Zoom Acquires Keybase
601–610 of 751 posts
Re: Zoom Acquires Keybase
#602Earlier quoted context omitted.
It is funny that Zoom was one of the companies that I flagged in my head as the worst (or rather, most dangerous) up-and-coming tech company and I considered Keybase one of the most promising up-and-coming tech companies. Keybase solves a (to me) nontrivial problem: How to bring private keys into social media. Just a silly example: You don't use the same private-public key exchange in Whatsapp as you would use for yo…
> Zoom was one of the companies that I flagged in my head as the worst [...] Keybase one of the most promising Hear hear. It really is an absurd world we live in, and I had a good chuckle about that - just before I deleted my Keybase account.
Re: Zoom Acquires Keybase
#603Earlier quoted context omitted.
> Zoom was one of the companies that I flagged in my head as the worst [...] Keybase one of the most promising Hear hear. It really is an absurd world we live in, and I had a good chuckle about that - just before I deleted my Keybase account.
Can you elaborate on what concerns you so much that it warrants deleting your account right upon hearing the news?
Re: Zoom Acquires Keybase
#604For years people have been begging Keybase to allow them to pay them for the service and Chris Coyne always refused. Now they've lost their independence and they're owned by a communication company that has [edit: the majority of] its dev team in China. I use Keybase to talk to my friend in China since it's one of the few services they don't block. This is a pretty disappointing outcome.
Re: Zoom Acquires Keybase
#605Earlier quoted context omitted.
If Keybase acquired Zoom (haha), then, sure. This is a PR move for a public company. They'll probably gut Keybase, move their Chinese server generated AES128 keys to AES256 keys generated by you and uploaded to their Chinese server, then call it a day. I can't think of a single instance where acquisition of a smaller company like this resulted in an improved version of the original product. How many of us are running…
Apple aquired NeXT and completely reinvented their organisation based on that.
Re: Zoom Acquires Keybase
#606Earlier quoted context omitted.
I didn't downvote. Here are my thoughts. > I believe the argument is that a private key encrypted with a password is not cryptographically different from a plaintext private key. You have it backwards. On principle an encrypted anything (key in this case) is of zero value to anyone. It does’t matter if you tweet encrypted messages every 30 seconds to millions of followers or not: they're encrypted. When you use a pas…
If people have bad passwords, that makes brute force recovery of the private key on a Keybase server plausible, right? At least a lot more so than the whole key from scratch. I'd assume that a machine generated key has more entropy than any password that a human can memorize. If sharing a password-protected private key is perfectly safe, why bother having them? Why don't PGP users just password protect everything? Ab…
What’s “sharing” here? You “share” an encrypted private key with Keybase so you yourself can recover it back from anywhere using the password that you know. PGP, meanwhile, is used for communication with people who are not you.
> If people have bad passwords, that makes brute force recovery of the private key on a Keybase server plausible, right? At least a lot more so than the whole key from scratch.
Yes. If you want to upload an encrypted copy of your key to someone you wouldn’t trust with the key, you should use a strong password.
> I'd assume that a machine generated key has more entropy than any password that a human can memorize.
That’s not a correct assumption, but your password doesn’t have to be more complex than the key to be safe against brute force anyway, especially when work is added with scrypt (which is what Keybase uses).
Re: Zoom Acquires Keybase
#607Re: Zoom Acquires Keybase
#608Earlier quoted context omitted.
Yeah holy crap. I've been a big fan of Keybase since they launched, but this is a deathknell. I guess I'm not too surprised, Keybase didn't seem to have a business model, but still, disappointing that they're going to go into death this way. Attention people starting businesses: VC funding is fun and all, but please, have a business model. Your users and employees depend on it.
While honourable advice, the bottom line is Keybase sold without having a business model. So perhaps better advice is, start a business even if you don’t have a plan and someone may buy it anyway.
A better world for your personal pocketbook maybe, but certainly a worse world for the rest of us. I wouldn't characterize that as "better" in any general sense.
Re: Zoom Acquires Keybase
#609Very unfortunate. Besides its main purpose, Keybase has been my chat app of choice for quite a while, after I decided I could no longer put up with Signal's general crappiness. Keybase has been one of the very few performant and usable "new-style" applications that I've used -and the only one of its kind. Sadly I am forced to suffer electron-based vomit every day -between Skype, Teams, Whatsapp, Hangouts, Facebook me…
The Keybase app is also written in Electron.
I didn't say that all electron apps have to suffer, at the same time it seems to me that there is a strong correlation.
Re: Zoom Acquires Keybase
#610For years people have been begging Keybase to allow them to pay them for the service and Chris Coyne always refused. Now they've lost their independence and they're owned by a communication company that has [edit: the majority of] its dev team in China. I use Keybase to talk to my friend in China since it's one of the few services they don't block. This is a pretty disappointing outcome.
So what now? Maybe someone could clone the GitHub repos. And/or are GnuPG keyservers safe enough again?
For chat, Session looks most interesting. It's got the Signal messaging bits. Plus anonymity via the Loki onion network. And it's available for all platforms.
However, it's very new, and often buggy. And the Loki Foundation is Australian. So at some point they'll likely get pressured to backdoor stuff. And they probably won't be able to disclose that, unless someone leaks.
There's also Tox, where each user runs a Tor onion client. That's secure enough in Whonix. But the Whonix user base is miniscule, and I wouldn't trust an implementation in Windows. But then, maybe Session in Windows is too iffy as well.
Anyway, I'll be deleting my Keybase account, as soon as I've negotiated alternate comms with my contacts.