Live data from Hacker News

Keybase Exploding Messages

keybase.io

101–110 of 155 posts

Re: Keybase Exploding Messages

#101

Author here. I'm seeing the same comment in 4 different places on here, worded with various amounts of hostility. I now wish I had addressed this in the FAQ on the post. There's the suggestion that an exploding feature is worthless, given your partner can just take a screenshot or video of what you sent. This suggestion is missing (1) that your relationship with a partner is disproportionately okay at the time you se…

I love this! And I love the bomb gif. I still miss your original logo, but have come to like the little girl.

Anyway, maybe it's just me, but I never communicate anything to anyone that would be hugely problematic if published. That is, for that persona. Which is carefully compartmentalized from other personas. So Mirimir has rather restrictive limits. My meatspace identity has even more restrictive limits. But some of my personas have no limits, and are basically throw-aways.

Edit: And that's basically how accounts work on HN, right? I mean, throwaway use seems quite common, and accepted.

Re: Keybase Exploding Messages

#102

Author here. I'm seeing the same comment in 4 different places on here, worded with various amounts of hostility. I now wish I had addressed this in the FAQ on the post. There's the suggestion that an exploding feature is worthless, given your partner can just take a screenshot or video of what you sent. This suggestion is missing (1) that your relationship with a partner is disproportionately okay at the time you se…

This is what people don't seem to get, exploding messages aren't an airtight solution to the risks of sharing sensitive information with someone. You're always taking a risk when you do that. Exploding messages change the default way that sensitive information is handled, and changing the default can have a profound impact, for all the reasons you lay out.

My issue is with the way they are marketed. I would be cool with just a “don’t retain” flag that does just that.

But making a big deal about “exploding” is dangerously incorrect that many users will make incorrect assumptions.

I’m not worried about screenshots, I’m worried about my plugin that archvives all text inbound to me that then requires me to respond to subpeona, etc.

From a security standpoint, this feature should not impact behavior since it is meaningless. If users don’t understand this, then it will cause heartache.

Re: Keybase Exploding Messages

#103

You might be surprised, but for some people this feature can be life or death. My team has been actually waiting for Keybase to have this. We work in countries where some of us are regularly taken aside by the local police or armed forces and our phones are being checked to see if we have anything against the current government. We have to constantly make sure our communication has no traces. We'll be moving to Keyba…

Why don’t you just use a client that deletes messages? Why would you wait for keybase to implement this?

Re: Keybase Exploding Messages

#104
post #53

Author here. I'm seeing the same comment in 4 different places on here, worded with various amounts of hostility. I now wish I had addressed this in the FAQ on the post. There's the suggestion that an exploding feature is worthless, given your partner can just take a screenshot or video of what you sent. This suggestion is missing (1) that your relationship with a partner is disproportionately okay at the time you se…

The most important purpose of these exploding message capabilities is destruction of data that doesn’t need to be archived. The primary threat is compromise of a device. Keybase allows you to revoke keys but that assumes you are aware that the device has been compromised. Which is already too late for sensitive messages. The average user doesn’t understand data persistence, or secure destruction of data. Manafort is…

As a user of messaging services, I nearly never want to delete a message. I want to be able to use my digital memory extension (phone) to store messages so that I can easily recall my conversations. Rarely do I want to delete a message. In fact, I would only want to delete it if it's sensitive: I rarely message such sensitive things. Most people fall into this camp. It's rare for someone to never want any message to be kept.

Why do you want your messages deleted by default when you use one of these secure messaging clients?

Re: Keybase Exploding Messages

#105

This very article shows you the problem with "features" like this. You see that video demonstrating the feature? Notice how you can read the content of the message which was supposedly deleted?

If you don't trust the receiver you should not be sending them anything sensitive to begin with. This feature just eliminates the messages in case something happens to the recipent or their device if either become compromised. Let's say I work IT and user Bob forgot their password again and needs a temporary reset. I can message him his temporary password that expires in 3 minutes so that they can login and set a new…

I trust the receiver.

I don't trust future bad actors who get hold of the device, including the receiver should they turn.

Re: Keybase Exploding Messages

#106
post #53

Earlier quoted context omitted.

The most important purpose of these exploding message capabilities is destruction of data that doesn’t need to be archived. The primary threat is compromise of a device. Keybase allows you to revoke keys but that assumes you are aware that the device has been compromised. Which is already too late for sensitive messages. The average user doesn’t understand data persistence, or secure destruction of data. Manafort is…

As a user of messaging services, I nearly never want to delete a message. I want to be able to use my digital memory extension (phone) to store messages so that I can easily recall my conversations. Rarely do I want to delete a message. In fact, I would only want to delete it if it's sensitive: I rarely message such sensitive things. Most people fall into this camp. It's rare for someone to never want any message to…

Hell, I wish messaging services made conversation much more searchable. I hate having to scroll and scroll to find some past conversation topic that maybe had interesting thoughts/links/shared media.

Re: Keybase Exploding Messages

#108

Author here. I'm seeing the same comment in 4 different places on here, worded with various amounts of hostility. I now wish I had addressed this in the FAQ on the post. There's the suggestion that an exploding feature is worthless, given your partner can just take a screenshot or video of what you sent. This suggestion is missing (1) that your relationship with a partner is disproportionately okay at the time you se…

They always push features to their limits and then criticize. Even telegram’s “screenshot taken” notification can be overcomed by taking a photo/video of the chat with an another phone. But the hassle of doing that is not worth it sometimes, so one can estimate the expectation of the leak, while being completely unsafe before “special forces”. We figured it out in one of in-house intrigues, but didn’t do it even having three phones on the table. Boring, unproductive and shady methods were high enough barriers to stop. Do a good thing and don’t care about pedants.

Re: Keybase Exploding Messages

#109
post #85

As a security layperson my initial reaction was "how can cryptography help with expiring messages, once it's decrypted it's decrypted, that doesn't sound right", but I'm curious if I'm understanding correctly that this is actually two separate features: 1) clients voluntarily respecting "please delete this message at X time" and 2) forward secrecy. And Keybase has tied them together for UX reasons since people tend t…

This is not functionality meant to make sure the other party will not have access to the massage after X time anymore, it's just convenience opsec: If you don't want someone to know X after some time, you should never tell him in the first place (he doesn't need to hijack the keybase client, he can simply "remember" the message). Instead this makes it easy to limit paper trace using a nice UX.

Re: Keybase Exploding Messages

#110

Earlier quoted context omitted.

This is what people don't seem to get, exploding messages aren't an airtight solution to the risks of sharing sensitive information with someone. You're always taking a risk when you do that. Exploding messages change the default way that sensitive information is handled, and changing the default can have a profound impact, for all the reasons you lay out.

My issue is with the way they are marketed. I would be cool with just a “don’t retain” flag that does just that. But making a big deal about “exploding” is dangerously incorrect that many users will make incorrect assumptions. I’m not worried about screenshots, I’m worried about my plugin that archvives all text inbound to me that then requires me to respond to subpeona, etc. From a security standpoint, this feature…

If I seen that flag without your comment, I would have no fn idea what it does and how.
Post reply on HN