anyone care to expand on the practical applications/implications/threat model where this makes sense?
It works as long as no one takes a screenshot.
Keybase Exploding Messages
11–20 of 155 posts
Re: Keybase Exploding Messages
#12Re: Keybase Exploding Messages
#13Re: Keybase Exploding Messages
#14click on some text in the article, it "explodes" :)
Re: Keybase Exploding Messages
#15"I have nothing to hide"
Because no one is trying to hurt you
Re: Keybase Exploding Messages
#16Re: Keybase Exploding Messages
#17Re: Keybase Exploding Messages
#18 I send an exploding message, set for 1 day, to Bob.
Bob checks his chat a week from now.
Does Bob get the message? Or has it already exploded?
I guess I'm asking when the actual explosion timer starts - when the message is sent, or when it is read? For group messages, do all parties need to read it before the timer starts?Re: Keybase Exploding Messages
#19Consider this: I send an exploding message, set for 1 day, to Bob. Bob checks his chat a week from now. Does Bob get the message? Or has it already exploded? I guess I'm asking when the actual explosion timer starts - when the message is sent, or when it is read? For group messages, do all parties need to read it before the timer starts?
Does the timer begin when the message is sent or received?
Sent.
This seems like the only sensible answer for group chats. And we can't have a different answer for 1-on-1 chats and group chats. That would confuse people. Not the kind of person who reads an FAQ such as yourself, of course.
So our answer is simple: you set a timer and the message is gone after that time.
Re: Keybase Exploding Messages
#20As I understand, Keybase chat is open-source? ( https://github.com/keybase/client ) I don't have time to read through the code right now, but I'd love to hear how they implemented exploding messages with untrustworthy clients. I've thought about it a few times before, and it seems one of the few places that closed software has an advantage - You can't easily force third-party clients to delete messages. If they've so…
It is impossible to implement this feature "safely" even with trusted clients -- worst case I take a screenshot or even a photograph of the device displaying the message before it explodes. If you don't trust the person at the other end, this is never going to work. It's more useful for "we both agree that we don't want a paper trail" kind of thing.