keybase / keybase/keybase-issues

Partial tracking of only specific proofs or the fingerprint?

Open
#1,465 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

Currently it seems that when tracking, in the human verification step, you should be sure about at least one of the proofs presented, or the fingerprint, before you decide to sign your tracking. It is surely better when you can say, that multiple or all of the proofs are linking to accounts that you know are under control of the person to be tracked.

Wouldn't it be a good thing if you could state, for which of the proofs you are sure about the linked account, and for which you don't know if its actually the person's? Because I think that is a very real thing happening while tracking. Kind of the same thing when you certify only specific UIDs on an OpenPGP certificate, because you didn't check the others.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the human verification and tracking flow described in the issue. Define how confidence can be recorded separately for each proof and for the fingerprint; done should make it possible to track only the proofs whose linked accounts are known to be controlled by the person.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.