keybase / keybase/keybase-issues
Invite requests should be signed
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
Currently the invite system doesn't requires any kind of authentication other than being logged in unlike other operations like tracking. On one side this may be confusing to users and on the other it will give an incentive for attackers to attack accounts.
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue names no files, tests, or entry points. Start by locating the invite system and comparing its request authentication with tracking operations; clarify the signing design and attack scenarios before implementation. Done means invite requests are signed and no longer rely only on being logged in.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100