keybase / keybase/keybase-issues

Team Management

Open
#2,508 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

Hey Keybase Team,

I'm a big fan of what Keybase is doing, and I sort of see it at PGP's and real electronic identity's last hope. I know you've got your hands full with kbfs, the site, and the dozens of apps that every software startup has to produce these days, so I'll try to keep my non-technical pontificating as short as possible.

I started a new identity at Keybase today, but I got an invite pretty early on. I was reminded to check out Keybase again because I was tweaking the following internal document of ungodly length, yet again, to clarify the steps:

Gist: Getting a Key, and Obtaining Unlocked Access to the Repo

I don't expect you to read it, because that's the problem: that excerpt is only about the middle third of the total document, which also includes steps to install GPG for various platforms, how to fix broken symlinks in homebrew-installed gpg1 vs gpg2, how to revoke access, etc.

I like Keybase, but I've always been a crypto nerd. I'd like it anyway. I like that I have these proofs on my account, but I know there's a very real chance they'll never get used. My first PGP key, which lived from 1998-2003, and was published everywhere, and was probably only used 15 times, due to having to explain steps like the above document. That doesn't matter to me, though: I like the ideas and ideals of what Keybase is trying to do, and during the beta-meantime I'll invite and explain what it does to anyone I think may be interested.

However: Securely managing a collection of employees', contractors', and generally distributed team's keys, built on top of Keybase's ease-of-use (vs. the alternative) would get used dozens of times a month. I don't know what the solution would look like, or if it'd involve terms like "orgs" or "teams", "signed, sync'd keychains", "email domain verification", but anything that'd even cut the above document by a third would be worth a recurring monthly payment. It'd be a rage-induced impulse buy the next time I had to walk someone through the above document.

I think Keybase has thought the hardest about both the usability and security sides of situations like these. I don't know what the roadmap looks like, but I also believe Keybase has the best opportunity to provide a solution to organizations that already have these issues, and perhaps create a larger market of organizations who would have these more secure infrastructures in place if the process weren't so onerous.

Just a thought. Thanks again, and good luck.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the linked “Getting a Key, and Obtaining Unlocked Access to the Repo” gist and the issue’s discussion of employee and contractor key management. The issue does not identify repository files, tests, or an implementation entry point; the work is done only after the desired team key-management scope and solution are defined.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.