keybase / keybase/keybase-issues
Clarify whether non human public entities can have a Keybase account
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
The Keybase interface is remarkably useful from a company perspective to allow companies to verify their contributions or for ease of receiving confidential information.
For example depending on the situation it may be permissible to have a partner generate some shared key and then send it to your company via a PGP encrypted message using the Keybase UI to generate this message even if they have never themselves signed up. This may sufficiently harden some other less secure communication channel such as email. Or permit a reasonable level of non-repudiation if the sender also has a PGP Key / is registered on Keybase.
Furthermore organisations can have things like Twitter accounts, Websites etc so a good chunk of the current options should work for proofs. Sadly not the gist option unless it could be exposed as a full public repo instead of specifically as a gist.
As long as the login details are held by a trusted group of individuals such as the systems administrators I see this working quite well to transfer reasonably sensitive information due to the client side nature for sending and ease of use for non-technical users. However Keybase is described as a public directory of people so it is unclear whether other public entities with a designated controlling group such as companies can have their own Keybase presence. I see no technical reason why this would not work albeit with the caveats that the necessity of sharing the login details reduces the security level possible but it is unclear from the terms whether this is permitted.
Contributor guide
No contributing guide indexed for this repository
Research direction
Review the Keybase account terms and the rules for proofs and public identities. Determine whether a company or other non-human public entity may maintain an account under shared control, and document the permitted status and relevant caveats. No file or test is mentioned in the issue.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100