Notices where this attachment appears
-
> Keybase’s iOS client has received a backdoor.
> It seems that Stellar, the extremely well-funded and well-marketed cryptocurrency, has struck a deal with Keybase to “airdrop” (give away) their tokens to keybase users in an effort to drive adoption.
> Keybase updated their iOS client to sign an attestation, as a user, that a given stellar address belongs to them, even if it does not. This is done without any user interaction or consent, violating the fundamental principle of Keybase’s product until now: the user controls their keys.
> Of course, the user controls their keys using Keybase’s software, which, under normal circumstances, means the user controls their keys. But in this instance, Keybase’s software decided to sign, for a user, without their knowledge or consent, an attestation saying that username*keybase.io is a legitimate stellar payment address for the user—even if the user has never heard of it.
https://sneak.berlin/20190929/keybase-backdoor/