Live data from Hacker News

Keybase Exploding Messages

keybase.io

51–60 of 155 posts

Re: Keybase Exploding Messages

#51

Author here. I'm seeing the same comment in 4 different places on here, worded with various amounts of hostility. I now wish I had addressed this in the FAQ on the post. There's the suggestion that an exploding feature is worthless, given your partner can just take a screenshot or video of what you sent. This suggestion is missing (1) that your relationship with a partner is disproportionately okay at the time you se…

> But with Snapchat, taking a screenshot is knowingly violating a social agreement.

My exposure to SnapChat suggests that this is not the case. Screenshoters are treated more like rascals than felons. This may depend on the content of the message though. My incoming messages tend to be more silly faces than nudes.

Edit: Or rather, it is the case, but the social agreement is a lightly enforceable one. Closer to not holding an elevator door than eating a coworker's lunch.

Re: Keybase Exploding Messages

#52
post #13

Exploding messages are a stupid gimmick that does not hold up to any nontrivial threat model. What's out there is out there. Clients programmed to throw away plain- and ciphertext can simply be modified to keep them. Is the intersection of the set of clueless fools and set of people who want to use strong encrypted chats really this large??

What non-trivial threat model? Requires one side to have already been compromised and for a new client to be written to not throw away the message. For any secure messaging scheme or encryption protocol how do you actually protect against that?

Without authentication and keeping remote party secure NOTHING will protect you (besides the threat of violence I guess).

There is currently no way to encrypt a message using a secure DNA-based public-key encryption that makes it so only that person can read the message.

You have to show it to whoever is "authorized" at some point. We hope the keys are kept safe to assure us of that.

Re: Keybase Exploding Messages

#53

Author here. I'm seeing the same comment in 4 different places on here, worded with various amounts of hostility. I now wish I had addressed this in the FAQ on the post. There's the suggestion that an exploding feature is worthless, given your partner can just take a screenshot or video of what you sent. This suggestion is missing (1) that your relationship with a partner is disproportionately okay at the time you se…

The most important purpose of these exploding message capabilities is destruction of data that doesn’t need to be archived.

The primary threat is compromise of a device. Keybase allows you to revoke keys but that assumes you are aware that the device has been compromised. Which is already too late for sensitive messages.

The average user doesn’t understand data persistence, or secure destruction of data. Manafort is a good example of this. I wish apps just expired messages by default. I don’t understand why WhatsApp doesn’t have this feature.

Re: Keybase Exploding Messages

#54
post #40

This is like snapchat, they're offering something that they can't actually guarantee. Of course keybase users are going to be generally more knowledgeable than snapchat users and most will understand the limitations.

It's still better to delete the message than to leave it there "because you can't guarantee it 100% either way". Defense in depth.

I quote this far too much on security but "Perfect is the enemy of good." Meaning, people often dismiss improvements because they're technically imperfect.

And it isn't just random forum discussions, major technologies like secure DNS, secure email, etc were held back years because nobody could agree on compromises needed to make improvements.

Re: Keybase Exploding Messages

#55
Of course this is not to address the case where the recipient would take a screenshot. I still find disappearing messages useful to reduce attack surface if say, the phone gets taken away and unlocked by someone else, or a backup of it is found and restored on something else, or if the phone gets compromised at some point at least not all previous messages are exposed, etc. A useful feature, not meant to address scenarios or malicious recipients or previous compromised devices.

Re: Keybase Exploding Messages

#58

Author here. I'm seeing the same comment in 4 different places on here, worded with various amounts of hostility. I now wish I had addressed this in the FAQ on the post. There's the suggestion that an exploding feature is worthless, given your partner can just take a screenshot or video of what you sent. This suggestion is missing (1) that your relationship with a partner is disproportionately okay at the time you se…

A use case I run into often is with people I trust, so I don't fear they will take screenshots, etc, but I don't want to keep that data in the chat history. Most of the time I turn to protonmail using their expire option, now I can use keybase. Most of the time is when I need to pass a password to coworkers.

Re: Keybase Exploding Messages

#59

Author here. I'm seeing the same comment in 4 different places on here, worded with various amounts of hostility. I now wish I had addressed this in the FAQ on the post. There's the suggestion that an exploding feature is worthless, given your partner can just take a screenshot or video of what you sent. This suggestion is missing (1) that your relationship with a partner is disproportionately okay at the time you se…

I'm not a Snapchat user but doesn't that app, at least on Android, alert senders when a receiver takes a screenshot? You can still take a picture with a second device and that functionality isn't totally portable, but interesting feature. Do you think that concept has any utility here?

if someones determined they'll root their android and capture them anyway.

I think it's a great feature if you think of it (exploding messages) not as an assurance against someone who shouldn't be trusted, but that they won't forget to clean the trash.

Re: Keybase Exploding Messages

#60
post #19

Consider this: I send an exploding message, set for 1 day, to Bob. Bob checks his chat a week from now. Does Bob get the message? Or has it already exploded? I guess I'm asking when the actual explosion timer starts - when the message is sent, or when it is read? For group messages, do all parties need to read it before the timer starts?

From the FAQ: Does the timer begin when the message is sent or received? Sent. This seems like the only sensible answer for group chats. And we can't have a different answer for 1-on-1 chats and group chats. That would confuse people. Not the kind of person who reads an FAQ such as yourself, of course. So our answer is simple: you set a timer and the message is gone after that time.

>And we can't have a different answer for 1-on-1 chats and group chats.

What might be the reasoning here that Keybase won't do it yet Signal messenger does start the timer on the "receive" end?

Post reply on HN