keybase / keybase/keybase-issues

"safer" way to unlock PGP key inline?

Open
#237 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

I'm just generally wary of any third-party software which does ncurses console stuff and then throws up an "enter gpg passphrase" prompt. It would be trivial for something other than the gnupg binary to be grabbing my passphrase that way.

I'm moving my keys to a physical device soon, but I'd also feel a lot more comfortable if I could see the cleartext request, manually sign it by invoking my own gpg binary from the shell, and then continue.

Maybe this is too much paranoia for how you intend keybase to be used, but I view it more as a directory service than a direct encryption tool.

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue proposes a safer inline passphrase flow for PGP operations, including showing the cleartext request and letting the user invoke their own gpg binary from a shell. It names no files, tests, or entry points, so the first step would be to locate the relevant keybase client flow and determine the intended signing interaction. Done would require an agreed design and an implemented, verified workflow.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.