Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Documentation on security implications and use of phone numbers in Keybase #18945

Closed
nealmcb opened this issue Aug 14, 2019 · 13 comments
Closed

Comments

@nealmcb
Copy link

nealmcb commented Aug 14, 2019

I was surprised to see the message "Add your phone number so your friends can find you." on my Keybase Android app today. But I see no way to search by phone number. And the only options are "Add number" (by default) and "Later".

I searched high and low for documentation on the intended use of this, what Keybase would do with it, how it could be used by me and my friends, what the privacy policy was, etc etc.
I found nothing in the blog, and only a smattering of mentions here in issues. That's very distressing for a privacy-focused app.

The most interesting hit was Stop nagging about email verification and allow disabling unwanted features · Issue #18903 · keybase/client with its link to Why Apple’s Notification Bubbles Are so Stressful - OneZero. And I agree. Having that red highlite of "1" on the bottom left of my app is very distracting even though I'm colorblind so red is not very bright.

I also found a bunch of PRs but no design document or the like.

So what's up? Why would this feature be helpful? What are the security issues? And how do I get that "1" to go away without suggesting I'm interested in seeing this request again, until I know what's in it for me?

@junderw
Copy link

junderw commented Aug 14, 2019

you can search by phone number by just typing in the number in user search

@jamesdwilson
Copy link

you can search by phone number by just typing in the number in user search

but what if i don't WANT to be discoverable by phone, email or other methods?
Like @nealmcb says, I want the simple feature to say "don't ask me again about this"

@heronhaye
Copy link
Contributor

@nealmcb We'll have a doc out soon.
You can get rid of the badge by clicking "later", the app won't ask you again unless you go to the settings page yourself to add a phone number.

@heronhaye
Copy link
Contributor

We wrote some docs at https://keybase.io/docs/chat/phones_and_emails. Let us know if there's anything else you want to know that's missing, we'll add it. Thanks!

@nealmcb
Copy link
Author

nealmcb commented Aug 16, 2019

I think the information from that handy document, and tips on privacy implications, should be part of the client documentation. There are no tips in the client on how to search for phone numbers, and it is counter-intuitive at least for me that you'd just search "people" e.g. in the Keybase filter.
The "Import phone contacts" option in Settings should link to the document or provide related info in a popup or the like.
Better clarity on this will help both attract some people to use the feature via your guarantees of not abusing the information, and also give more confidence in Keybase in general to other people who might otherwise see this as a big deviation from their expectations.
Can you re-open this until this sort of info is more discoverable in the client?

@heronhaye
Copy link
Contributor

I think the information from that handy document, and tips on privacy implications, should be part of the client documentation.

Agree, we will link to this page from within the client in the next release.

There are no tips in the client on how to search for phone numbers, and it is counter-intuitive at least for me that you'd just search "people" e.g. in the Keybase filter.

This will be clearer in the next release.

Can you re-open this until this sort of info is more discoverable in the client?

Okay

@blakejwc
Copy link

I may have missed it when skimming the conversation—could you please add "phone number and email verifications are only verified by the Keybase server" to your privacy policy and also clarify that contact information provided for finding other users does not go through any third-party services?

@jamesdwilson
Copy link

Please consider not requiring me to provide my personal contact info at all to Keybase. I find this abhorrent for a supposedly pro-privacy company to require this information.

See also #18903

@maxtaco
Copy link
Contributor

maxtaco commented Sep 27, 2019

It's considered and it currently works. Please check again. If it's actually requiring an email or phone number, it's a bug.

@jamesdwilson
Copy link

Thank you so much @maxtaco! Removing the email was the solution I was seeking. It no longer has the orange dot now and I am happy!

@aspiers
Copy link

aspiers commented Jul 11, 2020

We wrote some docs at https://keybase.io/docs/chat/phones_and_emails. Let us know if there's anything else you want to know that's missing, we'll add it. Thanks!

That link is (now) 404 - the correct URL is https://book.keybase.io/docs/chat/phones-and-emails.

@aspiers
Copy link

aspiers commented Jul 11, 2020

Also navigation to that page is broken; submitted as keybase/book-content#52

@aspiers
Copy link

aspiers commented Jul 11, 2020

I think the information from that handy document, and tips on privacy implications, should be part of the client documentation.

Agree, we will link to this page from within the client in the next release.

This link is now broken for the same reason as listed in keybase/book-content#52.

Also, you only added it to the mobile client, and missed the desktop client. Filed as #24262.

Can you re-open this until this sort of info is more discoverable in the client?

Okay

Please re-open again until the above is fixed. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

7 participants