Live data from Hacker News

Zoom Acquires Keybase

keybase.io

621–630 of 751 posts

Re: Zoom Acquires Keybase

#621
post #498
post #410

Earlier quoted context omitted.

You don't understand what Keybase does. The whole point is that you don't just use it to upload a key. You link various verified identifies of yours across the web to your Keybase account so people know the PGP key there is the one of the verified person. It's a way to tie all your verified identifies together. If someone would manage to compromise a bunch of identities of someone on the internet, and then create a K…

In reality: I used keybase for a while. When I allowed a domain to expire and the DNS record disappeared, keybase threw up warning both in cli and their website that my identity verification couldn't be completed. My only problems I ever had with keybase was related to the cloud storage they offer. My real wish is that keybase supported ssh keys and would provide them as an agent.

You can revoke the DNS signature. I'll assume your keybase account name is the same as on HN.

I do agree on the ssh key feature being nice, and, here's a link: https://keybase.io/blog/keybase-ssh-ca You could also just use the keybase file system to keep ssh keys around.

Re: Zoom Acquires Keybase

#622

Earlier quoted context omitted.

Is it called "soften the language" to fix a 100% factual error? Honestly I feel that if you're arguing in one direction or another and haven't checked the facts, maybe it's better not to argue about it?

The vast majority of the Zoom software development team is based out of companies in China. They do have support people in the US and a handful of non-support engineering which is why I said thanks and immediately updated the comment to say "majority" instead of "entire" since it's more correct. That technicality is less relevant to the main point of the argument.

They do have a large R&D presence in China.

As of January 2020, they had 2,532 full-time employees. Of those, 1,396 were in the US and 1,136 were in international locations. Within the 1,136 is "more than 700" employees in R&D in China.[1]

A LinkedIn search for "engineer" working for "Zoom Video Communications" in location "United States" shows up 558 results.[2]

Their entire management team is in the US, and of their 17 data centres, only 1 is in China.[3][4]

[1] https://www.sec.gov/ix?doc=/Archives/edgar/data/1585521/0001... [2] https://www.linkedin.com/search/results/people/?facetCurrent... [3] https://zoom.us/team [4] https://blog.zoom.us/wordpress/2020/05/04/navigating-a-new-c...

Re: Zoom Acquires Keybase

#623
Somewhat predictable move. Buying a security company (on the cheap with Keybase) is an easy way to advertise “See, security now!”. It’s a fast-track solution to slap some duct tape on the problem and at least say they fixed it.

Re: Zoom Acquires Keybase

#624

Earlier quoted context omitted.

"Zoom is based in California’s Silicon Valley, but it owns three companies in China that develop its software. The Citizen Lab said the structure allowed the company to lower its development costs, but added “this arrangement may make Zoom responsive to pressure from Chinese authorities.”" https://www.theguardian.com/uk-news/2020/apr/24/uk-governmen... The implication is that China is hostile and leverages their powe…

Isn't the US actually at least as bad if not worse? Thanks to Edward Snowden we know without speculation that the US "is hostile and leverages their power to censor/collect communication information from companies and their people without checks on this power" (ok, supposedly there is secret judges that secretly check on this power, but that doesn't really do any good does it?). The USA also "pressure companies to ha…

Criticisms were/are made against NSA surveillances and in the case where government tried to silence such criticism (Snowden), opinions that support Snowden's actions were made and published, even made into books and movies, without repercussion. Bloggers that support Edward Snowden did not disappear. Movie directors and screenwriters are not made pariah by their industry or sent to Guantanamo.

This sort of whataboutism does not surprise me but it's getting tiring when made repeatedly in disguise of intelligent discourse. It's dishonest because the difference is blatant.

Re: Zoom Acquires Keybase

#625
post #40

Earlier quoted context omitted.

why not look at the problem the other way around? I don't have much respect for zoom's security practices, while I do have much respect for the keybase team. Perhaps this is Zoom's way of admitting that there is no way they can just solve the problem internally by keeping doing what they're doing and they need to get some fresh blood and build upon good practices designed outside their current culture.

> why not look at the problem the other way around? Because no one ever buys or hires a conscience. If you thought a conscience was worth having one, that implies you would already have one and thus wouldn't need to outsource it in the first place. Ethics always rolls downhill. If Al Capone goes out and hires Mr. Rogers, the power imbalance between them means Mr. Rogers is going to get dirtier than Capone will get cl…

Why not look at their recent actions instead?

