keybase / keybase/keybase-issues

Linux install instructions provide code signing key, but no acutal signature for the .deb package

Open
#2,529 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

https://keybase.io/docs/the_app/install_linux

The documentation mentions "If you want our code signing key, you can get it here and verify it here." But the rest of the instructions only give a way to get the .deb and install it without prior verification. I would expect to be able to verify the package before running any `sudo` commands. Going to the download page https://s3.amazonaws.com/prerelease.keybase.io/linux_binaries/deb/index.html doesn't provide any signatures either.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the Linux installation instructions at keybase.io/docs/the_app/install_linux and the package listing at s3.amazonaws.com/prerelease.keybase.io/linux_binaries/deb/index.html. Determine how a downloaded .deb can be verified with the published code-signing key before any sudo command; done means the signature is available and the instructions describe that pre-install verification.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux
Domain
operating-systems, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.