keybase / keybase/keybase-issues
"safer" way to unlock PGP key inline?
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
I'm just generally wary of any third-party software which does ncurses console stuff and then throws up an "enter gpg passphrase" prompt. It would be trivial for something other than the gnupg binary to be grabbing my passphrase that way.
I'm moving my keys to a physical device soon, but I'd also feel a lot more comfortable if I could see the cleartext request, manually sign it by invoking my own gpg binary from the shell, and then continue.
Maybe this is too much paranoia for how you intend keybase to be used, but I view it more as a directory service than a direct encryption tool.
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue proposes a safer inline passphrase flow for PGP operations, including showing the cleartext request and letting the user invoke their own gpg binary from a shell. It names no files, tests, or entry points, so the first step would be to locate the relevant keybase client flow and determine the intended signing interaction. Done would require an agreed design and an implemented, verified workflow.
Written by the indexing model from the issue text.
Assessment
- Domain
- cryptography
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100