keybase / keybase/keybase-issues

How does Keybase verify the ownership of the PGP keys?

Open
#3,735 5 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

I am new to keybase and I found the client codebase pretty huge to get the answer of my question, but how does keybase verify that the client-generated PGP keys are actually owned by the client? does the server sends some challenge encrypted by the claimed public key and waits for the unencrypted version or what exactly?

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the Keybase client codebase, tracing PGP key generation and the ownership-verification flow described in the question. Document whether verification uses a server challenge or another mechanism, and cite the relevant entry points so the explanation can be checked against the implementation.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.