SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Keybase: "Our Browser Extension Subverts our Encryption, but why Should We Care?"
Date    Saturday September 08 2018, @03:06PM
Author    martyb
Topic   
from the couldn't-care-less-or-could-they? dept.
https://soylentnews.org/article.pl?sid=18/09/08/0013211

canopic jug writes:

Software developer Wladimir Palant has written a blog post explaining a fatal shortcoming in Keybase's browser extension. Keybase claims to offer end-to-end encryption for chat and file sharing despite being inside a browser. The browser extension is apparently flawed in that when it inserts itself into third-party web sites, it fails to remain isolated from the third party sites and thus potentially exposes all secret information or even allows the forging of messages and files under the compromised identity. The response from Keybase to Wladimir has been underwhelming.

Two days ago I decided to take a look at Keybase. Keybase does crypto, is open source and offers security bug bounties for relevant findings — just the perfect investigation subject for me. It didn't take long for me to realize that their browser extension is deeply flawed, so I reported the issue to them via their bug bounty program. The response was rather... remarkable. It can be summed up as: "Yes, we know. But why should we care?"

His recommendation is to uninstall the Keybase browser extension as soon as possible. The status of the phone application is unclear, as he has not looked into it.


Original Submission

Links

  1. "canopic jug" - https://soylentnews.org/~canopic+jug/
  2. "a fatal shortcoming in Keybase's browser extension" - https://palant.de/2018/09/06/keybase-our-browser-extension-subverts-our-encryption-but-why-should-we-care
  3. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=28882

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, Keybase: "Our Browser Extension Subverts our Encryption, but why Should We Care?" on 2024-05-14 20:07:50