keybase / keybase/keybase-issues

Feature request: Allow a device key to maintain a separate passphrase

Open
#2,395 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

At the moment, all device keys have the same passphrase, and changes to the passphrase are propagated through the entire graph. Since some of my devices are physically much more secure than others, I would like the option of flagging those devices as having a separate passphrase, which is not subject to propagation.

So, my secure devices could have simple passphrases that I can remember and type, while less secure devices can have the whole 64 character base 64 random number that I use elsewhere. This would save me the additional steps of logging in to my password manager, copying the password to the clipboard, pasting it into the pinentry, etc. - all of which I must do at the moment.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or entry points are identified in the issue. Begin by locating the client’s device-key passphrase propagation logic; done means secure devices can use an independently set passphrase that is excluded from propagation while other devices retain current behavior.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.