Live data from Hacker News

Zoom Acquires Keybase

keybase.io

411–420 of 751 posts

Re: Zoom Acquires Keybase

#411

It's kinda ironic that Keybase disappears into Zoom the day after Matrix/Riot enabled end-to-end encryption by default, with cross-signed device verification similar to Keybase's concept of connected keys - see https://blog.riot.im/e2e-encryption-by-default-cross-signing... . In other words, a fully open source (and open standardised) alternative continues to exist in the form of Matrix. [disclaimer: project lead for…

It's funny, but I think I get most of my Riot/Matrix news from your comments scattered about hacker news.

Anyway, I run a matrix server for my family (and we all use the Riot client) and the number one issue is encryption and mysterious "Unable to Decrypt" messages. (Closely followed by how rough the Android client is.) This fixes all of that (well, once RiotX replaces the standard Android client) and I think it will remove a lot of friction.

Thanks for your work!

Re: Zoom Acquires Keybase

#412

Earlier quoted context omitted.

Matrix isn’t a company, it’s a non-profit foundation, expressly set up to protect its users: see https://matrix.org/foundation for details. Riot is a Matrix client made by New Vector ( https://vector.im ), the company started by the team who originally created Matrix. The endgame there is to sell Matrix hosting ( https://modular.im ), support and other value-added services for Matrix. We are categorically not going t…

I can imagine keybase delivering a similar statement back in the day, good luck.

Keybase was always grey area since the server-side was proprietary.

Matrix is 100% Free Software and you can run a server yourself.

Re: Zoom Acquires Keybase

#414

For years people have been begging Keybase to allow them to pay them for the service and Chris Coyne always refused. Now they've lost their independence and they're owned by a communication company that has [edit: the majority of] its dev team in China. I use Keybase to talk to my friend in China since it's one of the few services they don't block. This is a pretty disappointing outcome.

[deleted]

Re: Zoom Acquires Keybase

#416
post #139

Earlier quoted context omitted.

> Zoom has not and will not build a mechanism to decrypt live meetings for lawful intercept purposes. That seems to include past tense.

I wonder how important the word "live" is there. Does this statement only apply to real-time decryption of ongoing meetings?

And how long of a delay counts as no longer "live"? After the meeting ends? Five seconds? A millisecond? Does the latency to the server mean it's not "live", since it happened in the past?

Re: Zoom Acquires Keybase

#418
post #296
post #66

Earlier quoted context omitted.

Well, it's pretty clearly an aquihire. Zoom gets a team of highly skilled cryptographers and Internet protocol experts. Good for them. But that means the team that created Keybase as an innovate PKI store won't be working on that anymore. That's not Zoom's business, and probably won't be, as Keybase themselves never figured out how to turn it into a business.

The biggest challenge with acquihiring is retention. Allowing the acquired team to continue what they were doing is the only somewhat foolproof strategy to deal with it. It's a question of pocket depth and expectations. How much will the new team contribute to the "home" product? If expectations are too high chances are that much of the team won't stay and the acquisition will turn out to be a waste of money. With lo…

Retention isn’t going to be a problem in this market. Hiring in general has almost disappeared. And if you get hospitalized with coronavirus without health insurance, it will almost certainly lead to bankruptcy. It’s too risky not to have a job right now.

Re: Zoom Acquires Keybase

#419

Cue the anti-China conspiracy theories. It's incredible how effective the anti-China propaganda has been.

Eric Yuan is at least socially vulnerable to the PRC, before the question of whether he is collaborating. Zoom is mostly developed in PRC, and they were found to have architected their system in an impractical way which “just happened to” expose customer secrets to the PLA.

I just don't find it that plausible that Zoom was accidentally architected in the singular boneheaded way that could send the only keys necessary to decrypt sessions, to servers in a country where those keys can be, and regularly are, secretly compelled from the people transporting them (inb4 somebody plays whataboutism with NSA, yes, it's bad when the U.S. does it too, but NSA doesn't mean to compromise U.S. national security).

That country happens to be the PRC, which is seemingly on the verge of an aggressive war with the U.S. over, among other things, their insistence on illegitimate claims to international waters in the South China sea.

Re: Zoom Acquires Keybase

#420
This is actually a really interesting acquisition, keybase wasn't going anywhere yet was producing some really good stuff. On the other hand zoom is a bunch of security and cryptography amateur, I can't wait to see what's going to happen. Good luck!
Post reply on HN