keybase / keybase/keybase-issues

Keybase Teams - Direct Message and personal folders within teams rather than outside for security

Open
#3,233 1 comment 8 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

We use keybase at work to share secrets. It's a great product and it's super easy to share secrets; we love it... Unfortunately it's not as easy to un-share these secrets and that could be a security issue... What happens when someone leaves the company but they still have this SSL cert or whatever we shared with them... I have to go through and delete all of the history / private folder stuff I've shared w/ them (and all of my co-workers need to do the same -- never going to happen)...

To support this; maybe you could chat to something like and then when joelwampler leaves the company and we remove him from appdirect_inc.ops, he no longer has access to either of these folders

- appdirect_inc.ops/private/nshenry03,joelwampler
- appdirect_inc.ops/private/nshenry03,joelwampler,vovans82,avallens

Same idea w/ teams and personal folders

- /keybase/team/appdirect_inc.ops/private/nshenry03,joelwampler
- /keybase/team/appdirect_inc.ops/private/nshenry03,joelwampler,vovans82,avallens

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or entry points. Start by tracing how team membership controls access to team and private folders, then define the behavior for removing a member; done should ensure removed members cannot access previously shared team-scoped folders.

Written by the indexing model from the issue text.

Assessment

Domain
authorization, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.