Live data from Hacker News

Keybase’s browser extension subverts its encryption

palant.de

51–60 of 79 posts

Re: Keybase’s browser extension subverts its encryption

#51
post #29

Meh. I wouldn't (and didn't) trust Keybase anyway. My reasoning is that you're given some encryption software (keybase javscript on its website or browser extension) but the software is changing all the time: it might get re-downloaded on a tab refresh, the extension might download a "new version" or whatever... So basically you're supposed to trust an always changing piece of code (can you be auditing every piece of…

Facebook later disabled the possibility interacting with its chat via external non-facebook-branded clients (afaik) I don't think that's true, actually. The existence of Caprine[0] seems to suggest otherwise! 0: https://github.com/sindresorhus/caprine

I remember when Pidgin OTR worked fine with the old Facebook Chat, which I believe was based on the XMPP protocol. The move to Facebook Messenger deprecated this API and I don't think it works anymore.

In the case of Caprine, it appears not to use any official API and is just scraping the web page for the right elements. This seems quite fragile and also a non-trivial body of code.

Re: Keybase’s browser extension subverts its encryption

#52
post #20
post #13

Keybase also silently subverts smartcards for in-memory keys per my findings here: https://github.com/keybase/keybase-issues/issues/1946 In general I find Keybase to be a step forward in user experience and two steps backwards in terms of actual security. They just don't seem to care about the latter at all and have not demonstrated any cooperation with standards bodies like the OpenPGP working group where members ha…

They don't throw everything on the blockchain for no reason. They specifically back up the root of the merkel tree into the blockchain. Honestly, the OpenPGP world has so competently failed at usability and is only adopted by the most hard core of nerds. Even I have stopped using it for the most part. And that it is two steps back in security overall is just not true. Maybe in some individual features that you care a…

> the OpenPGP world has so competently failed at usability

Don't you know? There's a rule that all cryptographic software must be arcane and obscure and virtually impossible to use correctly by anyone other than obsessive nerds.

Re: Keybase’s browser extension subverts its encryption

#53

if you are going to encrypt a message, it must at some point be input without encryption. Just like you wouldn't type a sensitive message with someone looking over your shoulder, you can use common sense and limit use of this extension. Keybase is fantastic. i've been using keybase for 2 years now and have had no issue accessing my files through kbfs. with keybase teams you can store secrets at rest and make them eas…

> if you are going to encrypt a message, it must at some point be input without encryption.

How do you feel about someone else composing the message that "you" (your encryption software) are going to encrypt? Because that's what the article is talking about.

Re: Keybase’s browser extension subverts its encryption

#54
post #32
post #31

Earlier quoted context omitted.

Looks to me like someone posted spam and it got removed. And yes, unfortunately, that's a thing on github these days.

Unless the title was lifted from another issue for the purpose of spam... ...this actually looks like a potential security weakness that was purged from the public space. (CWE-921)

it wasn't purged, per say. if you click "edited by maxtaco" on KirtiRamchandani's first comment, you get a dropdown to select the versions, and you can still find the original text.

Re: Keybase’s browser extension subverts its encryption

#55
post #20
post #13

Keybase also silently subverts smartcards for in-memory keys per my findings here: https://github.com/keybase/keybase-issues/issues/1946 In general I find Keybase to be a step forward in user experience and two steps backwards in terms of actual security. They just don't seem to care about the latter at all and have not demonstrated any cooperation with standards bodies like the OpenPGP working group where members ha…

They don't throw everything on the blockchain for no reason. They specifically back up the root of the merkel tree into the blockchain. Honestly, the OpenPGP world has so competently failed at usability and is only adopted by the most hard core of nerds. Even I have stopped using it for the most part. And that it is two steps back in security overall is just not true. Maybe in some individual features that you care a…

We already have a distributed backup system: the keyserver network. There are also efforts like DANE to put it in DNS. They however refuse to sync with it. They only sync with their own proprietary servers using their own protocol.

Also there are projects in the OpenPGP world making very easy to use workflows and interfaces without centralizing or breaking standards. OpenKeychain for android is a fantastic example of this.

