keybase / keybase/keybase-issues
Keybase desktop has no app protection (PIN) or 2FA
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
The native desktop application does not require *any* login verification. Upon opening, a malicious user could revoke all verification, change the passphrase for the account, and revoke all gpg keys. This effectively erases a user.
The concept of installing on many devices to ensure the stability of your identity chain basically becomes a huge attack surface without some form of login verification. At minimum, a pin should be unique on each device.
Contributor guide
No contributing guide indexed for this repository
Research direction
No files, tests, or entry points are named. Start by locating the native desktop login and account-action flows, then determine how device-specific PIN protection or 2FA would cover destructive operations such as revoking verification and GPG keys. Done should include an agreed security design and coverage for the protected actions.
Written by the indexing model from the issue text.
Assessment
- Domain
- desktop, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100