keybase / keybase/keybase-issues

You can put website accounts you never owned in sigchain

Open
#2,699 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

When I created keybase.io account I played with it a bit, trying how things works, how it checks your claims...
When I tried to claim hackernews account from complete stranger with curl/GPG/bash method, account was added to my sigchain even though I never confirmed I own it with post in hackernews profile.
Here is the sighain: https://keybase.io/lurker69/sigchain
First I claimed (via curl/GPG/bash) 2. zsiciars but never confirmed it. Later I claimed 3. Residue and confirmed it. Later I did the same for 5. lurker69.
If you look at sigchain, both 2. and 3. claim signatures look the same, visitor might assume that at one point I controlled both of those accounts, but I didnt. (this could be exploited to convince inexperienced visitor that you controlled account you never did)
I didnt check my sigchain before I confirmed 5. lurker69 hackernews account, so I dont know if 2. zsiciars was in sigchain before I confirmed it or it appeared only after confirming 3. Residue. I can do more tests if you wish.
If you check signature point 5. It states that it revoked signature point 3. And you dont see same revoking message at signature point 3 regarding revocation of point 2. Is this the indication that signature point 2. was never confirmed?

I would suggest that you dont include unconfirmed webpage accounts signature points in sigchain at all. Or if that is not possible that you put notation next to them noting if they were confirmed or not.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the linked sigchain for the unconfirmed zsiciars and confirmed Residue and lurker69 claims, then reproduce the claim and confirmation sequence described in the issue. Done means the sigchain no longer presents an unconfirmed website account as confirmed, or clearly labels its confirmation status.

Written by the indexing model from the issue text.

Assessment

Tech stack
bash
Domain
authentication, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.