Live data from Hacker News

Zoom Acquires Keybase

keybase.io

611–620 of 751 posts

Re: Zoom Acquires Keybase

#611

Earlier quoted context omitted.

"Zoom is based in California’s Silicon Valley, but it owns three companies in China that develop its software. The Citizen Lab said the structure allowed the company to lower its development costs, but added “this arrangement may make Zoom responsive to pressure from Chinese authorities.”" https://www.theguardian.com/uk-news/2020/apr/24/uk-governmen... The implication is that China is hostile and leverages their powe…

Isn't the US actually at least as bad if not worse? Thanks to Edward Snowden we know without speculation that the US "is hostile and leverages their power to censor/collect communication information from companies and their people without checks on this power" (ok, supposedly there is secret judges that secretly check on this power, but that doesn't really do any good does it?). The USA also "pressure companies to ha…

I think that while both countries have the technology to facilitate censorship and oppression, the US is much more careful about how they do it. China isn't afraid to use their control over information to assist the oppression of Uighurs in 're-education' camps for example.

Re: Zoom Acquires Keybase

#612
post #602

Earlier quoted context omitted.

Can you elaborate on what concerns you so much that it warrants deleting your account right upon hearing the news?

Zoom is, or was, collecting a list of running applications on machines. Keybase requires that you run it on multiple devices for security. It would be reasonable to expect that Zoom would love to embed such data harvesting in the Keybase client.

Do you have a reference for this? Were they confirmed to be sending the info to the server? I would note that it wouldn't be uncommon for a program like zoom to have the relevant api calls in it to allow the user share a specific app with the conference call.

Re: Zoom Acquires Keybase

#613
post #142

Earlier quoted context omitted.

It seems that we live in an era where if you made bad decisions in the past, you can never be trusted to make good decisions ever again. Even if you own your bad decisions and show lots of improvement. Nope. Once a pariah, always a pariah.

Zoom's decisions did not feel like mistakes so much as an expression of their values. The company repeatedly prioritised ease of use while doing the absolute minimum on the security front. Are there any grounds to believe that that calculus has changed?

> did not feel like mistakes so much as an expression of their values

That's an intepretation you're choosing to make.

Re: Zoom Acquires Keybase

#615

So, unless I've missed it in the comments here, what are the alternatives? Where are people putting their keys?

Mailvelope, KWallet, Signal, Jitsi, not sure what does encrypted IRC-like chats as well..

Re: Zoom Acquires Keybase

#616
post #376
post #311

Earlier quoted context omitted.

> It seems that we live in an era where if you made bad decisions in the past, you can never be trusted to make good decisions ever again. Even if you own your bad decisions and show lots of improvement. I've seen this turn out for the best literally one time, and that was Microsoft. All the other times the bad company just continues its horrible slide into madness. It doesn't die either, just silently keeps churning…

Microsoft isn't turning out for the best, though. They are just very good at putting a dusting of Open Source sugar on things.

However you call it, they’re producing value for me instead of (or in addition to) their shareholders.

Re: Zoom Acquires Keybase

#617
post #40

Earlier quoted context omitted.

why not look at the problem the other way around? I don't have much respect for zoom's security practices, while I do have much respect for the keybase team. Perhaps this is Zoom's way of admitting that there is no way they can just solve the problem internally by keeping doing what they're doing and they need to get some fresh blood and build upon good practices designed outside their current culture.

> why not look at the problem the other way around? Because no one ever buys or hires a conscience. If you thought a conscience was worth having one, that implies you would already have one and thus wouldn't need to outsource it in the first place. Ethics always rolls downhill. If Al Capone goes out and hires Mr. Rogers, the power imbalance between them means Mr. Rogers is going to get dirtier than Capone will get cl…

Well put! But it depends on how you approach the issue.

If having a conscience means prioritizing security above all else, then Keybase is doomed.

But security isn’t the only thing that matters. Zoom seems to have focused on making a very user friendly product. Keybase focused on making security more user friendly. In many ways, the user focus of both apps is their Prime selling point.

Perhaps they weren’t buying a conscience, they were fixing a blind spot.

Re: Zoom Acquires Keybase

#618

Earlier quoted context omitted.

They don't have access to your unencrypted private key, it's just a backup of your private key which is encrypted by (hopefully) a very strong password. This feature saved my skin on one occasion.

Well, you still have to trust them not to ship a website update where the client side scripts would leak your decrypted private key :) To be fair, you also have to trust native apps and browser extensions the same way. But with websites, the risk of a sudden and targeted (not noticed by the general public) update is much greater!

Which is why they push you towards not using the website, and also explain how they (through some steps) put their application version's hashes into the bitcoin blockchain.

And the client is open source, which iirc includes being built by distribution's maintainers/build servers instead of Keybase.io.

Re: Zoom Acquires Keybase

#619
post #613
post #142

Earlier quoted context omitted.

Zoom's decisions did not feel like mistakes so much as an expression of their values. The company repeatedly prioritised ease of use while doing the absolute minimum on the security front. Are there any grounds to believe that that calculus has changed?

> did not feel like mistakes so much as an expression of their values That's an intepretation you're choosing to make.

Calling it an interpretation is nothing short of revisionism. Nobody considers the hidden web server to have been an oversight. It required forethought and effort. It's not as if they didn't know what they were doing.

Re: Zoom Acquires Keybase

#620

Earlier quoted context omitted.

Isn't the US actually at least as bad if not worse? Thanks to Edward Snowden we know without speculation that the US "is hostile and leverages their power to censor/collect communication information from companies and their people without checks on this power" (ok, supposedly there is secret judges that secretly check on this power, but that doesn't really do any good does it?). The USA also "pressure companies to ha…

People don't get disappeared for actively disagreeing with the government.

Usually, but they do get into unfortunate accidents from time to time.
Post reply on HN