Live data from Hacker News

Security Through Transparency

security.googleblog.com

21–30 of 41 posts

Re: Security Through Transparency

#21
post #4

> The relationship between online personas and public keys should be automatically verifiable and publicly auditable. This description sure sounds like exactly what https://keybase.io provides.

Can't upvote this enough!

I even wrote a prototype chrome extension for a few friends and myself: http://lettergram.github.io/AnyCrypt/

I love the idea of keybase, I just wish it was used by more people.

Re: Security Through Transparency

#22
post #4

> The relationship between online personas and public keys should be automatically verifiable and publicly auditable. This description sure sounds like exactly what https://keybase.io provides.

I just got an invite to Keybase. Is there a reason why

1. it's invite based?

2. it supports very few external services that you can verify (I can't figure out a way to verify LinkedIn or Gitlab for instance) ?

Re: Security Through Transparency

#23
post #22
post #4

> The relationship between online personas and public keys should be automatically verifiable and publicly auditable. This description sure sounds like exactly what https://keybase.io provides.

I just got an invite to Keybase. Is there a reason why 1. it's invite based? 2. it supports very few external services that you can verify (I can't figure out a way to verify LinkedIn or Gitlab for instance) ?

I don't really have a good answer for you. Invite-based services are a good way to scale out without getting a huge spike all at once (even Gmail was introduced using invites), but I don't know how long Keybase intends to stick with the invite model or when they'll expand it.

As for services, each service that's supported presumably needs custom code, and also needs to have a publicly-auditable way to post a proof that cannot be done by anyone other than the owner of the account (e.g. for Twitter you need to actually tweet something, for GitHub you need to post a gist, etc). I don't have a LinkedIn account or use GitLab so I don't know if those services have an effective way to handle such a proof.

For reference, here's a ticket asking for LinkedIn support - https://github.com/keybase/keybase-issues/issues/1115. Here's one for GitLab - https://github.com/keybase/keybase-issues/issues/1242 - which documents some barriers there (such as no API to get GitLab snippets).

Re: Security Through Transparency

#24
post #4

> The relationship between online personas and public keys should be automatically verifiable and publicly auditable. This description sure sounds like exactly what https://keybase.io provides.

Off-topic: I have 10 Keybase invites — does anybody want or need one?

Re: Security Through Transparency

#25
post #24
post #4

> The relationship between online personas and public keys should be automatically verifiable and publicly auditable. This description sure sounds like exactly what https://keybase.io provides.

Off-topic: I have 10 Keybase invites — does anybody want or need one?

Unless I'm missing something, an invite is not need to use Keybase.

Re: Security Through Transparency

#26
post #20

This is awesome! I was at bar with a group of security people / cryptographers during the Real World Crypto conference last week. We were discussing what we thought some of the most important security research papers from the last five years were. Everyone agreed that CONICKS (which is what Key Transparency is based on), will likely have a huge impact in the next five years or so. I'm excited to see Google finally op…

Got a link to a copy of this paper you can share? A quick google search didn't turn up anything useful.

Re: Security Through Transparency

#27
post #24

Earlier quoted context omitted.

Off-topic: I have 10 Keybase invites — does anybody want or need one?

Unless I'm missing something, an invite is not need to use Keybase.

Yes it is to skip the long line, although there are semi-secret invite codes that can be used infinitely.

Re: Security Through Transparency

#29
post #13

The post mentioned the inadequacy of PGP. I would like to see a comparison with Keybase ( https://keybase.io ) which addresses similar problems.

CT is mostly an automagic comparison. You don't need to do anything and you get encryption and trust and all that stuff. While keybase is a step in the right direction, it does not make communication any more secure by default. You still need to setup PGP and use it to benefit from keybase.io So in essence; CT is that one step ahead of keybase.io that makes it much much more useful but keybase is still a step in the…

Keybase does not need a PGP setup. Keybase has moved on from that and use NaCl to solve the multi-device problem. GPG is just one more node in your trust chain.

Re: Security Through Transparency

#30
post #24
post #4

> The relationship between online personas and public keys should be automatically verifiable and publicly auditable. This description sure sounds like exactly what https://keybase.io provides.

Off-topic: I have 10 Keybase invites — does anybody want or need one?

Yes, please.

My email is in my profile.

Post reply on HN