keybase / keybase/keybase-issues
Stop encouraging users to upload private keys.
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
I'm not sure if this has already been discussed but [every](http://technet.microsoft.com/en-us/library/cc962023.aspx), [single](https://www.gnupg.org/gph/en/manual/c481.html#AEN506), [place](https://isc.sans.edu/diary/A+Reminder%3A+Private+Key+Security/12817), [you](https://www.thawte.com/code-signing/whitepaper/best-practices-for-code-signing-certificates.pdf), [look](https://help.ubuntu.com/community/GnuPrivacyGuardHowto#Backing_up_your_private_key), securing your private key is of the utmost importance.
Encouraging private keys (especially since this service is meant to make PGP easy) to be tossed to an online server is extremely bad practice and **should be discouraged**, if not disallowed.
With all the elimination of trust Keybase promises with publicly auditable proofs, why would you make people upload keys to your server?
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue identifies a security concern about uploading private keys but names no files, tests, or implementation entry points. Review the existing discussion and current key-upload behavior, then define whether the desired outcome is discouragement or disallowing uploads before implementation.
Written by the indexing model from the issue text.
Assessment
- Domain
- cryptography, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100