keybase / keybase/keybase-issues

generic_web_site proofs shouldn’t allow non-https URLs

Open
#1,218 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

The more I think about this the more it bothers me. As it stands, this proof is _way_ easier for a bad guy to fake than all the others. Firesheep could do it.

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue identifies the generic_web_site proof and the requirement that it reject non-HTTPS URLs; no file or test is named. Start by locating the proof-validation entry point, then verify the behavior against existing proof checks and ensure non-HTTPS URLs are rejected.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.