keybase / keybase/keybase-issues
Account Recovery Flow Issues
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
I've been doing some exploratory testing around the account recovery and password / passphrase reset use case. I think there are a few things that could be improved:
- The passphrase reset email and the new passphrase page should make it very clear that the hosted private key will be deleted from the server (perhaps too much info was removed in https://github.com/keybase/keybase-issues/issues/94)
- Users should be prompted to export their key when it's generated
- Add an easy way to regenerate a key (not just to upload one)
- More messaging around having to redo proofs would be useful
- Existing sessions are not logged out
- If the user is logged in then changing the password should force all sessions to re-authenticate
Keep up the good work. Looks like a very promising service. :+1:
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the account recovery and password/passphrase reset flows, along with the linked issue #94. The work is complete when the requested key-loss warnings, key export and regeneration options, proof guidance, and session re-authentication behavior are defined and implemented.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100