keybase / keybase/keybase-issues
generic_web_site proofs shouldn’t allow non-https URLs
Open
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
The more I think about this the more it bothers me. As it stands, this proof is _way_ easier for a bad guy to fake than all the others. Firesheep could do it.
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue identifies the generic_web_site proof and the requirement that it reject non-HTTPS URLs; no file or test is named. Start by locating the proof-validation entry point, then verify the behavior against existing proof checks and ensure non-HTTPS URLs are rejected.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100