keybase / keybase/keybase-issues
Idea for additional account reset without a total wipe?
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
If someone has no device added or what ever, how about emailing the user with a random blob, have them sign that blob with the private key that matches the public key they have on file for their account. Then email it back to you. Once the site gets the response, it verifies to ensure the signature matches the key on record and the data is the correct random data that was provided, then offer the capability to reset the password or what ever you do? Just a thought I had. Should be secure, especially if the devices thing and the command line gives access back without a wipe, should be essentially no different, just not requiring a device to be added.
Contributor guide
No contributing guide indexed for this repository
Research direction
No files, tests, or entry points are identified. First clarify the account-recovery requirements, threat model, and relationship to existing device or command-line recovery before locating the relevant implementation and defining completion criteria.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100