keybase / keybase/keybase-issues

Feature request: Proof of non-disclosure

Open
#1,619 9 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

Keybase should provide a mechanism, such that:
1) A user can attest non-disclosure of their private PGP key to keybase
2) Keybase affirms the claim by validating the lack of private key data in their database
3) Keybase automatically negates the affirmation and attestation upon receipt of private-key data.

Reason: In ring0 security circles, simply utilizing keybase is equivalent to disclosure of the private key, due to there being no mechanism to ensure that the key was not leaked by a third-party.

Contributor guide

No contributing guide indexed for this repository

Research direction

Issue #1619 names no files, tests, or entry points. Start by defining how the attestation is represented, how Keybase validates the absence of private-key data, and how receiving such data automatically invalidates it. Done requires an agreed design and tests covering attestation, affirmation, and negation.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.