keybase / keybase/keybase-issues

Too short time to do a manual proof.

Open
#1,753 5 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

I feel that the time to do a PGP key proof is too short. I Think the time should be extendable, preferable with a CSRF protected button, to prevent attacks. I understand that there is a need for a timelimit when proofing for the security, but the current timelimit is too short and halfway through the process I get that the time expired.

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue does not name a file, test, or entry point. Start by reproducing the manual PGP proof flow and locating where its timeout and renewal controls are handled. Done means allowing a secure, CSRF-protected extension while retaining an appropriate proofing time limit.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.