Live data from Hacker News

Ask HN: Keybase Alternatives?

news.ycombinator.com

121–130 of 237 posts

Re: Ask HN: Keybase Alternatives?

#123
post #61

If you just want to share your public key safely, a .well-known directory on your domain works these days: https://wiki.gnupg.org/WKD

Just a quick note on WKD since I've been bitten by this a few days ago: as soon as you set it up, some people will start using your keys automatically, without even knowing it (eg. it seems that ProtonMail automatically uses keys found on a WKD to encrypt outgoing mails). While in itself it's not a bad idea, you'd better prepare for this to avoid looking stupid like me, when you receive a casual encrypted mail and yo…

> ...when you receive a casual encrypted mail and you're not able to read it (my private keys are air-gapped...

Could you elaborate on why you put your public key in well-known and also how (and for what purposes) you use your air-gapped private key? As an average user, I’ve always been worried about private keys being stolen or lost.

Re: Ask HN: Keybase Alternatives?

#126
post #92

> I myself mostly use the following features from Keybase: Chat, KBFS, Git repositories and encrypting messages sent out-of-band via PGP in Keybase (and the various cryptographic tools [signing, validation etc]) While all these features are individually nice, I kinda started to worry about Keybase as a product when they started bolting on stuff like this. I think the key (pun intended) to stable & ongoing success in…

The key differentiator of Keybase (at least back when I joined during early alpha) is that it links identities across different web properties, so that one can easily find someone’s personal site(s) or profiles on other platforms with cryptographic certainty. AFIACT this crucial aspect is missing from keys.pub.

> easily find someone’s personal site(s) or profiles on other platforms with cryptographic certainty

I always thought it was meant the other way around: if you know someone from HN, you just have to look them up on Keybase and you can talk to them.

Re: Ask HN: Keybase Alternatives?

#127
post #119

Earlier quoted context omitted.

I've had one person use it to find me after a conference, confirm my various online identities (he only had one handle to work with), and contact me securely. That leadededededed to paying work, so it was important even if it only happened one time.

> That lead to paying work Typo: it should be “led”, not “lead”

typo corrected, thanks!!

Re: Ask HN: Keybase Alternatives?

#128
post #85

Since nobody's mentioned Wire, it's not a 1:1 alternative but it's close in terms of chat. I don't think any 1:1 alternative to KeyBase will rise up anytime soon, hosting git and files will be a bit to build up to. Website: https://wire.com/en/ Their backend is open source unlike KeyBase: https://github.com/wireapp/wire-server

We've been using Wire in our company for a few years now, I can't say it's a great UX or bug-free, but it gets the job done and supports most things we want like being available on all platforms, key verification (proper e2ee, not like Keybase that trusts the server on first use), (group) calling and (group) video calling, audited, open source, sending files of course, timed/expiring messages, no need for a phone num…

Wire is great on paper (and PowerPoint slides). Not on my machines.

Re: Ask HN: Keybase Alternatives?

#129
post #114

Earlier quoted context omitted.

If you have reason to be concerned about the CCP undermining your communications infrastructure, it's a distinction without a difference. Like yes, you're correct, the person you're replying to is wrong. But the reason they brought it up remains valid with the correction.

If someone first makes a false accusation, then post a “correction” only to double down on a lesser yet still false accusation, I’d say it’s reason enough to conclude that they’re arguing in bad faith and attempting to slander. You don’t need to spread false information to make a possibly valid point. People also increasingly use this sort of “yeah, they play fast and loose with facts but they have a point so cheers”…

If you're getting hung up about the difference of me saying "entirely" and "largely" – yeah ok you're right. Mathematically, for the word "entirely" to be true, it would have to be every single breathing soul at zoom that ever touches any tech.

I actually did mis-read from an older article that all their development is done in China (the language is that their R&D and tech teams are concentrated in China). Hence I said entirely. But yes let's go with largely. This is an argument about who has jurisdiction to force the altering of parts of their tech stack.

Entirely vs Largely: Does that do _anything_ to alter my concerns? Nope.

Re: Ask HN: Keybase Alternatives?

#130
post #8

I am also curious here. I have used and advocated strongly for Keybase with a couple of local government clients to send sensitive files back and forth (not sensitive in the sense of national security, but more to preserve privacy and store encrypted at rest). But I want to get ahead of the concern that Keybase is now owned by a Chinese company, which instantly compromises it. PGP is dead on arrival, since it's an ov…

Having development in the US just means they'd have to be concerned about illicit US government interference. How is that an improvement? https://www.aclu.org/other/surveillance-under-usapatriot-act https://www.eff.org/deeplinks/2020/03/earn-it-act-violates-c...

Yes, and to the couple of my clients who are governments of AMERICAN cities, that answer is clear. (And that was my original premise).

I am no cheerleader for NSA surveillance. People who know me in real life are probably tired of hearing me talk about it (and privacy/security in general).

Post reply on HN