keybase / keybase/keybase-issues

Clarify whether non human public entities can have a Keybase account

Open
#1,757 4 comments 4 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

The Keybase interface is remarkably useful from a company perspective to allow companies to verify their contributions or for ease of receiving confidential information.

For example depending on the situation it may be permissible to have a partner generate some shared key and then send it to your company via a PGP encrypted message using the Keybase UI to generate this message even if they have never themselves signed up. This may sufficiently harden some other less secure communication channel such as email. Or permit a reasonable level of non-repudiation if the sender also has a PGP Key / is registered on Keybase.

Furthermore organisations can have things like Twitter accounts, Websites etc so a good chunk of the current options should work for proofs. Sadly not the gist option unless it could be exposed as a full public repo instead of specifically as a gist.

As long as the login details are held by a trusted group of individuals such as the systems administrators I see this working quite well to transfer reasonably sensitive information due to the client side nature for sending and ease of use for non-technical users. However Keybase is described as a public directory of people so it is unclear whether other public entities with a designated controlling group such as companies can have their own Keybase presence. I see no technical reason why this would not work albeit with the caveats that the necessity of sharing the login details reduces the security level possible but it is unclear from the terms whether this is permitted.

Contributor guide

No contributing guide indexed for this repository

Research direction

Review the Keybase account terms and the rules for proofs and public identities. Determine whether a company or other non-human public entity may maintain an account under shared control, and document the permitted status and relevant caveats. No file or test is mentioned in the issue.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.