keybase / keybase/keybase-issues
Sign in – devices available after typing username
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
I'm not sure if this is the best place to write this but I was a bit surprised when I signed in on a new device that I could see the devices that were already signed in. If an attacker were to try to sign in to someone elses keybase account it would be much easier when knowing which devices to look for.
Might it make sense to simply ask the person signing in to find one of the other devices and then hide the signed in devices – or is the information about which devices are signed in something that's already available through other channels?
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue concerns the sign-in flow and the visibility of already signed-in devices, but it names no files, tests, or entry points. Start by locating the device-selection step in the sign-in implementation and reviewing the existing security behavior; done requires an agreed design and verification that device details are no longer exposed unnecessarily.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100