Live data from Hacker News

Zoom Acquires Keybase

keybase.io

531–540 of 751 posts

Re: Zoom Acquires Keybase

#531

Earlier quoted context omitted.

The thing I like about Keybase is that keys are always generated client-side and never leave the client, and all of the functionality associated with adding/removing devices is done in a way so that there's no way for a server to tamper with it (aside from denying service). Is that true in Matrix? Several services advertise themselves as "end-to-end" encrypted, but then when you poke harder it turns out either there…

Yes, Matrix is properly end-to-end encrypted (with all keys generated clientside) and has been independently audited as such: https://www.nccgroup.trust/us/our-research/matrix-olm-crypto... . We have gone to huge efforts to prevent MITMs via device verification and cross signing - which specifically addresses both problems of a) losing chat history when you move between devices (via https://github.com/uhoreg/matrix-d…

Just to confirm, if I turn off backup, does anything stop working aside from needing at least one device to be operational at any given time?

Edit: Specifically, is key backup tied to the ability to recover account history on a new device, or can I still get that with key backup disabled as long as I have at least one other device active?

Edit 2: Can you address this paragraph:

> One point for super-paranoid users: currently the private key used to sign your own devices and the private key used to sign other users are encrypted by your recovery passphrase/key and stored on the server to allow recovery if you lose all your devices. We also allow signing keys to be shared (gossiped) between devices, but right now the implementation also stores them encrypted on the server too. This restriction will be fixed in future, but for now if you don’t trust your server with encrypted keys, you may want to hold off on using cross-signing.

If I understand correctly, sounds like security is based on the complexity of your recovery passphrase and an implicit assumption that the passphrase doesn't get transmitted to the server... is that correct?

Re: Zoom Acquires Keybase

#532

Earlier quoted context omitted.

Care to elaborate? Just curious...

https://news.ycombinator.com/item?id=22997245 and requiring gnome-keyring on Linux are issues for me.

Does it actually require GNOME Keyring or does it just use libsecret? Because libsecret is dope and has been nothing but a joy to work with.

Re: Zoom Acquires Keybase

#533

Earlier quoted context omitted.

Lucky for us it is open source? I was hoping to use it to replace Dropbox but they kept not taking my money... small wonder they went for the acquisition.

What was the main difference with this a drop box though? It's encrypted?

[deleted]

Re: Zoom Acquires Keybase

#534

Earlier quoted context omitted.

> was it literally 100% for money or did want of these goods play a role: > cotton, silk, indigo dye, salt, spices, saltpetre, tea, and opium. Surely access to those provides some benefit other than making money, which it also did for them. This is an utterly meaningless distinction. Money is fungible with all of those goods.

I am not sure you are using fungibility completely correctly because the goods have a condition, are perishable, they can be bartered or traded or maybe are fungible with respect to each other but are not literal money and literally interchangeable with money. Anyway, if you want to go down that path you can easily conclude that literally any good or activity is just money, that you live a money-dominated life and we…

> literally any good or activity is just money

In the grand context of life, no (despite the vast majority of large scale events that we learn about in history being usually a result of conflict over money/power) , but in the context of business, as this thread is, yes in a for-profit business literally every good and activity is about money.

Some businesses may choose to sacrifice money for things like employee well-being or community contribution, but that's a choice they make, or more likely are forced to make.

Re: Zoom Acquires Keybase

#535
post #372

Earlier quoted context omitted.

We have letsencrypt and permanent.org as non-profits. An idea of a identity and key non-profit sounds like another critical piece we would need for a free, open web

Seems a bit early to call 'permanent.org' a critical piece, even if it succeeds all it's doing is cloud storage.

That's fair. We'll see how well they execute their vision.

However, after playing with it, checking out their board of directors, and deconstructing their app design, their vision is not really "cloud storage", at least, not the way we typically think of it.

Their long-term mission is preserving a digital legacy, oriented around relationships, families, and organizations. You don't use permanent.org to store things in the cloud that people normally think as "cloud storage", not for the day-to-day stuff. The kind of things you want to store in there are the things you want the world and your descendents to have access to after you die. They won't have to (directly) pay upkeep to keep that legacy preserved. I think that is convincing enough for me to see it as a critical piece of free and open web, even if this doesn't seem obviously connected to the idea of preserving a legacy.

For example, an indie musician wouldn't have to rely on SoundCloud to keep their recorded music around. SoundCloud is not in the business of preserving the creative work; they are in the business of aggregating users and they use user content to do it. Placing those music files in permanent.org has a much better shot of preserving that creative legacy for future generations than leaving it on SoundCloud.

Re: Zoom Acquires Keybase

#537

Earlier quoted context omitted.

Is it called "soften the language" to fix a 100% factual error? Honestly I feel that if you're arguing in one direction or another and haven't checked the facts, maybe it's better not to argue about it?

If the original claim was "100% of the dev team is in China", and the reality is "only 80% of the dev team is in China", then that'd be a 20% factual error, mathematically speaking.

Or would it be a 25% error, i think it would make most sense to calculate the error-difference in relation to the actual value instead of in relation to the erroneous value.

Re: Zoom Acquires Keybase

#538
post #530

For years people have been begging Keybase to allow them to pay them for the service and Chris Coyne always refused. Now they've lost their independence and they're owned by a communication company that has [edit: the majority of] its dev team in China. I use Keybase to talk to my friend in China since it's one of the few services they don't block. This is a pretty disappointing outcome.

Fingers crossed they open source the server portion at least -> https://github.com/keybase/client/issues/24105

+1

Re: Zoom Acquires Keybase

#539
post #532

Earlier quoted context omitted.

https://news.ycombinator.com/item?id=22997245 and requiring gnome-keyring on Linux are issues for me.

Does it actually require GNOME Keyring or does it just use libsecret? Because libsecret is dope and has been nothing but a joy to work with.

https://keys.pub/docs/specs/keyring.html

Re: Zoom Acquires Keybase

#540
post #25

> Zoom does not and will not proactively monitor meeting contents, but our trust and safety team will continue to use automated tools to look for evidence of abusive users based upon other available data. > Zoom has not and will not build a mechanism to decrypt live meetings for lawful intercept purposes. > We also do not have a means to insert our employees or others into meetings without being reflected in the part…

Well, yeah, duh. What do you expect them to do? Hire a PMC and fight a war with the police when they come around to raid the server room? Go into hiding so that the security agency can't steal the upgrade signing key from them? We can't expect all of the internet to operate like Wikileaks and The Pirate Bay. If the justice system is broken, then the people aren't safe.

>What do you expect them to do? Hire a PMC and fight a war with the police when they come around to raid the server room? Go into hiding so that the security agency can't steal the upgrade signing key from them?

No, we want them to assume the same thing we are assuming. That if their service becomes successful, they will be coerced to compromise their users, regardless of how frequently they promise that they would never do so.

If they are even bothering to make public announcements like this, then that means they believe the security of their system can be founded on the honor of their employees. It's important to recognize that this isn't even true if you assume every member of their team is an uncorruptible seraphim.

Instead, where possible, the service should be zero knowledge, where not possible, it should be considered insecure.

Post reply on HN