keybase / keybase/keybase-issues

Load signing key and verify signature of installer before running dpkg

Open
#2,065 7 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

Related to #2064, the install page should walk the user through installing the keybase pubkey and validating a signature on the install package prior to running installation to ensure the download hasn't been tampered with.

See: https://www.torproject.org/docs/debian.html.en

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the install page, related issue #2064, and the Debian installation guidance linked in the issue. Determine how the Keybase public key and package signature should be presented before dpkg runs. Done means the page clearly walks users through key installation and signature validation before installation.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux
Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.