On April 1 the CEO basically said they messed up and would pause all feature development and focus exclusively on security & privacy for 90 days.[1] They've also done weekly video AMAs that are summarised on their blog under the 90-Day Security Plan posts.[2]

They've made a lot of progress.

The Keybase acquisition is absolutely about helping to build a security team that can help them implement end-to-end encryption across 1000 person meetings. You can see that from this Twitter post[3] from Alex Stamos and this interview[4] with him.

[1] https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... [2] https://blog.zoom.us/wordpress/category/announcements/ [3] https://twitter.com/alexstamos/status/1258405729720918016 [4] https://cheddar.com/media/zoom-acquires-keybase-beefs-up-sec...

Re: Zoom Acquires Keybase

#626
post #142

Earlier quoted context omitted.

It seems that we live in an era where if you made bad decisions in the past, you can never be trusted to make good decisions ever again. Even if you own your bad decisions and show lots of improvement. Nope. Once a pariah, always a pariah.

Zoom's decisions did not feel like mistakes so much as an expression of their values. The company repeatedly prioritised ease of use while doing the absolute minimum on the security front. Are there any grounds to believe that that calculus has changed?

You're absolutely right that past decisions focused on ease-of-use over security.

For evidence that they've changed their focus you can see their April 1 blog post[1] and the weekly video AMAs they do that are summarised in their "90-Day Security Plan Progress Report" blog posts.[2]

They're making a lot of progress.

The Keybase acquisition is about building out a strong security team that will help them implement end-to-end encryption in 1,000 person meetings, which currently isn't possible anywhere.[3]

[1] https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... [2] https://blog.zoom.us/wordpress/category/announcements/ [3] https://twitter.com/alexstamos/status/1258405729720918016

Re: Zoom Acquires Keybase

#627

Somewhat predictable move. Buying a security company (on the cheap with Keybase) is an easy way to advertise “See, security now!”. It’s a fast-track solution to slap some duct tape on the problem and at least say they fixed it.

They bought Keybase to bring on a strong security team as they try to build end-to-end encryption into 1,000 person meetings which is currently not possible with any solution.[1]

They'll either deliver that or they won't.

[1] https://twitter.com/alexstamos/status/1258405729720918016

Re: Zoom Acquires Keybase

#628

Earlier quoted context omitted.

Sure, but it's not "on its own", it's in the context of the investment in security mentioned by the parent comment.

At this point, I'm confused, and I'm not sure what point you or the other commenter are looking for me to concede. Zoom is paying some security consultants, pushed out some product updates, and bought Keybase, so it's a story book ending?

I am not looking for you to concede anything. You said nothing has been done to show you that the calculus of their priorities has changed and I listed some things that could possibly show that. It’s up to you if you believe that is significant enough to convince you.

Frankly, I don’t care if it does or not. I was just providing some visible signs of investment.

Re: Zoom Acquires Keybase

#629

Earlier quoted context omitted.

DAO: https://en.wikipedia.org/wiki/Decentralized_autonomous_organ...

So if I'm reading this right... the participants of the DAO can band together and sell their company to a company as well? It looks like a DAO just requires some kind of cryptocurrency to participate, and then the participants get control over the operations of the DAO. So ownership is transferable at any time by these parties.

It would have to be built into the DAO smart contract. You could make a smart contract where it can't be sold.

Re: Zoom Acquires Keybase

#630

Earlier quoted context omitted.

It is funny that Zoom was one of the companies that I flagged in my head as the worst (or rather, most dangerous) up-and-coming tech company and I considered Keybase one of the most promising up-and-coming tech companies. Keybase solves a (to me) nontrivial problem: How to bring private keys into social media. Just a silly example: You don't use the same private-public key exchange in Whatsapp as you would use for yo…

Yes, this was exactly how I mentally categorized these two companies as well. My first reaction was: it can't be that keybase can it? Huh, well maybe I'd sell my principles for that much money too, oh well. Maybe some keybase employee will end up being a whistleblower sometime soon though.

Well, they are pitching this as bringing secure stuff to the masses. So it's arguably not all that inconsistent with what Chris etc have been saying about Keybase.
Post reply on HN