keybase / keybase/keybase-issues
Keybase Teams - Direct Message and personal folders within teams rather than outside for security
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
We use keybase at work to share secrets. It's a great product and it's super easy to share secrets; we love it... Unfortunately it's not as easy to un-share these secrets and that could be a security issue... What happens when someone leaves the company but they still have this SSL cert or whatever we shared with them... I have to go through and delete all of the history / private folder stuff I've shared w/ them (and all of my co-workers need to do the same -- never going to happen)...
To support this; maybe you could chat to something like and then when joelwampler leaves the company and we remove him from appdirect_inc.ops, he no longer has access to either of these folders
- appdirect_inc.ops/private/nshenry03,joelwampler
- appdirect_inc.ops/private/nshenry03,joelwampler,vovans82,avallens
Same idea w/ teams and personal folders
- /keybase/team/appdirect_inc.ops/private/nshenry03,joelwampler
- /keybase/team/appdirect_inc.ops/private/nshenry03,joelwampler,vovans82,avallens
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue names no files, tests, or entry points. Start by tracing how team membership controls access to team and private folders, then define the behavior for removing a member; done should ensure removed members cannot access previously shared team-scoped folders.
Written by the indexing model from the issue text.
Assessment
- Domain
- authorization, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100