keybase / keybase/keybase-issues
Explaining basics sooner/Properly overwriting proofs
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
This is not anymore an issue to me, but unless something changes, it might as well be issue for other new users.
When I first proved my twitter and github, the console client told me everything's OK, and because I tend to keep my stuff tidy, I deleted both proofs, as they were already checked, so not needed anymore. Only a few minutes later, emails hit my inbox explaining not to delete the proofs. Well...too late. So I went to the website, checked on the proofs, and tried to click replace. I got instructed to simply run keybase prove again and it should be OK. So I did.
Everything seemed OK, up to the morning. When I woke up, I got emails, that both proofs were broken. They probably still pointed to the original deleted ones. So I had to explicitly revoke both signatures first and reprove them again.
I believe the solution might be to tell users not to delete the proofs when they establish them in the console, not only later in an email. Also, check, that the proofs overwrite properly as I have an impression, this is not the case.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with the console client and website flows around `keybase prove`, proof deletion, replacement, and revocation. Reproduce the sequence described and verify that users are warned before deleting proofs and that reproving replaces the old proof without requiring explicit revocation first.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100