keybase / keybase/keybase-issues

Integrate Web of Trust Validation

Open
#257 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

One of the ways to validate keys is to find that they've been signed by you or by people whose keys you already have. Keybase could also check the local GPG keys of the user as another source of authentication. (This might be better if there was a means to sign other user's keys and notify them that you've signed it to allow them to re-upload the newly signed key?)

e.g.
✔ public key fingerprint: C499 65E1 3128 AAD9 9589 F5EC 3DCE F7AC B68F D3B5
✔ "geofflane" on twitter: https://twitter.com/geofflane/status/444532350815203328
✔ "geofflane" on github: https://gist.github.com/9553100
✔ "geofflane" is trusted by "someone else, and another someone"

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or entry points are identified. Start by clarifying the proposed Web of Trust flow, including local GPG keys, key signing, notifications, and trusted-identity display; done requires an agreed scope and acceptance criteria for these behaviors.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, cryptography, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.