keybase / keybase/keybase-issues
Keybase Deleted my PGP Key
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
[I have always used an offline PGP key][sigchain] with Keybase, and regularly renew the key every 3-6 months. I use the supplied `curl` and `gpg` script to update my key in Keybase and have been doing this since 11/13/2016, with my most recent update to my key being 11/02/2021.
My key fingerprint is `6D63 865D 1C6E EB0F 92C3 94A1 5D21 FFA2 7D8D CC66` (or `6D63865D1C6EEB0F92C394A15D21FFA27D8DCC66` without spaces), and is available [here on my security website][pgp-key-cdn] or [on keys.openpgp.org and other keyservers (download link)][pgp-key-keyserver].
Somewhere between [November 2nd]() and [November 12th, 2021](https://twitter.com/naftulikay/status/1459371932332150791), Keybase deleted my PGP key. This event does not show up in my signature chain because it wasn't a change that I made.
I don't have the ability to update my PGP key, the key is just gone, not present on [my keybase page][keybase]. The one device that I had was a mistake, I have always preferred to use GnuPG itself rather than the `keybase` CLI, and I have no access to this device. I would have deleted it from my profile back then, but Keybase won't allow me to do that, as it mandates that at least one device exists.
My PGP master key is offline and airgapped, and my sub-keys exist on a hardware security device that I use every day.
The website says I can _add_ a new PGP key, but this will, of course, invalidate all of my proofs and break my signature chain.
I have two questions:
1. Why did Keybase remove my key?
2. Is there any way for me to restore my key without breaking all of my proofs and starting a completely new history?
[keybase]: https://keybase.io/naftulikay
[pgp-key-cdn]: https://secops.naftuli.wtf/pgp/7D8DCC66.asc
[pgp-key-keyserver]: https://keys.openpgp.org/vks/v1/by-fingerprint/6D63865D1C6EEB0F92C394A15D21FFA27D8DCC66
[sigchain]: https://keybase.io/naftulikay/sigchain
[sigchain-20211102]: https://keybase.io/naftulikay/sigchain#e14747e5c44f424f7e8b69ed78b3d90dc73a58dc8b85bb970c69201c49775bab0f
Contributor guide
No contributing guide indexed for this repository
Research direction
No repository files, tests, or code entry points are identified. Review the reported Keybase profile, sigchain, and linked public key first; the issue would be resolved by explaining the deletion and whether the existing key and proof history can be restored without starting over.
Written by the indexing model from the issue text.
Assessment
- Domain
- cryptography, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100