4 ms·
In case anyone's curious, all Keybase users are now getting "per user keys" (PUKs). It's a key whose secret key is encrypted for each of your devices, and whose
by maxtaco 9y ago
In case anyone's curious, all Keybase users are now getting "per user keys" (PUKs). It's a key whose secret key is encrypted for each of your devices, and whose public key is advertised publicly in your sigchain. New users get a PUK right away, and older users run a background thread to make one. wilg's thread missed a window and would have rerun in 50 minutes, but he solved the problem by starting up a different device.
In turn, all team crypto operations happen for PUKs (and not device keys) so it's necessary to have a PUK before you can use teams. These details are mainly hidden from users, except for bugs (as above, but we'll fix it soon). This is a change from previous designs, but the advantage is that when a user adds a new device, she'll get instant access to all teams, when the PUK's secret key is encrypted for the new device. Whenever a user deletes a device, there's a rekey cascade --- the user's PUK is rotated, and so are all teams the user is a member of.
More info here: https://keybase.io/docs/teams/puk https://keybase.io/docs/teams/puk
- Gaelan 9y agoHow does this interact with device compromise?
- azag0 9y agoFrom the link: "On device revoke, the revoking device makes a new master key, encrypts for the private key for all remaining devices, and writes the new master key to the sigchain along with the statement revoking the old device."
- maxtaco 9y agoExactly. Sorry for the doc bug there. s/master key/PUK/g, now fixed on the site. An earlier internal name for PUKs was "master keys" but we've since changed.