keybase / keybase/keybase-issues

Dealing with Market Research and User Cultivation

Open
#1,549 5 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

Originally from [@frank-borkin](https://github.com/frank-borkin) posted [here](https://github.com/keybase/keybase-issues/issues/518#issuecomment-95498884).

Original statement:

> as this list gets implemented, how does privacy work? Theoretically, I can see a proof on someone's Twitter, look them up here (batched via API) and get their Facebook, multiple email addresses (if they uploaded their own key), OS (from GPG version), etc. It's great for stalking. Also, Facebook can recognise these posts, do an automated lookup and link my G+ account and everything else (which I deliberately didn't tell it about). You've essentially become a marketers wet dream - linking multiple social profiles together in a 100% accurate way - how are you going to stop abuse of the service when there are so many companies whose entire business model is to put together by inference what you've done explicitly, and can now be seen just by googling "keybase proof"?

I wanted this in its own thread because #518 is getting long and discussion about issues like this isn't going to help anyone looking for something specific--but I think it's an entirely valid and vital question. @maxtaco @malgorithms

I'm pretty sure the same rules of DDoS come into play here. It's **very** hard to distinguish valid visitors from malicious visitors (unless they're crawling and adhere to robots.txt -- but lets be honest, which company that collects consumer data is gonna do that?) and even harder to mitigate them getting the wrong information without singling out valid users.

Quite honestly, I really think this bridge will have to be crossed eventually and it'd be healthy for the community to at least begin low level discussion now.

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or entry points. Start by reviewing the privacy and abuse risks described for Keybase proofs, social-profile linking, and public lookups; a concrete mitigation scope and acceptance criteria are still needed.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.