keybase / keybase/keybase-issues

Don't send links in emails that teach users bad habits in the face of phishing attacks

Open
#3,504 0 comments 2 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

Today I got a message about the https://keybase.io/a/i/r/d/r/o/p/spacedrop2019 airdrop:
**Subject: You've been airdropped $21.50 USD worth of Stellar Lumens in Keybase**.
It is full of legitimate links to both keybase.io and stellar.org, and is clearly legitimate in other ways, convincing me that you did send it out on purpose. That's bad because it teaches users habits which make phishing and malware attacks, specifically around crypto-currencies, that much easier.

The email even violates the promise at [Stellar | Security Guide - How To Protect Yourself From Scammers](https://www.stellar.org/blog/stellar-security-guide-protect-scammers/) that emails about Stellars will come from **stellar.org**, and ignores the fact that that given Unicode attacks and others, humans are just not qualified to validate URLs in emails, even when they're been warned.

At a minimum, all emails from Keybase, even the notifications users have requested, should omit private information and include text warning users from clicking on links in emails in general, and advising them to simply go to their Keybase client to get the relevant information securely and directly. And implementing end-to-end signatures as described #374 would help also.

Contributor guide

No contributing guide indexed for this repository

Research direction

No source files or tests are named. Start by reviewing the email-notification behavior described here and the end-to-end signature proposal in issue #374; done requires an agreed, testable scope for removing private information, adding anti-phishing guidance, and directing users to the Keybase client.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.