keybase / keybase/keybase-issues

Provide a way to verify Keybase app download integrity

Open
#2,375 7 comments 9 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

When you go to download the Keybase app it would be nice if there was a way to verify the integrity of the download.

The Tor Project serves as a good example of this. They provide signature for each of their downloads and clear instructions on how to verify the integrity of the download ([Downloads with signatures](https://www.torproject.org/projects/torbrowser.html.en), [Verification instructions](https://www.torproject.org/docs/verifying-signatures.html.en), [Signing keys page](https://www.torproject.org/docs/signing-keys.html.en)).

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the Tor Project reference links in the issue and inspect the existing Keybase download flow; no file or test is named. Done means downloads have an integrity-verification mechanism and clear instructions, including the relevant signing keys.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.