keybase / keybase/keybase-issues

Keybase desktop has no app protection (PIN) or 2FA

Open
#3,135 13 comments 6 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

The native desktop application does not require *any* login verification. Upon opening, a malicious user could revoke all verification, change the passphrase for the account, and revoke all gpg keys. This effectively erases a user.

The concept of installing on many devices to ensure the stability of your identity chain basically becomes a huge attack surface without some form of login verification. At minimum, a pin should be unique on each device.

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or entry points are named. Start by locating the native desktop login and account-action flows, then determine how device-specific PIN protection or 2FA would cover destructive operations such as revoking verification and GPG keys. Done should include an agreed security design and coverage for the protected actions.

Written by the indexing model from the issue text.

Assessment

Domain
desktop, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.