keybase / keybase/keybase-issues

Account Recovery Flow Issues

Open
#1,457 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

I've been doing some exploratory testing around the account recovery and password / passphrase reset use case. I think there are a few things that could be improved:
- The passphrase reset email and the new passphrase page should make it very clear that the hosted private key will be deleted from the server (perhaps too much info was removed in https://github.com/keybase/keybase-issues/issues/94)
- Users should be prompted to export their key when it's generated
- Add an easy way to regenerate a key (not just to upload one)
- More messaging around having to redo proofs would be useful
- Existing sessions are not logged out
- If the user is logged in then changing the password should force all sessions to re-authenticate

Keep up the good work. Looks like a very promising service. :+1:

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the account recovery and password/passphrase reset flows, along with the linked issue #94. The work is complete when the requested key-loss warnings, key export and regeneration options, proof guidance, and session re-authentication behavior are defined and implemented.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.