keybase / keybase/keybase-issues

Sign in – devices available after typing username

Open
#3,541 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

I'm not sure if this is the best place to write this but I was a bit surprised when I signed in on a new device that I could see the devices that were already signed in. If an attacker were to try to sign in to someone elses keybase account it would be much easier when knowing which devices to look for.

Might it make sense to simply ask the person signing in to find one of the other devices and then hide the signed in devices – or is the information about which devices are signed in something that's already available through other channels?

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue concerns the sign-in flow and the visibility of already signed-in devices, but it names no files, tests, or entry points. Start by locating the device-selection step in the sign-in implementation and reviewing the existing security behavior; done requires an agreed design and verification that device details are no longer exposed unnecessarily.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.