keybase / keybase/keybase-issues

Feature requests

Open
#1,074 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

- 1. More flexible profile verification

It would be nice to not be limited to a predefined set of services, like if I prefer gitorious to github, or if I want to prove my identity on other web profiles where I can't upload a text file nor set DNS records.

It should be possible for users add new external sites, either by a system of vote so the keybase developers add it, or by a system allowing the users to define the name of the site, the url pattern for the site's user profiles, and a part of their profile page (or some other page on the service, like on reddit currently) that they can control to provide the verification, for instance.
- 2. Possibility of proving web identities for Tor Hidden Services and I2P EepSites

It could work just like web identities do now, except the verification would need to be done over Tor / I2P.

For those who wonder the interest of proving the identity behind an technically anonymous service, remember that the anonymities to protect can be the ones of the visitors, and that a GPG key can also be anonymous/pseudonymous.

Of course, it would be nice to be able to combine these two feature requests.
- 3. Possibility to prove ownership of email addresses

The verification could be done like once a month by sending an email that should be replied to within a week with a signed message.

I'm actually not sure this one is very relevant.

Maybe something similar for IRC nicknames ?
- 4. Make Keybase an OpenID provider

I just think it would make sense, but really that may just be me :).
- 5. Make the server side of Keybase open source and decentralized/federated

I know this may be a hard challenge (for the second part of the request) because of Zooko's triangle, but really it's a bit sad to think that the GPG web-of-trust has to be replaced with a centralized service that becomes a point of failure: if keybase.io disappears or change its mind for whatever reasons (that may not be its own choice) all the existing verifications are made useless because they actively depend on the centralized server.

EDIT: I now understand that the verification is done entirely on the client side and does not depend on keybase.io which only provide the proof that needs to be verified. Cool. So what I think should be decentralized is only the user-friendly directory feature ("I have this twitter username, I want its public key"), which is technically distinct from the identity ownership claims.

In any case, thanks a lot for trying to improve the user-friendliness of end-to-end crypto for people :).

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or entry points and combines five separate proposals. It needs to be split into independently scoped issues before a contributor can identify the affected area or determine what completion means.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
10/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.