keybase / keybase/keybase-issues
Minor issue: Fingerprint of new user's key sent to inviter before verification
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
I have recently invited another user to Keybase, he had uploaded his existing public key while registering, but he did not verify it (by self-signing Keybase request).
As a result I received e-mail about registration of my invitee that contained firgerprint of his public key (and no notice that the key has not yet been verified).
The public key might have also been displayed on the website for some time (prior to verification), but it is possible that the key was displayed only to the user himself for the purpose of verification.
Several hours later Keybase.io website displayed that the new user has no key published. The public key was re-uploaded and successfully verified afterwards.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing the invitee registration email and public-key verification flow described in the report, then reproduce the sequence with an uploaded but unsigned key. Check both the invitation email and the website state before verification; done means unverified keys are not presented as verified and the user receives an accurate status notice.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100