Live data from Hacker News

Keys.pub – Manage cryptographic keys and user identities

keys.pub

51–60 of 92 posts

Re: Keys.pub – Manage cryptographic keys and user identities

#51
post #43

Hi all, I'm the author of keys.pub. Can the mods change the title of this post at all? This project is meant to be supportive of ideas from Keybase and to promote Saltpack and this title is weirdly disparaging. (Edit: Title was changed, thanks!) Thanks everyone for the feedback. This project is in its early stages but the goal is to make it easier to manage and securely store keys and secrets. I'm currently working o…

You might want to put some sort of identifying information about yourself somewhere, on the site or the github project? Maybe a key of some kind? :-)

Re: Keys.pub – Manage cryptographic keys and user identities

#52
post #27

Earlier quoted context omitted.

The entire cryptocurrency airdrop thing has caused lots of noise, triggered campaigns to try and hack/social engineer accounts that would qualify the attacker to grab more cryptocurrency, ... It makes it vastly less likely I'll recommend Keybase with those associations, which diminishes the value of the "key part". (Not recommending it both because it makes me question the long-term priorities of the product and beca…

Isn't Keybase built exactly for this though? To be able to look at the connected accounts/proofs, and know that a given Keybase user has proven control of those accounts? An attacker looking for crypto may have hacked someone's HN or GitHub. However, with Keybase, you can establish someone you want to talk to has linked their Twitter and their web domain and the like, whereas an attacker probably does not have access…

Keybase promised to give out free cryptocurrency to everyone who linked an existing Github and HN account, which lead to an attack wave on such accounts from people wanting to claim that: https://essays.suryad.com/hnhack/

If you are an identity service and do things that paint a target on others online identities, causing attackers to want to link my account with their fake accounts on your service for profit, you have an image problem. Similarly, that's not something I particularly want important services to be funded through long-term.

Re: Keys.pub – Manage cryptographic keys and user identities

#53
post #40

Earlier quoted context omitted.

Precisely the reasoning for writing tools that do one thing very well.

The problem with that is that it completely disregards one market, i.e., the one that wants an integrated system. You could probably install six programs that do these individual things, but then you'd have to install six programs. That's a non-starter for those looking for the integrated solution.

What if you made a unified installer that installs those six tools configured in a certain default way?

Re: Keys.pub – Manage cryptographic keys and user identities

#54
post #43

Hi all, I'm the author of keys.pub. Can the mods change the title of this post at all? This project is meant to be supportive of ideas from Keybase and to promote Saltpack and this title is weirdly disparaging. (Edit: Title was changed, thanks!) Thanks everyone for the feedback. This project is in its early stages but the goal is to make it easier to manage and securely store keys and secrets. I'm currently working o…

Sure, no problem. I've used the HTML doc title but I had to shorten it to fit 80 chars. If there's a better—more accurate and neutral title—let us know.

(Submitted title was "Keys.pub – Keybase Without the Cruft".)

Edit: I changed the title to something the author suggested in an email. Before that it was "Keys.pub – Manage keys, sigchains, identities, signing, encryption, passwords".

Re: Keys.pub – Manage cryptographic keys and user identities

#55
post #54
post #43

Hi all, I'm the author of keys.pub. Can the mods change the title of this post at all? This project is meant to be supportive of ideas from Keybase and to promote Saltpack and this title is weirdly disparaging. (Edit: Title was changed, thanks!) Thanks everyone for the feedback. This project is in its early stages but the goal is to make it easier to manage and securely store keys and secrets. I'm currently working o…

Sure, no problem. I've used the HTML doc title but I had to shorten it to fit 80 chars. If there's a better—more accurate and neutral title—let us know. (Submitted title was "Keys.pub – Keybase Without the Cruft".) Edit: I changed the title to something the author suggested in an email. Before that it was "Keys.pub – Manage keys, sigchains, identities, signing, encryption, passwords".

That's great, thank you.

Re: Keys.pub – Manage cryptographic keys and user identities

#57
post #17
post #6

Earlier quoted context omitted.

Sounds interesting, how is this feature useful?

One way we use it is for shared team secrets (e.g. API tokens) in infrastructure scripts. https://github.com/plyint/encpass.sh/blob/master/extensions/...

Used a similar strategy to great success at a previous startup for various credentials. Everything else had higher friction and was causing devs to do insecure things to avoid that friction.

Re: Keys.pub – Manage cryptographic keys and user identities

#58
This is very cool but I screwed up 2 of my "sigchains" to Reddit and to GitHub by deleting the underlying messages (I didn't realize I wasn't supposed to) so now two of my identities are messed up and I can't even use the app. I get this message: "panic: Unknown user status content-invalid (13)". Great project, but needs a better way to clean up invalid keys and re-issue them.

Re: Keys.pub – Manage cryptographic keys and user identities

#59
post #43

Hi all, I'm the author of keys.pub. Can the mods change the title of this post at all? This project is meant to be supportive of ideas from Keybase and to promote Saltpack and this title is weirdly disparaging. (Edit: Title was changed, thanks!) Thanks everyone for the feedback. This project is in its early stages but the goal is to make it easier to manage and securely store keys and secrets. I'm currently working o…

Your project is very cool. Could you help me fix my account though? I messed up two of the IDs: mfrager@github & mfrager@reddit. Will these be automatically purged from the keys.pub server after a certain amount of time for being invalid?

Re: Keys.pub – Manage cryptographic keys and user identities

#60
post #33

I, for one, am happy Keybase user, excited about their new features and can see it already becoming a much better (but not ideal) alternative to Signal for private IM (proper encryption, every device is first-class, usable CLI, no phone-number bullshit, good team chats, etc). But I do see that the same reason I am optimistic is the same reason many users are disappointed and they're right - Keybase seems to have pivo…

Keybase jumped the shark with their crypto coin offering.

They added a wallet feature that was compatible with an existing crypto coin, there was no offering.
Post reply on HN