keybase / keybase/keybase-issues
One-Way Verifications
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
Hi,
I'd like to ask you to consider adding one-way verifications. What I mean is this: The current setup establishes two-way cryptographic ties between a keybase.io account and several other accounts / websites / whatever. With this, everyone can make reasonably sure that a certain PGP key belongs to a certain person.
Now it would be awesome if we could use this PGP key to verify more identities, where public proof is not so easy, say for example jabber IDs, or key fingerprints used for OTR / TextSecure / whatever. I cannot publicly prove that I have access to a certain jabber ID, but I can sign the statement "if someone from foo@bar.com contacts you via jabber, you may assume that it's me" with my PGP key. Thus, people who track my keybase account can then also start to trust this jabber ID.
I am fully aware of the fact that "the other way round" may not be assumed, i.e. I may in this case not assume that a certain jabber user, TextSecure user, or whatever is really that guy on keybase. That's why these proofs may not be used to proof the identity of someone on keybase. One might even consider not showing them on the keybase profile page at all, to mitigate this issue.
My hope was, that in the future, there would be a public API so that (for example) TextSecure could ask keybase something like this:
- "Hey, I got some TextSecure user who tells me that his key fingerprint is 0xDEADBEEF", keybase responds "Jon Doe signed a statement that this is his key, here's the statement: ..."
- TextSecure now checks if the user tracked (i.e. signed) Jon Doe's PGP key that signed this statement. If so, it somehow displays "I verified that this key belongs to your tracked keybase.io user Jon Doe"
- Profit.
I know there are a lot of concerns about centralization of proofs, NSLs, etc. I'd kindly ask to keep this issue on-topic and take further discussions to #979 . That ticket originally was about the same issue as this, but has decidedly gone off-topic.
Contributor guide
No contributing guide indexed for this repository
Research direction
Read this proposal alongside issue #979, which the author identifies as the place for broader discussion. Clarify the one-way proof model and the proposed public API flow for Jabber, TextSecure, and OTR identities; done would mean an agreed design and implementation scope, not just a new profile display.
Written by the indexing model from the issue text.
Assessment
- Domain
- cryptography, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100