Keybase.io Vulnerability (2014)
ejj.io
ejj.io
For instance, the hypothetical "I want to track twitter.com/ev" person, who tries "keybase track ev".
Keybase client responds with:
✔ public key fingerprint: 1206 AE26 8AD6 8171 5390 7EC5 2E5D F3D2 4DC0 DE19 ✔ "not_ev" on twitter: https://twitter.com/not_ev/status/448871129671680001 Is this the ev you wanted? [y/N] n
...To which, it's not unreasonable to expect any person to note that this person is "not_ev". It would be really sloppy to pull the trigger on this.
I would recommend personally clicking through all the Twitter/Github links to make sure they're not some carefully made impersonator account, but even doing the bare minimum (reading the output of "keybase track") should get you there.
As an aside: if anyone wants a keybase invite hit me up, I've still got 7 free.
Also posted a year ago: https://news.ycombinator.com/item?id=7487797
Totally a lame vulnerability? Yes. Pretty effective? Also yes. If you go back in the github issue[1], it was even good enough to fool Chris, who founded the site, for 10 seconds.