Keybase iOS Has a Backdoor?
31–40 of 56 posts
Re: Keybase iOS Has a Backdoor?
#32Are you sure you didn't just accidentally agree to it without realizing it?
Re: Keybase iOS Has a Backdoor?
#33My vague recollection is that I had to agree before Keybase would add a Stellar key to my account. Now it's certainly possible that they've changed things since then to do it automatically, but if so, you should be able to find the code for it as all of the apps are open source: https://github.com/keybase/client Are you sure you didn't just accidentally agree to it without realizing it?
Re: Keybase iOS Has a Backdoor?
#34This article isn't just misleading; it's entirely false, and the title is both highly damaging AND false. Someone below threw out the word "libel" here. I don't know about that, but it's incredibly frustrating to read this title on HN right now.
* THERE IS NO BACKDOOR HERE. Neither the especially scary kind suggested by the title (everyone assumes encryption breaking!), nor the coerced attestation kind suggested in the text.
* Put simply, KEYBASE HAS NOT BACKDOORED its apps and cannot coerce them into signing someone else's Stellar address into a profile.
Further, THIS USER VOLUNTARILY GENERATED A STELLAR PRIVATE KEY. What follows is the flow for generating a Stellar wallet and attaching it to one's profile. The author of this post went through this flow on Feb 4, 2019:
1. Visited the "wallet" tab in the app
2. read a brief description of Stellar in a modal.
3. Saw our disclaimer in a modal (not hidden - printed out front) about how scary cryptocurrency is, how it's permanently attached to your identity, and how it's important to backup your private key if you plan on leaving Keybase.
4. Only once they accepted that, then their client app (not our server) generated a Stellar private key. The app signed the public Stellar address into his sig chain. And the Stellar private key counter-signed, proving bidirectionally. The stellar key was then encrypted in a way so their devices could gossip them to each other.
So to be clear (1) this writer did in fact have that Stellar Key. And (2) we, Keybase, did not. And (3) they knew they were doing it. I encourage anyone curious to go try it out -- the flow has not changed.
I don't understand what their agenda is here. Offering some charity, perhaps they went through this flow late at night and forgot. (Looks like they generated their Stellar account well after midnight in Europe.) But the claims in the post are just false.
I accept some people don't like the opinionated cryptocurrency partnership Keybase has formed. We do like Stellar. However, that doesn't change our security story. Nor does it force users to set up Stellar keys, and something like half of our users have not. Actually - we spent a great effort building around the fact that many users wouldn't be interested in the cryptocurrency side of things.
For those who generate Stellar keys and then change their mind, not wanting them, we'll add the feature to delete all of them.
Anyway, this is just not true. All of it.
Re: Keybase iOS Has a Backdoor?
#35Not every keybase user has a stellar attestation. When it happened to me I think I had to take some action. I don't remember the exact language. Anyone have that detail?
I think you’re right. If I remember correctly I did not have a stellar address until I clicked the ‘Wallet’ button in the Keybase app. That action and the device it was issued from was recorded in my chainlink on Feb 15, 2019 .. which sounds about right. I also remember feeling a bit tricked, because I wasn’t aware that by clicking that button a stellar address would be created and permanently linked to me.
Re: Keybase iOS Has a Backdoor?
#36Official response here - I work for Keybase. This article isn't just misleading; it's entirely false, and the title is both highly damaging AND false. Someone below threw out the word "libel" here. I don't know about that, but it's incredibly frustrating to read this title on HN right now. * THERE IS NO BACKDOOR HERE. Neither the especially scary kind suggested by the title (everyone assumes encryption breaking!), no…
Is there any precedent to getting posts like this (blatant lies) removed from HN? I will report the post, but this article has the potential to be highly damaging to your business, even if it has zero truth to it.
Re: Keybase iOS Has a Backdoor?
#37Keybase has a built in business model that they don't want to take advantage of for some unknown reason. They made a combo of services that are a "more private" business dropbox, slack and git hosting, which are all business that charge money. I don't understand why they don't charge money for it? Is it because all of their implementations are currently slow and they don't want to be subject to the SLAs that business…
Re: Keybase iOS Has a Backdoor?
#38Official response here - I work for Keybase. This article isn't just misleading; it's entirely false, and the title is both highly damaging AND false. Someone below threw out the word "libel" here. I don't know about that, but it's incredibly frustrating to read this title on HN right now. * THERE IS NO BACKDOOR HERE. Neither the especially scary kind suggested by the title (everyone assumes encryption breaking!), no…
I agree with this. It is very sensational & I was expecting something totally different when I clicked on it then what I found.
I think a moderator should change this title.
This is done without any user interaction or consent, violating the fundamental principle of Keybase’s product until now: the user controls their keys.
I am confussed by this. Pre- stellar accounts have to opt in to a wallet... and after you get one you can easily find the private key in the settings.
Re: Keybase iOS Has a Backdoor?
#39My vague recollection is that I had to agree before Keybase would add a Stellar key to my account. Now it's certainly possible that they've changed things since then to do it automatically, but if so, you should be able to find the code for it as all of the apps are open source: https://github.com/keybase/client Are you sure you didn't just accidentally agree to it without realizing it?
I am aware of the things to which I consent. This is not one of them.
Re: Keybase iOS Has a Backdoor?
#40The author clearly was just momentarily angry, used some exaggerated language knowing how it would read and is now trying to stand their ground.
Closest thing to a point I see them making is that generated wallets should include an option to be removed from the attestation list, or be deleted if not wanted to begin with.
Valid (if not slightly petty) user feedback maybe, "BACKDOOR IN SECURE APP ALERT ALERT" definitely not...