While they could have expanded better on their reasoning for not using iframes, I feel this is an overly dramatic post. The browser extension is not their main product and they explicitly say so. The author is completely dismissing [0] the entire product just because of a side project, which in the worst case scenario could be fixed by the community by submitting a patch. It is also strange that the author seems to f…
The author is completely dismissing [0] the entire product If he's looking for bug bounties (be it for cash, kudos, principles, or to see it fixed), and he finds a security bug and doesn't get a bounty, why would he keep looking? Fool me once, shame on you; fool me twice...
Keybase’s browser extension subverts its encryption
11–20 of 79 posts
Re: Keybase’s browser extension subverts its encryption
#12While they could have expanded better on their reasoning for not using iframes, I feel this is an overly dramatic post. The browser extension is not their main product and they explicitly say so. The author is completely dismissing [0] the entire product just because of a side project, which in the worst case scenario could be fixed by the community by submitting a patch. It is also strange that the author seems to f…
Re: Keybase’s browser extension subverts its encryption
#13In general I find Keybase to be a step forward in user experience and two steps backwards in terms of actual security. They just don't seem to care about the latter at all and have not demonstrated any cooperation with standards bodies like the OpenPGP working group where members have expressed interest multiple times in adding generic URL uids to the openpgp public key itself to replicate and decentralize the idea of social media based trust bootstrapping (the one good idea from Keybase in spite of terrible execution). Instead they insist on their complex proprietary walled garden system that does not integrate with existing keyservers and throws everything on the bitcoin blockchain for reasons.
Keybase has become the IE of crypto and I can't take any security project seriously that even -integrates- with them.
Re: Keybase’s browser extension subverts its encryption
#14I have to say I am surprised and disappointed. Keybase has up until now been a shining example of doing crypto right but still accessible and easy to use. This decision falls strictly on the wrong side of the line of acceptable compromises. > there were technical reasons why iframes didn’t work, though I forget the details It could be that there is one or a couple of engineers at Keybase who made this decision and ar…
Then I found out that they're not using popular and audited libraries like OpenPGPjs instead... writing their own!
Re: Keybase’s browser extension subverts its encryption
#15I have to say I am surprised and disappointed. Keybase has up until now been a shining example of doing crypto right but still accessible and easy to use. This decision falls strictly on the wrong side of the line of acceptable compromises. > there were technical reasons why iframes didn’t work, though I forget the details It could be that there is one or a couple of engineers at Keybase who made this decision and ar…
As best I can tell they have rolled their own mostly closed source crypto solution from day 1.
Re: Keybase’s browser extension subverts its encryption
#16Keybase also silently subverts smartcards for in-memory keys per my findings here: https://github.com/keybase/keybase-issues/issues/1946 In general I find Keybase to be a step forward in user experience and two steps backwards in terms of actual security. They just don't seem to care about the latter at all and have not demonstrated any cooperation with standards bodies like the OpenPGP working group where members ha…
For the record it soon may be possible to use native GnuPG through the browser extension:
> Installer: New optional module "Browser Integration" to register GnuPG as backend for Mailvelope 3.0.
Source: https://www.gpg4win.org/change-history.html
But given Keybase's track record I already know they're not interested in that.
Re: Keybase’s browser extension subverts its encryption
#17Keybase also silently subverts smartcards for in-memory keys per my findings here: https://github.com/keybase/keybase-issues/issues/1946 In general I find Keybase to be a step forward in user experience and two steps backwards in terms of actual security. They just don't seem to care about the latter at all and have not demonstrated any cooperation with standards bodies like the OpenPGP working group where members ha…
This description perfectly captures my impression on Keybase too (especially the part on unwillingness to decentralize their social-media based identities). For the record it soon may be possible to use native GnuPG through the browser extension: > Installer: New optional module "Browser Integration" to register GnuPG as backend for Mailvelope 3.0. Source: https://www.gpg4win.org/change-history.html But given Keybase…
Re: Keybase’s browser extension subverts its encryption
#18Earlier quoted context omitted.
The author is completely dismissing [0] the entire product If he's looking for bug bounties (be it for cash, kudos, principles, or to see it fixed), and he finds a security bug and doesn't get a bounty, why would he keep looking? Fool me once, shame on you; fool me twice...
There are rules for bug bounty programs: - https://hackerone.com/keybase
To me it reads like there's nothing preventing this bug report from deserving a bounty.
Re: Keybase’s browser extension subverts its encryption
#19Earlier quoted context omitted.
The author is completely dismissing [0] the entire product If he's looking for bug bounties (be it for cash, kudos, principles, or to see it fixed), and he finds a security bug and doesn't get a bounty, why would he keep looking? Fool me once, shame on you; fool me twice...
Keybase is clearly stating that it is infact not a bug, but an intentionally not implemented feature.
Re: Keybase’s browser extension subverts its encryption
#20Keybase also silently subverts smartcards for in-memory keys per my findings here: https://github.com/keybase/keybase-issues/issues/1946 In general I find Keybase to be a step forward in user experience and two steps backwards in terms of actual security. They just don't seem to care about the latter at all and have not demonstrated any cooperation with standards bodies like the OpenPGP working group where members ha…
Honestly, the OpenPGP world has so competently failed at usability and is only adopted by the most hard core of nerds. Even I have stopped using it for the most part.
And that it is two steps back in security overall is just not true. Maybe in some individual features that you care about, but not in general.
And the same thing counts that always counted, crypto that nobody is using is not protecting anything.
The have mostly moved on from GPG any a different libraries now. The GPG is mostly a legacy feature.