keybase / keybase/keybase-issues

Explaining basics sooner/Properly overwriting proofs

Open
#918 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

This is not anymore an issue to me, but unless something changes, it might as well be issue for other new users.

When I first proved my twitter and github, the console client told me everything's OK, and because I tend to keep my stuff tidy, I deleted both proofs, as they were already checked, so not needed anymore. Only a few minutes later, emails hit my inbox explaining not to delete the proofs. Well...too late. So I went to the website, checked on the proofs, and tried to click replace. I got instructed to simply run keybase prove again and it should be OK. So I did.

Everything seemed OK, up to the morning. When I woke up, I got emails, that both proofs were broken. They probably still pointed to the original deleted ones. So I had to explicitly revoke both signatures first and reprove them again.

I believe the solution might be to tell users not to delete the proofs when they establish them in the console, not only later in an email. Also, check, that the proofs overwrite properly as I have an impression, this is not the case.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the console client and website flows around `keybase prove`, proof deletion, replacement, and revocation. Reproduce the sequence described and verify that users are warned before deleting proofs and that reproving replaces the old proof without requiring explicit revocation first.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.