Live data from Hacker News

Keybase iOS Has a Backdoor?

sneak.berlin

1–10 of 56 posts

Re: Keybase iOS Has a Backdoor?

#2
Gotta say, I didn’t expect Keybase to do this after they announced their partnership back in 2018[0]

Automatically attesting keys with no user consent? Not good. This implies you are happy and willing to add arbitrary attestations to a users profile. For now you presumably have a rationale. But this is a can of worms I don’t think should have been opened.

[0] https://keybase.io/blog/keybase-stellar

Re: Keybase iOS Has a Backdoor?

#3
How exactly is signing a transaction on a user's behalf a backdoor? Headline seems extremely clickbaity.

At worst it's sketchy. For me as a user I don't even really care. Should they have asked for explicit consent? Yeah I guess...

Re: Keybase iOS Has a Backdoor?

#5
Not sure how the author defines a backdoor, but my definition does not include the addition of a payment feature, even if you don't want to use it.

The "article" reads like a rant from a user who is upset, that a free app now includes a cryptocoin partnership...

Re: Keybase iOS Has a Backdoor?

#6
post #5

Not sure how the author defines a backdoor, but my definition does not include the addition of a payment feature, even if you don't want to use it. The "article" reads like a rant from a user who is upset, that a free app now includes a cryptocoin partnership...

It's a bit more than "the addition of a payment feature", given the general promise and working principle of Keybase.

A large part of the value proposition has been "combining identities, users can sign attestation and if you see one you know and can validate that the user proved this as part of their identity". I can see how someone would label a mechanism that causes the app to make such a claim without the user being part of it a a backdoor. (EDIT: per their comment, keybase claims that the user always has to agree to sign up for a wallet, so it'd just be about publicly linking it)

Re: Keybase iOS Has a Backdoor?

#7
post #5

Not sure how the author defines a backdoor, but my definition does not include the addition of a payment feature, even if you don't want to use it. The "article" reads like a rant from a user who is upset, that a free app now includes a cryptocoin partnership...

The user is upset about the lack of user consent, which is a red flag in any open-source software.

Re: Keybase iOS Has a Backdoor?

#8
Well, that’s one way to kill your credibility quickly. Even if it was innocent, they should have anticipated that someone would have found this and inferred otherwise, and preemptively disclosed it.

This is public key encryption software, not a toy. Don’t act confused when your users pick everything apart.

Re: Keybase iOS Has a Backdoor?

#10
Keybase has a built in business model that they don't want to take advantage of for some unknown reason.

They made a combo of services that are a "more private" business dropbox, slack and git hosting, which are all business that charge money. I don't understand why they don't charge money for it? Is it because all of their implementations are currently slow and they don't want to be subject to the SLAs that businesses demand? That seems somewhat bizarre since they are solvable problems.

Hell I would like to like to pay them money for the service, in exchange for defined storage quotas (which expand in response to paying more $$$) and better performance but I can't.

Post reply on HN