, i.e. messages that appear to come from people or groups which actually don't. Why don't we allow non-individual entities, e.g. a website, to create its own Keybase profile? Then they can send signed email messages for newsletters and individual updates which recipients will know came from the website. So for example if OKCupid had a keybase account, e.g. keybase.io/okcupid, which can have a public key verified with the website domain. Then when the website sends a password reset email, for example, which is one potential vector for a phishing attack, they can sign the message and recipients who have PGP set up will know that it was actually sent from the right site.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the issue's proposal for non-individual Keybase profiles, website-domain verification, and signed email. Determine the required product and trust-model changes for a site-wide profile, then document a concrete design and acceptance criteria for recipients to verify messages from the website.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100