Live data from Hacker News

Keybase iOS Has a Backdoor?

sneak.berlin

41–50 of 56 posts

Re: Keybase iOS Has a Backdoor?

#41

Official response here - I work for Keybase. This article isn't just misleading; it's entirely false, and the title is both highly damaging AND false. Someone below threw out the word "libel" here. I don't know about that, but it's incredibly frustrating to read this title on HN right now. * THERE IS NO BACKDOOR HERE. Neither the especially scary kind suggested by the title (everyone assumes encryption breaking!), no…

This appears to be legit. I got the email about free Lumens, but I don't have a Stellar key signed by my private key. Granted, I haven't signed into my account from any of Keybase's mobile apps, but it seems unlikely that they would backdoor _only_ the mobile apps.

Re: Keybase iOS Has a Backdoor?

#42
I am _extremely_ disappointed by this news.

I would have been _much much_ happier to hear "we are not charging $5 (or $30 or $60 or whatever) per year for keybase users" than "we're going to make claims that you've signed or agreed to attestations which you do not know about and would never have consented to".

I've just update my keybase bio to say:

I'M NOT SURE I TRUST KEYBASE ANY MORE - THEY ARE REPORTEDLY SIGNING ATTESTATIONS FROM ME WITHOUT NOTIFICATION OR CONSENT. TAKE APPROPRIATE CARE WITH ANYTHING THEY"VE CLAIMED I'VE SIGNED

Re: Keybase iOS Has a Backdoor?

#43

Official response here - I work for Keybase. This article isn't just misleading; it's entirely false, and the title is both highly damaging AND false. Someone below threw out the word "libel" here. I don't know about that, but it's incredibly frustrating to read this title on HN right now. * THERE IS NO BACKDOOR HERE. Neither the especially scary kind suggested by the title (everyone assumes encryption breaking!), no…

Reading the article, I took sympathy with the Keybase team. As a dev working at a relatively large software company, I commonly see the smallest issues causing users to knee-jerk and claim conspiracy to harm them. Of course, this headline is shocking, and many probably upvoted it without reading the article, or having any context into your software. Is there any precedent to getting posts like this (blatant lies) rem…

The post appears to have been flagged and is no longer visible on the front page.

Honestly I don’t know if it’s better to hide it so it doesn’t do more damage, or to change the title so people who already saw it can see it’s false.

I actually can’t ever recall a story on HN that was so highly upvoted and damaging yet unsubstantiated. What a crappy situation.

Re: Keybase iOS Has a Backdoor?

#44
post #42

I am _extremely_ disappointed by this news. I would have been _much much_ happier to hear "we are not charging $5 (or $30 or $60 or whatever) per year for keybase users" than "we're going to make claims that you've signed or agreed to attestations which you do not know about and would never have consented to". I've just update my keybase bio to say: I'M NOT SURE I TRUST KEYBASE ANY MORE - THEY ARE REPORTEDLY SIGNING…

Not sure if you're still following, but Keybase replied and this entire article was blatantly false. There's an explicit opt-in here.

Re: Keybase iOS Has a Backdoor?

#45

How exactly is signing a transaction on a user's behalf a backdoor? Headline seems extremely clickbaity. At worst it's sketchy. For me as a user I don't even really care. Should they have asked for explicit consent? Yeah I guess...

keybase uses private/pub key. if keybase can use your private key to sign on your behalf, then maybe they can use that same private key to read private documents, transfer money, etc. no one but the user should ever have or know about the private key.

They write the software so they can likely do whatever they want with your key, even if it's only decrypted client-side. At the end of the day I still trust them which is necessary with all software, especially closed-source software.

Re: Keybase iOS Has a Backdoor?

#47
post #7
post #5

Not sure how the author defines a backdoor, but my definition does not include the addition of a payment feature, even if you don't want to use it. The "article" reads like a rant from a user who is upset, that a free app now includes a cryptocoin partnership...

The user is upset about the lack of user consent, which is a red flag in any open-source software.

But he apparently did consent, and just doesn't remember doing so.

Re: Keybase iOS Has a Backdoor?

#48
post #2

Gotta say, I didn’t expect Keybase to do this after they announced their partnership back in 2018[0] Automatically attesting keys with no user consent? Not good. This implies you are happy and willing to add arbitrary attestations to a users profile. For now you presumably have a rationale. But this is a can of worms I don’t think should have been opened. [0] https://keybase.io/blog/keybase-stellar

> Automatically attesting keys with no user consent? Not good.

Yeah. That's why Keybase doesn't. The app tells you exactly what you're doing, and requires you to confirm you want to do it. It even has a scary warning about cryptocurrencies.

Re: Keybase iOS Has a Backdoor?

#49

Official response here - I work for Keybase. This article isn't just misleading; it's entirely false, and the title is both highly damaging AND false. Someone below threw out the word "libel" here. I don't know about that, but it's incredibly frustrating to read this title on HN right now. * THERE IS NO BACKDOOR HERE. Neither the especially scary kind suggested by the title (everyone assumes encryption breaking!), no…

> Someone below threw out the word "libel" here.

Where? Your comment, and now this reply, are the only occurrences of that word on this page.

It's really irksome when someone tells me I consent to something that I don't. I'm the authority on whether or not my keys were used improperly—no one else.

You used my keys in a way in which I did not want. That's the beginning and the end of it.

I hope you got paid a lot for it.

Here are dozens of other users who made it all the way to GitHub and provided feedback in an effort to resolve the same issue:

https://github.com/keybase/client/issues/15555

How many others just gave up?

Re: Keybase iOS Has a Backdoor?

#50
post #49

Official response here - I work for Keybase. This article isn't just misleading; it's entirely false, and the title is both highly damaging AND false. Someone below threw out the word "libel" here. I don't know about that, but it's incredibly frustrating to read this title on HN right now. * THERE IS NO BACKDOOR HERE. Neither the especially scary kind suggested by the title (everyone assumes encryption breaking!), no…

> Someone below threw out the word "libel" here. Where? Your comment, and now this reply, are the only occurrences of that word on this page. It's really irksome when someone tells me I consent to something that I don't. I'm the authority on whether or not my keys were used improperly—no one else. You used my keys in a way in which I did not want. That's the beginning and the end of it. I hope you got paid a lot for…

Those users appear to acknowledge that there was consent sort before the key was generated.

> I created a stellar wallet to explore the feature

Post reply on HN