Zoom Acquires Keybase
511–520 of 751 posts
Re: Zoom Acquires Keybase
#512Earlier quoted context omitted.
Which already did some things wrong even though Keybase is around for a few years.
Care to elaborate? Just curious...
Re: Zoom Acquires Keybase
#513Given the security concerns around Zoom, and the apparent lack of QC that might have prevented those concerns, this news is appalling. I love Keybase, it's used by many people, but I suspect it will now die a quick death. More accurately I suspect it will slide into a coma - not quite dead, but not in wide use anymore either.
why not look at the problem the other way around? I don't have much respect for zoom's security practices, while I do have much respect for the keybase team. Perhaps this is Zoom's way of admitting that there is no way they can just solve the problem internally by keeping doing what they're doing and they need to get some fresh blood and build upon good practices designed outside their current culture.
Re: Zoom Acquires Keybase
#514Earlier quoted context omitted.
Is wayland support even a femto blip on Zoom's radar ?
They do keep saying "multiplatform", but I guess that's Windows/macOS/iOS/Android, not Linux. They're not the only ones though, this is what most companies call "on any device".
Re: Zoom Acquires Keybase
#515Re: Zoom Acquires Keybase
#516Earlier quoted context omitted.
It seems that we live in an era where if you made bad decisions in the past, you can never be trusted to make good decisions ever again. Even if you own your bad decisions and show lots of improvement. Nope. Once a pariah, always a pariah.
Zoom is only a pariah on Hacker News.
Re: Zoom Acquires Keybase
#517It's kinda ironic that Keybase disappears into Zoom the day after Matrix/Riot enabled end-to-end encryption by default, with cross-signed device verification similar to Keybase's concept of connected keys - see https://blog.riot.im/e2e-encryption-by-default-cross-signing... . In other words, a fully open source (and open standardised) alternative continues to exist in the form of Matrix. [disclaimer: project lead for…
The thing I like about Keybase is that keys are always generated client-side and never leave the client, and all of the functionality associated with adding/removing devices is done in a way so that there's no way for a server to tamper with it (aside from denying service). Is that true in Matrix? Several services advertise themselves as "end-to-end" encrypted, but then when you poke harder it turns out either there…
All keys are stored clientside, with the exception of if you enable serverside key backup, when they are then encrypted and optionally stored serverside to allow you to recover your history if you lose all your devices.
Re: Zoom Acquires Keybase
#518Re: Zoom Acquires Keybase
#519Earlier quoted context omitted.
Keybase was dead as soon as they took VC money. Their original purpose — tying identities to keys — could have been a nice small non-profit. But there aren't fortunes to be made from managing GPG keys, so they had to pivot into shark jumping.
We have letsencrypt and permanent.org as non-profits. An idea of a identity and key non-profit sounds like another critical piece we would need for a free, open web
Re: Zoom Acquires Keybase
#520For years people have been begging Keybase to allow them to pay them for the service and Chris Coyne always refused. Now they've lost their independence and they're owned by a communication company that has [edit: the majority of] its dev team in China. I use Keybase to talk to my friend in China since it's one of the few services they don't block. This is a pretty disappointing outcome.
I am curious: do they block Zoom?
This is likely related to both nations having rules that allow only their own agencies to wiretap.