keybase / keybase/keybase-issues

Doomsday scenarios and their effect on keybase?

Open
#2,345 1 comment 1 reaction 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

Again, apologies if this is a duplicate issue but a quick search picked up nothing obviously relevant.

I'm wondering whether you could clarify, perhaps in https://keybase.io/docs/server_security and the related documents (e.g. a list such as https://en.bitcoin.it/wiki/Weaknesses) about what exactly would happen to keybase under a certain number of possible future scenarios ranging from benign to “doomsday” in nature.

For example, here are some questions I'm concerned with and how them occurring would affect keybase as a software, a service and a concept (respectively):
- The bitcoin block chain breaks down (bitcoin loses its value, blockchain easy to fork). I imagine in this scenario, keybase could simply “migrate” to publishing its authenticity proofs in a different relevant blockchain instead, if possible.
- The keybase server becomes defunct. Is it possible for the community to host a replacement? Is it possible for the keybase software to work with alternative hosts? Is the server software open source? Is it possible to move towards a decentralized server system? (Perhaps relying on a blockchain for synchronization)
- The crypto behind keybase breaks down, e.g. RSA broken. We'd potentially need to mass-migrate GPG keys. How well would that work? What kind of effects could an attacker capable of breaking RSA wreak on keybase? What about an attacker with only read-only access? (Keeping in mind RSA almost surely will be broken within our lifetimes due to the advent of quantum computers alone)
- keybase.io website goes missing. Is it possible to host my own version of the keybase.io front-end website? Is all the code publicly available?

And probably more that I'm not thinking of right now. I can see from https://keybase.io/docs/server_security that keybase is applying a strong design of distrusting the central server, and I think this is a very healthy design choice. But I'm still wondering about what the real-world ramifications of a dead server would be, since as I understand it keybase still relies on a central API and reference point.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with https://keybase.io/docs/server_security and the related documents, including the linked Bitcoin weaknesses list. Review the proposed blockchain failure, server outage, cryptographic break, and website loss scenarios, then determine whether the documentation can explain their effects on Keybase as software, service, and concept, including hosting and migration possibilities.

Written by the indexing model from the issue text.

Assessment

Tech stack
blockchain
Domain
cryptography, documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.