Live data from Hacker News

Keybase Exploding Messages

keybase.io

121–130 of 155 posts

Re: Keybase Exploding Messages

#122

Earlier quoted context omitted.

I would be hesitant to trust a controversial screenshot of text because I know that can be faked so easily. A lot of people don't have that awareness, though.

Another feature of Keybase's exploding messages is that when they expire, the text is replaced by the md5sum of the message. So a faked screenshot can (potentially; I haven't verified this) be proven to be faked by appealing to the md5sum in its place, crucially, without needing to reveal the contents of the original message.

That would only work if everything else about the photo was identical - device, resolution, carrier, time, battery level. Seems very unlikely one could substitute even identical text in a screenshot with enough accuracy to get the same hash from an image file.

Re: Keybase Exploding Messages

#123
post #53

Earlier quoted context omitted.

The most important purpose of these exploding message capabilities is destruction of data that doesn’t need to be archived. The primary threat is compromise of a device. Keybase allows you to revoke keys but that assumes you are aware that the device has been compromised. Which is already too late for sensitive messages. The average user doesn’t understand data persistence, or secure destruction of data. Manafort is…

As a user of messaging services, I nearly never want to delete a message. I want to be able to use my digital memory extension (phone) to store messages so that I can easily recall my conversations. Rarely do I want to delete a message. In fact, I would only want to delete it if it's sensitive: I rarely message such sensitive things. Most people fall into this camp. It's rare for someone to never want any message to…

Plenty of people feel exactly the opposite, and avoid using messaging services for many purposes because of it. They want the bulk of what they say to fade away, because it is ephemeral, and they don't want to worry about it forever. More and more people are aware that, even if what you say today is perfectly benign, tomorrow it may be a problem. And why create potential problems, when there is absolutely no benefit to you in putting your request to your partner to buy some eggs on the way home on a permanent record?

You might worry about not being able to find something you said. Others worry about being able to find something they said.

I personally chose my defaults appropriately, with work stuff getting archived and everything else not even getting backed up. And realistically, even the work stuff is completely useless after a couple of years; a problem I have is not finding information, but finding current, useful information.

Re: Keybase Exploding Messages

#124

Earlier quoted context omitted.

Hell, I wish messaging services made conversation much more searchable. I hate having to scroll and scroll to find some past conversation topic that maybe had interesting thoughts/links/shared media.

As far as I know, Slack and Telegram are currently the two leaders in the “searchable” area of messaging apps.

Any client with proper log files (many IRC clients, Pidgin, etc) is much better than Slack, which uses word indexing rather than full search, meaning it doesn't find the message "helloworld.com" when you search for "world".

Re: Keybase Exploding Messages

#125

Author here. I'm seeing the same comment in 4 different places on here, worded with various amounts of hostility. I now wish I had addressed this in the FAQ on the post. There's the suggestion that an exploding feature is worthless, given your partner can just take a screenshot or video of what you sent. This suggestion is missing (1) that your relationship with a partner is disproportionately okay at the time you se…

Do you know https://privnote.com ?

I think it is very easy and useful. It is great to have something like this on Keybase.

Re: Keybase Exploding Messages

#126
post #97

Seriously, do we need a stupid animation and a silly-looking "ka-boom" image? It just comes across as trying too hard to be cute and ends up looking childish and stupid.

Metaphors like this help people understand what's happening. If the message just vanishes that could be for any number of reasons. But with this animation it's clear that the message is being erased. Keep in kind not everyone is a hackernews-reading computer expert.

Re: Keybase Exploding Messages

#127
post #53

Earlier quoted context omitted.

The most important purpose of these exploding message capabilities is destruction of data that doesn’t need to be archived. The primary threat is compromise of a device. Keybase allows you to revoke keys but that assumes you are aware that the device has been compromised. Which is already too late for sensitive messages. The average user doesn’t understand data persistence, or secure destruction of data. Manafort is…

As a user of messaging services, I nearly never want to delete a message. I want to be able to use my digital memory extension (phone) to store messages so that I can easily recall my conversations. Rarely do I want to delete a message. In fact, I would only want to delete it if it's sensitive: I rarely message such sensitive things. Most people fall into this camp. It's rare for someone to never want any message to…

I deliberately don't pay for Slack because of this. The 10,000 message limit is perfect for "enough memory to be useful, not enough to be dangerous". I'd love to see it as a feature in other messaging apps (i.e. "permanently erase all messages over 6 months old")

Re: Keybase Exploding Messages

#128
post #33
post #20

Earlier quoted context omitted.

A dead simple way to thwart the “screenshot” attack is to release a tool for accurately falsifying a screenshot. I’ve never seen this employed in practice though.

Photo, audio, and video evidence should already be dismissed until one is able to verify the integrity and source. All of these can already be believably faked - it's just a matter of educating people that a layperson can easily create fake things by using tools developed by research teams. Fake text is the easiest to fake if you can identify the font used - any image editor will work. HN uses 9pt Verdana, even witho…

Not even that much effort, just open the browser's dev tools and change the text in the post to say whatever you like.

Re: Keybase Exploding Messages

#130

Author here. I'm seeing the same comment in 4 different places on here, worded with various amounts of hostility. I now wish I had addressed this in the FAQ on the post. There's the suggestion that an exploding feature is worthless, given your partner can just take a screenshot or video of what you sent. This suggestion is missing (1) that your relationship with a partner is disproportionately okay at the time you se…

These are great rationale, but I think they belong in the feature marketing and UI, not just the FAQ.

As publicized (by Keybase and every other platform), exploding messages appear to put control of post-receipt management in the hand of the sender. This is especially credible coming from Keybase, since you guys are educating a lot of people about possibilities with careful crypto (e.g. forward secrecy). This has risks... you mention the Snapchat user who was protected from bullying, but what about the teen who wouldn't have sent that pic in the first place but felt safer because of SnapChat -- only to be bullied over a screenshot anyway?

Your description here is that exploding messages make it easier for both sides to announce and abide by a social contract about deletion. A name like "flag messages for auto-delete" (I'm sure someone can do better) would set the right impression.

Post reply on HN