keybase / keybase/keybase-issues
Documentation request: a precise outline of what we trust keybase with
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
I think it'd be valuable to explain precisely what users are trusting keybase to do and not to do, and what a malicious/compromised keybase could leak.
Things like:
- "We could be associating IP addresses with valid signatures from your keys; you'll have to take our word that we don't." [or perhaps you do? in which case it's good to know]
- "We could be serving up malicious code that harvests your client-side passcode and decrypts our server-side private key. Our server could be compromised and do that without us even wanting to. Here are the security measures we have in place to avoid that"
I think being forthcoming about things like that will help gain traction in a security-minded community, and might also help highlight holes that you haven't thought of.
Contributor guide
No contributing guide indexed for this repository
Research direction
No files, tests, or entry points are identified in the issue. Start by reviewing the requested trust boundaries and the examples involving IP addresses, signatures, client-side passcodes, server-side keys, and malicious code. Done would be precise documentation of what Keybase can and cannot expose, including relevant security measures.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100