Live data from Hacker News

Keys.pub – Manage cryptographic keys and user identities

keys.pub

21–30 of 92 posts

Re: Keys.pub – Manage cryptographic keys and user identities

#21
I, for one, am happy Keybase user, excited about their new features and can see it already becoming a much better (but not ideal) alternative to Signal for private IM (proper encryption, every device is first-class, usable CLI, no phone-number bullshit, good team chats, etc).

But I do see that the same reason I am optimistic is the same reason many users are disappointed and they're right - Keybase seems to have pivoted and they are headed in a completely different direction than they were when we joined.

Keys.pub looks to fulfill precisely the promise of "what Keybase was supposed to be". And crucially, I think; looks to be fully open source (server-side included, no sketchy opaque metadata spider-web by a US corporate).

I do see these two projects as fully complementary.

It would be interesting if this could, optionally, import pubkeys from Keybase as well. I think these could be complementary.

Re: Keys.pub – Manage cryptographic keys and user identities

#23
Lots of keybase early users here. I started really using it relatively recently, and mostly like it, regardless of "losing its way".

What I use are is the chat, git and filesystem. Verifying other people's identities - not so much.

The only problems are related to the GUI having hiccups, opening images posted to the chat, say. Git and filesystem are relatively slow, but can live with that.

Re: Keys.pub – Manage cryptographic keys and user identities

#24

Earlier quoted context omitted.

I see this from a lot of people and I'm puzzled, can you not just avoid using the features you don't like? I don't see anyone going "I used to use VS Code but they added a database viewer so I stopped".

The keybase client went from a small CLI to a persistently connected app that ties into a filesystem, cryptocurrency platform, chat ecosystem and more. Nothing is free. Adding features takes up resources, adds complexity and errors and increases attack surface. Sometimes that's an OK tradeoff - I like being able to see images in my email client. Sometimes the tradeoff is not worth it - my text centric IDE has no busi…

That's fair, my question was more about the cryptocurrency feature specifically. "General bloat" I can understand, if you only care about the keys.

It seems to me, though, that the key part is just the first step in an entire featureset: Once you have a reliable way to get trusted encryption keys for any person, you can build a whole lot of useful functionality on top of that, which is what they've been doing.

Personally, I wouldn't have much use for just the key exchange, and I really like the encrypted chat/repos/files/etc on top, but I can understand different preferences there.

Re: Keys.pub – Manage cryptographic keys and user identities

#25

I was a very early user of Keybase and I've been super disappointed in the direction they've gone. They've had some neat ideas along the way but packing them onto the key service and the cryptocurrency missteps have caused me to shy away from them. This looks like a good start for a real competitor. Obviously it's early but I'm seeing the right things.

I see this from a lot of people and I'm puzzled, can you not just avoid using the features you don't like? I don't see anyone going "I used to use VS Code but they added a database viewer so I stopped".

If they didn’t insist on putting a kext on my system (comes with the app for kbfs), or registering a persistent launchd agent that can’t be disabled (comes with the kbfs-free CLI, always reinstalls itself), then sure, I could ignore the features.

But they did, so their clients got kicked out of my system.

I also got spammy alerts mentioned by siblings (in email).

Re: Keys.pub – Manage cryptographic keys and user identities

#26
So there is no network that connects all the keys.pub clients together? Are you just supposed to do point-to-point connections through Wormhole? Still trying to understand it.

I keep hoping for a decentralized/federated network implementation for Keybase (or forked version) that will basically take the place of the centrally managed Keybase servers.

Re: Keys.pub – Manage cryptographic keys and user identities

#27

Earlier quoted context omitted.

The keybase client went from a small CLI to a persistently connected app that ties into a filesystem, cryptocurrency platform, chat ecosystem and more. Nothing is free. Adding features takes up resources, adds complexity and errors and increases attack surface. Sometimes that's an OK tradeoff - I like being able to see images in my email client. Sometimes the tradeoff is not worth it - my text centric IDE has no busi…

That's fair, my question was more about the cryptocurrency feature specifically. "General bloat" I can understand, if you only care about the keys. It seems to me, though, that the key part is just the first step in an entire featureset: Once you have a reliable way to get trusted encryption keys for any person, you can build a whole lot of useful functionality on top of that, which is what they've been doing. Person…

The entire cryptocurrency airdrop thing has caused lots of noise, triggered campaigns to try and hack/social engineer accounts that would qualify the attacker to grab more cryptocurrency, ... It makes it vastly less likely I'll recommend Keybase with those associations, which diminishes the value of the "key part". (Not recommending it both because it makes me question the long-term priorities of the product and because I don't want to explain why I'm recommending "weird cryptocurrency-stuff", which is the impressions others could have)

Re: Keys.pub – Manage cryptographic keys and user identities

#28

Earlier quoted context omitted.

I guess one man's cruft is another man's crucial feature.

Precisely the reasoning for writing tools that do one thing very well.

There is a downside to that, though... an integrated product that can do more than one thing can often be easier to use than two separate ones

Re: Keys.pub – Manage cryptographic keys and user identities

#29
This loses something important about Keybase sigchains: on Keybase, a sigchain represents an identity and not a single key, which makes it possible to add separate keys for different devices and to seamlessly replace and revoke keys over time. (Non-key-specific sigchains let the Keybase client do interesting things like automatically re-encrypting shared data when someone revokes an old key.)

Tying sigchains to keys seems limiting, and I'm curious if there's a reason for it. Otherwise, I like this a bunch.

Re: Keys.pub – Manage cryptographic keys and user identities

#30

I, for one, am happy Keybase user, excited about their new features and can see it already becoming a much better (but not ideal) alternative to Signal for private IM (proper encryption, every device is first-class, usable CLI, no phone-number bullshit, good team chats, etc). But I do see that the same reason I am optimistic is the same reason many users are disappointed and they're right - Keybase seems to have pivo…

Agree. This could be a useful way to expand the ecosystem that Keybase kick-started. We really need a modern alternative to the PGP ecosystem, and Keybase has been clear that they only want to do a subset of that.

Of course I also really like the client-facing stuff that Keybase has done. Roll out hasn't been perfect, but they provide a lot of useful, secure collaboration tools.

Post reply on HN