keybase / keybase/keybase-issues
Feature requests
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
- 1. More flexible profile verification
It would be nice to not be limited to a predefined set of services, like if I prefer gitorious to github, or if I want to prove my identity on other web profiles where I can't upload a text file nor set DNS records.
It should be possible for users add new external sites, either by a system of vote so the keybase developers add it, or by a system allowing the users to define the name of the site, the url pattern for the site's user profiles, and a part of their profile page (or some other page on the service, like on reddit currently) that they can control to provide the verification, for instance.
- 2. Possibility of proving web identities for Tor Hidden Services and I2P EepSites
It could work just like web identities do now, except the verification would need to be done over Tor / I2P.
For those who wonder the interest of proving the identity behind an technically anonymous service, remember that the anonymities to protect can be the ones of the visitors, and that a GPG key can also be anonymous/pseudonymous.
Of course, it would be nice to be able to combine these two feature requests.
- 3. Possibility to prove ownership of email addresses
The verification could be done like once a month by sending an email that should be replied to within a week with a signed message.
I'm actually not sure this one is very relevant.
Maybe something similar for IRC nicknames ?
- 4. Make Keybase an OpenID provider
I just think it would make sense, but really that may just be me :).
- 5. Make the server side of Keybase open source and decentralized/federated
I know this may be a hard challenge (for the second part of the request) because of Zooko's triangle, but really it's a bit sad to think that the GPG web-of-trust has to be replaced with a centralized service that becomes a point of failure: if keybase.io disappears or change its mind for whatever reasons (that may not be its own choice) all the existing verifications are made useless because they actively depend on the centralized server.
EDIT: I now understand that the verification is done entirely on the client side and does not depend on keybase.io which only provide the proof that needs to be verified. Cool. So what I think should be decentralized is only the user-friendly directory feature ("I have this twitter username, I want its public key"), which is technically distinct from the identity ownership claims.
In any case, thanks a lot for trying to improve the user-friendliness of end-to-end crypto for people :).
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue names no files, tests, or entry points and combines five separate proposals. It needs to be split into independently scoped issues before a contributor can identify the affected area or determine what completion means.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 10/100