keybase / keybase/keybase-issues
How does Keybase verify the ownership of the PGP keys?
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
I am new to keybase and I found the client codebase pretty huge to get the answer of my question, but how does keybase verify that the client-generated PGP keys are actually owned by the client? does the server sends some challenge encrypted by the claimed public key and waits for the unencrypted version or what exactly?
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with the Keybase client codebase, tracing PGP key generation and the ownership-verification flow described in the question. Document whether verification uses a server challenge or another mechanism, and cite the relevant entry points so the explanation can be checked against the implementation.
Written by the indexing model from the issue text.
Assessment
- Domain
- cryptography, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100