keybase / keybase/keybase-issues
Integrate Web of Trust Validation
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
One of the ways to validate keys is to find that they've been signed by you or by people whose keys you already have. Keybase could also check the local GPG keys of the user as another source of authentication. (This might be better if there was a means to sign other user's keys and notify them that you've signed it to allow them to re-upload the newly signed key?)
e.g.
✔ public key fingerprint: C499 65E1 3128 AAD9 9589 F5EC 3DCE F7AC B68F D3B5
✔ "geofflane" on twitter: https://twitter.com/geofflane/status/444532350815203328
✔ "geofflane" on github: https://gist.github.com/9553100
✔ "geofflane" is trusted by "someone else, and another someone"
Contributor guide
No contributing guide indexed for this repository
Research direction
No files, tests, or entry points are identified. Start by clarifying the proposed Web of Trust flow, including local GPG keys, key signing, notifications, and trusted-identity display; done requires an agreed scope and acceptance criteria for these behaviors.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, cryptography, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100