I use OpenKeychain on my phone and can sign files, access passwords, or decrypt email by tapping my yubikey to it. I can tap someone elses key to my phone to import their key to my addressbook. No terminals or fuss and at no point does any key come in contact with system memory of any device involved so I have strong assurances it can't be stolen even if my phone is totally compromised.

A big example of the 2 steps backwards of keybase: they use keys in system memory and abandoned any compatibility with the openpgp smartcard spec, yubikeys, etc. The industry is moving to smartcards for very good reason: malware is a thing and it can use/steal keys from system memory without user interaction. A key stored in a yubikey 4 OTOH never touches system memory and requires a physical touch for each operation.

You can have usability without throwing out security and standards. Keybase is just another in a long line of companies ignorantly throwing out any security features they don't understand using usability as an excuse for bad engineering.

Re: Keybase’s browser extension subverts its encryption

#56
post #41
post #17

Earlier quoted context omitted.

Any trust went out the window when I realized I could pull out my smartcard and continue signing things. My head exploded.

You just don't seem to understand how the service you are using works and guess what. Its different then pure PG. It was not designed to work with your smart-card as it is not primarily about that. Guess what, other people like me just realized that Keybase was not designed to be used like that and didn't use the smart-card together with Keybase. I guess you can fault them for not saying that explicitly but since the…

They used my openpgp key to setup my account. They link it on my profile as my key... I guess this gave me some crazy idea this was the key they actually use, not some silently created in memory keys that don't use the openpgp spec at all.

Re: Keybase’s browser extension subverts its encryption

#57

Earlier quoted context omitted.

Wire's apps feel slow and bloated on both desktop and mobile. Compared to Telegram, Wire is almost unusable.

As a user, Wire has been fast and reliable and usable (even by non-techies) on iOS for several years, across a wide range of network conditions and hostile networks. They are contributing to an IETF protocol (“MLS”) for E2E messaging, which is a long-term path to messenger interoperability.

I have not had the described slowness on Android and Windows (I think I tried it on Linux too) so I'm not sure what the parent commentator is speaking of.

Edit:

Relevant: https://tools.ietf.org/html/draft-barnes-mls-protocol-00

Re: Keybase’s browser extension subverts its encryption

#58

Earlier quoted context omitted.

Wire's apps feel slow and bloated on both desktop and mobile. Compared to Telegram, Wire is almost unusable.

As a user, Wire has been fast and reliable and usable (even by non-techies) on iOS for several years, across a wide range of network conditions and hostile networks. They are contributing to an IETF protocol (“MLS”) for E2E messaging, which is a long-term path to messenger interoperability.

a long-term path to messenger interoperability.

I remember when we had that before E2E was popularized, it was standardized, and then walled gardens broke their interoperability in the name of (claimed) better user experience and user numbers.

Re: Keybase’s browser extension subverts its encryption

#60
post #20
post #13

Keybase also silently subverts smartcards for in-memory keys per my findings here: https://github.com/keybase/keybase-issues/issues/1946 In general I find Keybase to be a step forward in user experience and two steps backwards in terms of actual security. They just don't seem to care about the latter at all and have not demonstrated any cooperation with standards bodies like the OpenPGP working group where members ha…

They don't throw everything on the blockchain for no reason. They specifically back up the root of the merkel tree into the blockchain. Honestly, the OpenPGP world has so competently failed at usability and is only adopted by the most hard core of nerds. Even I have stopped using it for the most part. And that it is two steps back in security overall is just not true. Maybe in some individual features that you care a…

> OpenPGP ... is only adopted by the most hard core of nerds.

This seems pretty inaccurate.

* Lots of software projects sign their releases with PGP.

* Almost all Linux distributions sign their software with PGP. If you use Linux, your security relies critically PGP.

* Github has support for PGP, and I see people use it.

* My random server hoster happens to sign all their emails with PGP.

You could claim that all these systems are run "by the most hard core of nerds", but at that point the statement loses its relevance.

Post reply on HN