keybase / keybase/keybase-issues

Issues with key functionalities after switching identities (specific use case but very problematic)

Open
#2,860 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

TL;DR: when switching between 2 accounts both authenticated using device keys created under paper keys, if I switch away from an account with no hosted private key, then switch back, I cannot perform cryptographic functionality like key revocations anymore. Windows Client, shell

Full Use Case:
I have 2 keybase accounts (and corresponding key families) that i use frequently. 1 of these is tied to a semi-anonymous online "persona" (yes yes i know there's no such thing as true anonymity with these things but googling it wont pop up with my house) and 1 which is tied to my personal identity that i use for "Official" communications and projects. My "Real" account uses Keybase private key hosting, my "persona" doesn't. We will refer to these as "persona" and "real" from now on. I recently had the laptop containing the original(and for persona, the only) copies of the main keypairs stolen, so I got a brand new laptop, then went and logged in to persona, then logged out and logged into real, both using paper keys i kept in my lockbox for just such an occasion, and created a new device key on both. I then went to revoke the stolen keys. on real i had no problem, I was able to revoke the old key and generate the new one. but when I switched back to persona, the function failed with an error saying i didnt have a key to perform this operation with. i tried logging out and logging in again with still no success. I ended up needing to log into ANOTHER new computer, enter paper key, create device key, then use device key to revoke my public key. this was a whole lot of extra effort.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reproducing the Windows Client shell workflow with two accounts: one using hosted private keys and one without, each authenticated with paper and device keys. Switch from the account without hosted keys to the other and back, then attempt a key revocation. Done means cryptographic operations such as revocation still work after switching identities, without requiring another computer.

Written by the indexing model from the issue text.

Assessment

Tech stack
shell
Domain
authentication, operating-systems, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.