keybase / keybase/keybase-issues

Documentation request: a precise outline of what we trust keybase with

Open
#78 2 comments 1 reaction 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

I think it'd be valuable to explain precisely what users are trusting keybase to do and not to do, and what a malicious/compromised keybase could leak.

Things like:
- "We could be associating IP addresses with valid signatures from your keys; you'll have to take our word that we don't." [or perhaps you do? in which case it's good to know]
- "We could be serving up malicious code that harvests your client-side passcode and decrypts our server-side private key. Our server could be compromised and do that without us even wanting to. Here are the security measures we have in place to avoid that"

I think being forthcoming about things like that will help gain traction in a security-minded community, and might also help highlight holes that you haven't thought of.

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or entry points are identified in the issue. Start by reviewing the requested trust boundaries and the examples involving IP addresses, signatures, client-side passcodes, server-side keys, and malicious code. Done would be precise documentation of what Keybase can and cannot expose, including relevant security measures.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.