Live data from Hacker News

Zoom Acquires Keybase

keybase.io

581–590 of 751 posts

Re: Zoom Acquires Keybase

#581
post #249
post #99

Earlier quoted context omitted.

I believe the argument is that a private key encrypted with a password is not cryptographically different from a plaintext private key. The password is more of a "keeping honest people honest" kind of thing, than true security. If it was truly secure, then you'd be using a new private key to encrypt your real private key, and then you're back to where you started. Cryptography is hard, which is why I was such a big f…

I didn't downvote. Here are my thoughts. > I believe the argument is that a private key encrypted with a password is not cryptographically different from a plaintext private key. You have it backwards. On principle an encrypted anything (key in this case) is of zero value to anyone. It does’t matter if you tweet encrypted messages every 30 seconds to millions of followers or not: they're encrypted. When you use a pas…

If people have bad passwords, that makes brute force recovery of the private key on a Keybase server plausible, right? At least a lot more so than the whole key from scratch. I'd assume that a machine generated key has more entropy than any password that a human can memorize.

If sharing a password-protected private key is perfectly safe, why bother having them? Why don't PGP users just password protect everything?

Above all else though, is there an authoritative source that can answer these questions? As a run-of-the-mill programmer, I don't really understand how crypto works well enough to trust my own common sense here. It's been drilled into my head that there are certain rules to follow set out by people who do know what they're doing. And when people say "it's all good, it's password protected", and I'm not sure what their credentials are, I get a little nervous. I did notice that Werner Koch uses Keybase, but if they could simply point to an "okay" from him or Zimmerman explaining the situation, it would be settled. To me anyway, it's not simply an abundance of caution ("paranoia"), it's that something seems fundamentally wrong with the approach and I just don't know the actual cost.

Re: Zoom Acquires Keybase

#582

Keybase helped me to identify a trend in the software industry: using a pretty UI to cover up the disruption of an open ecosystem with a closed, centralized replacement. Keybase seemed cool on the face of it - making encryption easier is a laudible goal, and PGP certainly could use the improvement. But, thanks to Keybase, now I ask different questions upfront. Beware the Keybase formula: 1. Integrates with an existin…

This is not a trend, it’s a long standing market strategy: https://en.m.wikipedia.org/wiki/Embrace,_extend,_and_extingu...

Can't it be both a trend and a marketing strategy?

Re: Zoom Acquires Keybase

#583
post #358

For years people have been begging Keybase to allow them to pay them for the service and Chris Coyne always refused. Now they've lost their independence and they're owned by a communication company that has [edit: the majority of] its dev team in China. I use Keybase to talk to my friend in China since it's one of the few services they don't block. This is a pretty disappointing outcome.

> communication company that has its entire dev team in China citation needed Also, what are you trying to imply by this assertion?

China is not to be trusted, Zoom and now Keybase is not to be trusted

Re: Zoom Acquires Keybase

#585

Earlier quoted context omitted.

Sure! The idea is that each proprietary project is wasting effort implementing their own clones of everyone else's software. To use your example, Google, Microsoft, Yahoo, Yandex etc etc are all developing their own search engines. Instead they could all be contributing to one search engine to push the state of search engine software forward, instead of all spinning their wheels re-doing what everyone else is doing.…

Thanks for the elaboration. I think you would be right about the greater good being served by everyone being aligned on the same search engine ONLY IF we understood search engines so well that we knew there to be only one mathematically optimal way to build search engines. Since we don't understand search engines that well, there is a LOT of value in the exploration over the space of search engines that these differe…

Well, in reality there wouldn't be one optimal product, there would be many, for the reason that you said -and for human reasons.

However they would still be able to borrow good bits from each other and gain insight on how things could be done differently, so arguably the end result would be a win. From a technical standpoint that is -I think where it gets messy is when we try to factor in the business implications.

Re: Zoom Acquires Keybase

#588
post #497

Earlier quoted context omitted.

(We've since changed the URL from https://blog.zoom.us/wordpress/2020/05/07/zoom-acquires-keyb... to that one)

Hi dang, are there any plans to introduce a marker of some sort so that people know whether the current URL is the same as the one it was submitted with? I find that often I have no idea what the comments are talking about

It's not clear to me whether that would add more signal to the comments or more noise.

If you have specific links to cases where this has been a problem, you'd be welcome to send them to hn@ycombinator.com so we can take a look. Or keep that in mind for the next time this comes up.

Re: Zoom Acquires Keybase

#589
post #236

Earlier quoted context omitted.

How can they be so obvlivious though? Their own blog post doesn't even mention the tarnished reputation Zoom has acquired lately. A lot of people will stop developing integrations for Keybase because of this. It's sad.

That's probably why Zoom is buying them, to double down on security and repair their reputation. They genuinely seem to be putting all their focus on improving security. Seems like a smart buy to me.

There hasn't been enough time since the noise about Zoom's security, for a company to inspect the goods, audit the books, negotiate, draft paperwork, share cocktails and all other stuff that come before announcing an acquisition. Especially in the middle of a disruptive situation. The process must had started many months ago.

Re: Zoom Acquires Keybase

#590
post #40

Given the security concerns around Zoom, and the apparent lack of QC that might have prevented those concerns, this news is appalling. I love Keybase, it's used by many people, but I suspect it will now die a quick death. More accurately I suspect it will slide into a coma - not quite dead, but not in wide use anymore either.

why not look at the problem the other way around? I don't have much respect for zoom's security practices, while I do have much respect for the keybase team. Perhaps this is Zoom's way of admitting that there is no way they can just solve the problem internally by keeping doing what they're doing and they need to get some fresh blood and build upon good practices designed outside their current culture.

> why not look at the problem the other way around?

Because no one ever buys or hires a conscience. If you thought a conscience was worth having one, that implies you would already have one and thus wouldn't need to outsource it in the first place.

Ethics always rolls downhill. If Al Capone goes out and hires Mr. Rogers, the power imbalance between them means Mr. Rogers is going to get dirtier than Capone will get clean.

Post reply on HN