Live data from Hacker News

Zoom Acquires Keybase

keybase.io

551–560 of 751 posts

Re: Zoom Acquires Keybase

#551
post #532

Earlier quoted context omitted.

https://news.ycombinator.com/item?id=22997245 and requiring gnome-keyring on Linux are issues for me.

Does it actually require GNOME Keyring or does it just use libsecret? Because libsecret is dope and has been nothing but a joy to work with.

I've seen some examples of GNOME keyring being required because it implements the freedesktop secrets standard (which I admit to knowing nothing of) where other secret managers do not. Presumably meaning there us no common interface, so we just pick the one that implements the spec. One example:

https://github.com/pithos/pithos/issues/559

Re: Zoom Acquires Keybase

#553
post #358

Earlier quoted context omitted.

> communication company that has its entire dev team in China citation needed Also, what are you trying to imply by this assertion?

"Zoom is based in California’s Silicon Valley, but it owns three companies in China that develop its software. The Citizen Lab said the structure allowed the company to lower its development costs, but added “this arrangement may make Zoom responsive to pressure from Chinese authorities.”" https://www.theguardian.com/uk-news/2020/apr/24/uk-governmen... The implication is that China is hostile and leverages their powe…

Isn't the US actually at least as bad if not worse? Thanks to Edward Snowden we know without speculation that the US "is hostile and leverages their power to censor/collect communication information from companies and their people without checks on this power" (ok, supposedly there is secret judges that secretly check on this power, but that doesn't really do any good does it?). The USA also "pressure companies to hand over PII on people they find to be political threats without due process" (so called "National Security Letters").

Re: Zoom Acquires Keybase

#554

For years people have been begging Keybase to allow them to pay them for the service and Chris Coyne always refused. Now they've lost their independence and they're owned by a communication company that has [edit: the majority of] its dev team in China. I use Keybase to talk to my friend in China since it's one of the few services they don't block. This is a pretty disappointing outcome.

It is funny that Zoom was one of the companies that I flagged in my head as the worst (or rather, most dangerous) up-and-coming tech company and I considered Keybase one of the most promising up-and-coming tech companies. Keybase solves a (to me) nontrivial problem: How to bring private keys into social media. Just a silly example: You don't use the same private-public key exchange in Whatsapp as you would use for yo…

> Zoom was one of the companies that I flagged in my head as the worst [...] Keybase one of the most promising

Hear hear. It really is an absurd world we live in, and I had a good chuckle about that - just before I deleted my Keybase account.

Re: Zoom Acquires Keybase

#555
post #25

> Zoom does not and will not proactively monitor meeting contents, but our trust and safety team will continue to use automated tools to look for evidence of abusive users based upon other available data. > Zoom has not and will not build a mechanism to decrypt live meetings for lawful intercept purposes. > We also do not have a means to insert our employees or others into meetings without being reflected in the part…

Consider these promises a warrant canary. They will be removed at some point.

I thought warrant canaries had to be in financial reports because those are one of the documents where companies are legally cannot lie under SEC rules?

Re: Zoom Acquires Keybase

#556
post #249
post #99

Earlier quoted context omitted.

I believe the argument is that a private key encrypted with a password is not cryptographically different from a plaintext private key. The password is more of a "keeping honest people honest" kind of thing, than true security. If it was truly secure, then you'd be using a new private key to encrypt your real private key, and then you're back to where you started. Cryptography is hard, which is why I was such a big f…

I didn't downvote. Here are my thoughts. > I believe the argument is that a private key encrypted with a password is not cryptographically different from a plaintext private key. You have it backwards. On principle an encrypted anything (key in this case) is of zero value to anyone. It does’t matter if you tweet encrypted messages every 30 seconds to millions of followers or not: they're encrypted. When you use a pas…

Hmmmm... so wouldn't you agree that a percentage of keys would be decryptable by iterating over all encrypted files of all accounts using password dumps? Seems like a good way to decrypt maybe 10%. Still sounds like a major problem, though.. not at the individual level, but at the systems level.

Re: Zoom Acquires Keybase

#557

Earlier quoted context omitted.

They have already massive infra in place. And are non-profit. Sort of 'natural' expansion. I would love to see it.

The problem with natural expansion is that it degenerates into feature creep. Is it natural to add a cryptocoin wallet later like Keybase did?

The advantage of following is that you get to cherry-pick what features actually got traction and skip over a lot of rat holes.

Re: Zoom Acquires Keybase

#558

Earlier quoted context omitted.

I didn't follow your reasoning about proprietary software depending on the broken window fallacy. I don't see how Google's proprietary search engine or Facebook's proprietary interface to our social network rely on the broken window fallacy. Would you mind elaborating?

Sure! The idea is that each proprietary project is wasting effort implementing their own clones of everyone else's software. To use your example, Google, Microsoft, Yahoo, Yandex etc etc are all developing their own search engines. Instead they could all be contributing to one search engine to push the state of search engine software forward, instead of all spinning their wheels re-doing what everyone else is doing.…

Thanks for the elaboration.

I think you would be right about the greater good being served by everyone being aligned on the same search engine ONLY IF we understood search engines so well that we knew there to be only one mathematically optimal way to build search engines.

Since we don't understand search engines that well, there is a LOT of value in the exploration over the space of search engines that these different companies represent.

The broken window fallacy argument is that those speaking of the benefits of the broken window are mistaking maintenance cost for generated value. That doesn't seem to be the case here. This is society implicitly investing in exploration over exploitation.

Re: Zoom Acquires Keybase

#559

Earlier quoted context omitted.

@Keybase users: Check if you uploaded your private key. I hope it is rare but now is the time to make that non existent.

I signed up so long ago that I'm not quite sure what you mean. I remember posting a bunch of public keys (like on my profile here). I think the keybase app generated them along with a private key but it has been like three years. I don't remember at all uploading one or where to find it if I did, can you explain the issue you have in mind a little more?

https://github.com/keybase/keybase-issues/issues/160

There is still (apparently under another command name) this ability to upload your private key.

Re: Zoom Acquires Keybase

#560
post #188

Earlier quoted context omitted.

That, and this is probably in large part a marketing/PR move. Public perception of zoom/security is "beyond horrible", thus visibly spending lots of money on an acquisition of a very well respected name in security helps them polish that image at least a little. And who knows, maybe they'll even work on actually improving security. Always the hopeless romantic/optimist, me. ¯\_(ツ)_/¯

> Public perception I'd say you overestimate that. Perhaps 0.01% of the public knows that Keybase exists and has a bad opinion of Zoom security. Expert's opinion is important, but does not automatically become general perception. (Anecdatum, I'm far from a security expert. I know that Keybase exists, even have an unused account; I use Zoom for work and don't blame them for not locking up tighter. Their blog post on t…

> Perhaps 0.01% of the public knows that Keybase exists and has a bad opinion of Zoom security. Expert's opinion is important, but does not automatically become general perception.

This is true, but perhaps a bit short-sighted. Expert opinion on Zoom is "avoid it like the plague". This does not automatically become general perception, true, but:

- Over time, expert opinions have a marked effect on adoption by non-experts in their vicinity. See the adoption of Firefox, or Google Chrome, for example.

- For a social networking platform, powerful well-connected never-adopters can pose a problem both to growth and to a budding monopoly. If CIOs and CISOs say, "Zoom over my dead body", that will tend to discourage adoption and encourage development of good alternatives.

Post reply on HN