Skip to content

keys-pub/website

Repository files navigation

title
keys.pub - Cryptographic key management, sigchains, user identities, signing, encryption, password manager, FIDO2

Install

Download for macOS

Download for Windows

Download for Linux

Or the command line only.

::: warning Unfortunately, this project is not currently being worked on. I may revisit this in the future, if you would like to sponsor development or hire me please reach out at [email protected]. :::

What is it?

Using the desktop app to encrypt a message from gabriel@github to multiple recipients.

::: warning This project is in development and has not been audited. :::

Why?

Key management is hard. We need tools, libraries, apps, services and documentation to help us.

How does it work?

The default key is a EdX25519 key capable of signing and encryption.

We can link this key to your identity on Github, Twitter, Reddit, HTTPS domain, etc, by creating a signed statement and publishing it both there and in your sigchain. (You can either revoke the sigchain statement or remove the signed statement to "unlink".)

You can search for keys by user name and service (e.g. gabriel@github, gabrlh@twitter), or lookup a user by a key identifier using a Web API.

The Saltpack format is used for signing and encryption.

The Noise Protocol is used to create a secure connection (Wormhole) between 2 computers/keys.

Key identifiers are Bech32 format, encode the type of key and public key bytes, and include a checksum with error correction.

The app and command line utility connect to a keysd daemon thats runs as a gRPC service on your computer. 3rd party applications can choose to use the command line interface, the gRPC interface or the go library directly.

keys pull gabriel@github
kex1mnseg28xu6g3j4wur7hqwk8ag3fu3pmr2t5lync26xmgff0dtryqupf80c

> echo "hi 🤓" | keys encrypt -a -r gabriel@github
BEGIN SALTPACK ENCRYPTED MESSAGE. kcJn5brvybfNjz6 D5ll2Nk0Z2co0as ...

The above example pulls the public key for the Github user gabriel, verifies it and creates an encrypted Saltpack message.

What else?

Go Libraries

All the features in the app are available through Go libraries.

See some examples

Similarities/Differences

  • Keybase: This project borrows many ideas from Keybase, including sigchains and user (proofs), and uses Saltpack other packages. However, this project only links a single key to a user.
  • Age: We also use Bech32 as a key identifiers, and convert Ed25519 keys to X25519.