keybase / keybase/keybase-issues

Update trust.db with tracking information

Open
#1,376 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

Currently the information whether a key belongs to a tracked user isn't reflected in the trust.db. In #220 the consensus was that this behavior should be the default. But I think it is important that the user can choose that the trust information is exported. Without exporting it, external gpg clients (e.g. kgpg, enigmail) will show the key as being untrusted. #220 contains a suggest of how keybase could update the trust. I think this is important for keybase to work well with enigmail. As has been said in #220 it is important to avoid the "key is not trusted". And while it is certainly most important to avoid it for the keybase cli itself, it should also be possible to avoid it in external apps. Also somewhat related to #327.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading the proposal in #220 and the trust.db handling described here; compare how tracked-user information is represented for the Keybase CLI and external GPG clients such as kgpg and enigmail. Done means defining the user-controlled export behavior and verifying that exported keys are not shown as untrusted by those clients.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.