keybase / keybase/keybase-issues

Stop encouraging users to upload private keys.

Open
#1,127 10 comments 5 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

I'm not sure if this has already been discussed but [every](http://technet.microsoft.com/en-us/library/cc962023.aspx), [single](https://www.gnupg.org/gph/en/manual/c481.html#AEN506), [place](https://isc.sans.edu/diary/A+Reminder%3A+Private+Key+Security/12817), [you](https://www.thawte.com/code-signing/whitepaper/best-practices-for-code-signing-certificates.pdf), [look](https://help.ubuntu.com/community/GnuPrivacyGuardHowto#Backing_up_your_private_key), securing your private key is of the utmost importance.

Encouraging private keys (especially since this service is meant to make PGP easy) to be tossed to an online server is extremely bad practice and **should be discouraged**, if not disallowed.

With all the elimination of trust Keybase promises with publicly auditable proofs, why would you make people upload keys to your server?

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue identifies a security concern about uploading private keys but names no files, tests, or implementation entry points. Review the existing discussion and current key-upload behavior, then define whether the desired outcome is discouragement or disallowing uploads before implementation.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.