keybase / keybase/keybase-issues

[Suggestion] Allow `verify` to verify emails with RFC3156 bodies (MIME with PGP signatures)

Open
#1,504 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

https://tools.ietf.org/html/rfc3156

If a user doesn't have an email client with some sort of signature verifier, if they could paste the raw email message into the verify window and have it verify the signature, that would be nice. It's really hard to do it manually without a client extension. Especially if you're not aware of what the signature is actually signing, the MIME part that is it's immediate sibling, which is often not apparent when the MIME part is often a multipart of text & html parts.

A user probably wouldn't realize this hierarchy without reading the RFC.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the verify window and RFC3156, focusing on how a raw email's MIME hierarchy and immediate sibling are selected for verification. Done means a pasted RFC3156 email can be checked and the interface clearly reports whether its PGP signature is valid.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.