keybase / keybase/keybase-issues
[Hypothetical] Keybase.io has received an NSL
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
**Note:** this is a fabricated, fake AP article. When reading it, you might want to pretend it's real. The nature of an NSL is that we can never know whether or when Keybase has received one.
> By THE ASSOCIATED PRESS
> Feb 13, 2016, 6:07 P.M. E.D.T.
>
> NYC - Anonymous sources close to Keybase, the U.S. based company that democratized private communication for the masses, allege that the company received a National Security Letter (NSL) sometime last week. When asked to comment we received no response from Keybase. Not that they could respond without breaking the law; the NSL includes a lifetime gag order preventing them from disclosing details about the letter or any cooperation with the NSA to expose customers' private communication.
>
> "Assuming it's true, Chris and Max have one tough decision ahead of them," says Ladar Levison. "They can comply with the letter, betray their users, and become complicit with the unconstitutional surveillance of our citizens. Or they stand up for their customers and shutter the Keybase service." Mr. Levison is no stranger to this dilemma; in May 2014 he [abruptly shut down his secure email service](http://lavabit.com) after, it is speculated, he received his own NSL.
>
> Mathew Greene, cryptographic researcher at Johns Hopkins, warns that the damage for some users could go beyond the confines of Keybase. "The lynchpin of private communication is your so-called secret key. Given the nature of Keybase customers, and the benefits of doing so, I speculate most customers host their keys on Keybase servers."
>
> The impact is broader than it initially seems. "Some customers will have used the same key with similar services," continues Prof. Greene, "such as Google's end-to-end Gmail privacy extension or Facebook Messenger." By coercing Keybase to divulge customers' keys, the NSA can listen in on messages originating from Keybase or any of the services sharing the same key.
>
> "If this news is true, the sensible thing is to switch out your keys and discontinue using Keybase. Unfortunately your past messages may still be exposed." Experts speculate that the NSA retains copies of encrypted messages, awaiting a time when breaking into the messages is technologically feasible or they get ahold of the keys to unlock them.
>
> The NSA must clear one last hurdle: guessing the password on your key. But recent studies show anywhere from 40% to 83% of passwords can be guessed in under a day with commodity hardware and widely available software. "The NSA's capabilities will be no worse than that, almost certainly better," says Greene.
>
> Does it matter if the allegations are true? According to cryptographer Bruce Schneier, "it's logical to assume Keybase was commandeered months ago, if not as early as 2014. If they haven't been commandeered yet, they will be." Schneier points out the most expedient protection is to never upload your secret key to Keybase. But he adds, "regardless of your precautions, the safest course is to believe everyone else entrusts Keybase with their secret key and by extension has entrusted it with the NSA."
>
> Which defeats the purpose, or so it would seem.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with the issue body and its 19-comment thread; it contains no file, test, or implementation entry point. Because the report is explicitly fabricated and does not specify a change or completion condition, there is no actionable newcomer path or verifiable definition of done.
Written by the indexing model from the issue text.
Assessment
- Domain
- cryptography, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 10/100