keybase / keybase/keybase-issues

User profiles do not distinguish between valid and revoked OpenPGP keys

Open
#2,893 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

Sample:

![capture](https://cloud.githubusercontent.com/assets/526124/23654352/896f19cc-0330-11e7-9605-10793fa7af8e.png)

The second key has been superseded by the first one. I believe it is desirable to show a notice of revocation status for any keys affected.

In this particular case, the revocation certificate includes a comment pointing to the new key as the superseding one. This is a scenario where keeping the revoked key on Keybase, together with a way of viewing the reason and comment for revocation, might be useful for other users.

See also keybase/client#6151.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing how user profiles display OpenPGP keys and the related discussion in keybase/client#6151. Done means revoked and valid keys are distinguishable, with the revocation reason and comment—including a superseding key when present—available to users.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.