And stupidly try to restart the same shit in the same niche.
Zoom Acquires Keybase
491–500 of 751 posts
Re: Zoom Acquires Keybase
#492Re: Zoom Acquires Keybase
#493Re: Zoom Acquires Keybase
#494Re: Zoom Acquires Keybase
#495Earlier quoted context omitted.
I remember thinking they were neat a few years ago, I made an account and tried out exchanging some keys. It’s slick but I don’t see how it was ever going to be a mainstream product for non technical users who mostly don’t even understand what encryption is. Haven’t heard anything about them since, I kinda already assumed they were dead.
It doesn’t have to be mainstream. A niche product can be viable. Unless you begin to accept investors money who want an exponential growth at all cost. But if that’s what you want as an investor, no idea why you would invest in Keybase.
Re: Zoom Acquires Keybase
#496Please please please can someone fork and RE the backend code?
Re: Zoom Acquires Keybase
#497Keybase's side of the announcement: https://keybase.io/blog/keybase-joins-zoom > What the Keybase team will be doing > Initially, our single top priority is helping to make Zoom even more secure. There are no specific plans for the Keybase app yet. Ultimately Keybase's future is in Zoom's hands, and we'll see where that takes us. Of course, if anything changes about Keybase’s availability, our users will get plenty o…
Re: Zoom Acquires Keybase
#498Earlier quoted context omitted.
Anyone can upload a key to keybase dot com too. You should never trust a key belongs to someone unless you have verified the fingerprint by other means e.g. speaking to them. This is basic security we have known since the 80s. Keybase dot com is a step backwards if anything because of the false sense of security it creates, as if they don't have a giant attack surface.
You don't understand what Keybase does. The whole point is that you don't just use it to upload a key. You link various verified identifies of yours across the web to your Keybase account so people know the PGP key there is the one of the verified person. It's a way to tie all your verified identifies together. If someone would manage to compromise a bunch of identities of someone on the internet, and then create a K…
My real wish is that keybase supported ssh keys and would provide them as an agent.
Re: Zoom Acquires Keybase
#499There were local, volunteering missions to help healthcare workers, the homeless, etc all done by some "non-profit" in europe. Those missions had state-sponsored ads, and I volunteered online. As soon as they required me to use zoom, I told them I would not use zoom. I just go on their whatsapp thing, so of course I get less info, etc. I really fail to understand how Zoom became so popular, and I was recently wonderi…
For Zoom though, I feel it's quite trivial to see how it became popular. Of all the various video chat/conferencing software that exists, Zoom is the easiest for the layperson to setup and use while also tending to be the best performing in terms of audio/video quality, latency, large numbers of users on a single call, etc. My girlfriend was able join a Zoom call with her parents a few days ago without even telling them how to do it; yesterday I overheard a 30 minute phone conversation while she tried to explain to her mother how to edit a facebook post (unsuccessfully, despite valiant efforts).
Outside of this niche community, basically nobody knows or cares about Zoom's various security gaffes. They just want something that works and gets out of the way. And I say all this as somebody who has watched others use Zoom a few times and read about it, but never used it myself nor felt the inclination to.
I'm sure you're right about specialists and strategies to try to spark mass adoption being things that happen, but the technology matters as well.
Re: Zoom Acquires Keybase
#500It's kinda ironic that Keybase disappears into Zoom the day after Matrix/Riot enabled end-to-end encryption by default, with cross-signed device verification similar to Keybase's concept of connected keys - see https://blog.riot.im/e2e-encryption-by-default-cross-signing... . In other words, a fully open source (and open standardised) alternative continues to exist in the form of Matrix. [disclaimer: project lead for…
Is that true in Matrix? Several services advertise themselves as "end-to-end" encrypted, but then when you poke harder it turns out either there is some sort of TOFU (so an opportunity for the server to insert itself) or else there is no device continuity (which means in the case of e.g. Whatsapp that keys are reprovisioned almost promiscuously to avoid bad UX). Whatsapp is a particularly bad example because (a) I lose chat history when I move devices, and yet (b) the UX does not require an old device to authenticate the new one, so I can compromise conversations (at least moving forward) if I can compromise a server.
How end-to-end is Matrix really, and how similar is the new support to Keybase's key management flow?