Live data from Hacker News

Introducing the Keybase filesystem

keybase.io

91–100 of 501 posts

Re: Introducing the Keybase filesystem

#92
> Your app will encrypt just for you and then awake and rekey in the background when that Twitter user joins and announces a key.

Isn't this the weak link in the chain? If you can convince the client that you're the person the data was encrypted for, it will re-encrypt it with a new key and send it to you, thus making the encryption useless. What's the protection against this, other than "don't worry, we won't introduce bugs"? (I'm not saying Random Twitter Troll will do this, but couldn't "the government" compel Keybase to re-encrypt your content with a key they have?)

What does the encryption add here that a server controlling access doesn't?

Re: Introducing the Keybase filesystem

#93
post #3

Earlier quoted context omitted.

Came here to say pretty much the same thing. It's slick and easy to use. It's actually the 'dropbox' I've always wanted and if they introduce a storage limit I'd pay. https://keybase.io/jgrahamc

What's also impressive is doing away with Dropbox's clunky "selective sync". While having everything stored locally sounds like a good idea at first, as you store more and more data is gets less and less user-friendly; in other words, power-users get the worst user experience. Additionally, creating an easy way to share files with friends without taking up their quota is awesome. This looks like it could be a very, v…

[deleted]

Re: Introducing the Keybase filesystem

#96

I've got invites (9) for Keybase that are collecting dust if anyone wants one. Email in profile. WOW: That happened fast, I'm all out of invites now... 2 minutes after posting emails started coming in and within 3 minutes I was out. Sorry if you didn't get one...

If anyone has invites still, erg at trifocus.net

I'll delete this comment once I get one.

Thanks!

Re: Introducing the Keybase filesystem

#97

Why is centralized crypto with a freemium biz model so welcomed? Remember Snowden? Remember parse?

"Centralised Crypto" in what sense? Unless I'm very much mistaken, your private key never leaves your control - signing/encryption is done client-side.

They are the trusted source for my public key.

Re: Introducing the Keybase filesystem

#98
On the page it says it is "open source Go". Does that mean that, at least theoretically, I (or another independent provider) could build this and run my own personal keybase server? If so, that would really excite me. The one thing that really keeps me away from most cloud storage and sync services is lockin. I just am not willing to be come super dependent on a service that is building their business around proprietary lockin rather than providing an excellent service.

Re: Introducing the Keybase filesystem

#99
post #82

About 4 years ago I was involved with a commercial software project attempting to do exactly this. What we built worked but it wasn't positioned in a way that interested our target audience (Enterprise customers). First, bravo for making it happen in a way that is getting people excited. Second, I sincerely wish you the best luck in getting people to pay for it in a way that is sustainable for a business. We built a…

I think they only gloss over the security on the front side. Have you read the documentation?

https://keybase.io/docs/server_security https://keybase.io/docs/sigchain

They do specifically mention the problem of javascript crypto. They also mention the fact they want to be mirrored.

That said, I don't actually know enough to make smart decisions in this space. But I'd be interested in your thoughts after reading the docs (if you haven't already).

Post reply on HN