Collected research
An analysis of logic flaws in web-of-trust services
Web-of-trust services such as Keybase verify identity by scraping a token from a page the user controls. Three logic flaws break that: a gist the victim forks carries the attacker's token under the victim's name, a site allowing dots in usernames lets an attacker publish keybase.txt at its root, and a redirect-following scraper credits the wrong domain, each giving identity takeover.
Record
- Researcher
- EdOverflow and @EdOverflow
- Published by
- EdOverflow
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of EdOverflow and @EdOverflow, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .