Live data from Hacker News

Keybase’s browser extension subverts its encryption

palant.de

11–20 of 79 posts

Re: Keybase’s browser extension subverts its encryption

#11
post #7

While they could have expanded better on their reasoning for not using iframes, I feel this is an overly dramatic post. The browser extension is not their main product and they explicitly say so. The author is completely dismissing [0] the entire product just because of a side project, which in the worst case scenario could be fixed by the community by submitting a patch. It is also strange that the author seems to f…

The author is completely dismissing [0] the entire product If he's looking for bug bounties (be it for cash, kudos, principles, or to see it fixed), and he finds a security bug and doesn't get a bounty, why would he keep looking? Fool me once, shame on you; fool me twice...

There are rules for bug bounty programs: - https://hackerone.com/keybase

Re: Keybase’s browser extension subverts its encryption

#12

While they could have expanded better on their reasoning for not using iframes, I feel this is an overly dramatic post. The browser extension is not their main product and they explicitly say so. The author is completely dismissing [0] the entire product just because of a side project, which in the worst case scenario could be fixed by the community by submitting a patch. It is also strange that the author seems to f…

It all comes down to trustworthyness with products such as Keybase. If I were them, I'd make sure that Keybase comes across as trustworthy in all of their endeavours.

Re: Keybase’s browser extension subverts its encryption

#13
Keybase also silently subverts smartcards for in-memory keys per my findings here: https://github.com/keybase/keybase-issues/issues/1946

In general I find Keybase to be a step forward in user experience and two steps backwards in terms of actual security. They just don't seem to care about the latter at all and have not demonstrated any cooperation with standards bodies like the OpenPGP working group where members have expressed interest multiple times in adding generic URL uids to the openpgp public key itself to replicate and decentralize the idea of social media based trust bootstrapping (the one good idea from Keybase in spite of terrible execution). Instead they insist on their complex proprietary walled garden system that does not integrate with existing keyservers and throws everything on the bitcoin blockchain for reasons.

Keybase has become the IE of crypto and I can't take any security project seriously that even -integrates- with them.

Re: Keybase’s browser extension subverts its encryption

#14
post #2

I have to say I am surprised and disappointed. Keybase has up until now been a shining example of doing crypto right but still accessible and easy to use. This decision falls strictly on the wrong side of the line of acceptable compromises. > there were technical reasons why iframes didn’t work, though I forget the details It could be that there is one or a couple of engineers at Keybase who made this decision and ar…

When they started asking me for my private key and claiming it'll be secure because it's "encrypted" that raised a red flag for me.

Then I found out that they're not using popular and audited libraries like OpenPGPjs instead... writing their own!

Re: Keybase’s browser extension subverts its encryption

#15
post #2

I have to say I am surprised and disappointed. Keybase has up until now been a shining example of doing crypto right but still accessible and easy to use. This decision falls strictly on the wrong side of the line of acceptable compromises. > there were technical reasons why iframes didn’t work, though I forget the details It could be that there is one or a couple of engineers at Keybase who made this decision and ar…

Honest question: what makes you think they have -ever- done crypto right?

As best I can tell they have rolled their own mostly closed source crypto solution from day 1.

Re: Keybase’s browser extension subverts its encryption

#16
post #13

Keybase also silently subverts smartcards for in-memory keys per my findings here: https://github.com/keybase/keybase-issues/issues/1946 In general I find Keybase to be a step forward in user experience and two steps backwards in terms of actual security. They just don't seem to care about the latter at all and have not demonstrated any cooperation with standards bodies like the OpenPGP working group where members ha…

This description perfectly captures my impression on Keybase too (especially the part on unwillingness to decentralize their social-media based identities).

For the record it soon may be possible to use native GnuPG through the browser extension:

> Installer: New optional module "Browser Integration" to register GnuPG as backend for Mailvelope 3.0.

Source: https://www.gpg4win.org/change-history.html

But given Keybase's track record I already know they're not interested in that.

Re: Keybase’s browser extension subverts its encryption

#17
post #16
post #13

Keybase also silently subverts smartcards for in-memory keys per my findings here: https://github.com/keybase/keybase-issues/issues/1946 In general I find Keybase to be a step forward in user experience and two steps backwards in terms of actual security. They just don't seem to care about the latter at all and have not demonstrated any cooperation with standards bodies like the OpenPGP working group where members ha…

This description perfectly captures my impression on Keybase too (especially the part on unwillingness to decentralize their social-media based identities). For the record it soon may be possible to use native GnuPG through the browser extension: > Installer: New optional module "Browser Integration" to register GnuPG as backend for Mailvelope 3.0. Source: https://www.gpg4win.org/change-history.html But given Keybase…

Any trust went out the window when I realized I could pull out my smartcard and continue signing things. My head exploded.

Re: Keybase’s browser extension subverts its encryption

#18
post #7

Earlier quoted context omitted.

The author is completely dismissing [0] the entire product If he's looking for bug bounties (be it for cash, kudos, principles, or to see it fixed), and he finds a security bug and doesn't get a bounty, why would he keep looking? Fool me once, shame on you; fool me twice...

There are rules for bug bounty programs: - https://hackerone.com/keybase

Which one of those "outside the scope" categories would you say this one falls into then?

To me it reads like there's nothing preventing this bug report from deserving a bounty.

Re: Keybase’s browser extension subverts its encryption

#19
post #10
post #7

Earlier quoted context omitted.

The author is completely dismissing [0] the entire product If he's looking for bug bounties (be it for cash, kudos, principles, or to see it fixed), and he finds a security bug and doesn't get a bounty, why would he keep looking? Fool me once, shame on you; fool me twice...

Keybase is clearly stating that it is infact not a bug, but an intentionally not implemented feature.

You think the guy who wrote the article should swallow that line of BS and be motivated to do more free pentesting for them?

Re: Keybase’s browser extension subverts its encryption

#20
post #13

Keybase also silently subverts smartcards for in-memory keys per my findings here: https://github.com/keybase/keybase-issues/issues/1946 In general I find Keybase to be a step forward in user experience and two steps backwards in terms of actual security. They just don't seem to care about the latter at all and have not demonstrated any cooperation with standards bodies like the OpenPGP working group where members ha…

They don't throw everything on the blockchain for no reason. They specifically back up the root of the merkel tree into the blockchain.

Honestly, the OpenPGP world has so competently failed at usability and is only adopted by the most hard core of nerds. Even I have stopped using it for the most part.

And that it is two steps back in security overall is just not true. Maybe in some individual features that you care about, but not in general.

And the same thing counts that always counted, crypto that nobody is using is not protecting anything.

The have mostly moved on from GPG any a different libraries now. The GPG is mostly a legacy feature.

Post reply on HN