Live data from Hacker News

Zoom Acquires Keybase

keybase.io

631–640 of 751 posts

Re: Zoom Acquires Keybase

#631

Earlier quoted context omitted.

Isn't the US actually at least as bad if not worse? Thanks to Edward Snowden we know without speculation that the US "is hostile and leverages their power to censor/collect communication information from companies and their people without checks on this power" (ok, supposedly there is secret judges that secretly check on this power, but that doesn't really do any good does it?). The USA also "pressure companies to ha…

People don't get disappeared for actively disagreeing with the government.

That's true for US citizens. But not so much otherwise.

Edit: Someone disagrees? Consider Guantanamo Bay, third-party renditions, and drone strikes. If China did drone strikes, there'd be a huge outcry.

Re: Zoom Acquires Keybase

#632

Earlier quoted context omitted.

Zoom is, or was, collecting a list of running applications on machines. Keybase requires that you run it on multiple devices for security. It would be reasonable to expect that Zoom would love to embed such data harvesting in the Keybase client.

Do you have a reference for this? Were they confirmed to be sending the info to the server? I would note that it wouldn't be uncommon for a program like zoom to have the relevant api calls in it to allow the user share a specific app with the conference call.

Yes. https://www.howtogeek.com/664624/does-zoom-really-monitor-wh...

Re: Zoom Acquires Keybase

#633
post #249

Earlier quoted context omitted.

I didn't downvote. Here are my thoughts. > I believe the argument is that a private key encrypted with a password is not cryptographically different from a plaintext private key. You have it backwards. On principle an encrypted anything (key in this case) is of zero value to anyone. It does’t matter if you tweet encrypted messages every 30 seconds to millions of followers or not: they're encrypted. When you use a pas…

If people have bad passwords, that makes brute force recovery of the private key on a Keybase server plausible, right? At least a lot more so than the whole key from scratch. I'd assume that a machine generated key has more entropy than any password that a human can memorize. If sharing a password-protected private key is perfectly safe, why bother having them? Why don't PGP users just password protect everything? Ab…

I think people are confusing things a bit here. Sure, you can protect your pgp key with a password, but I don't think that adds a whole lot of security to your uploaded private keys. When you upload a pgp key to keybase, it encrypts the key again, using your keybase device key. So its double encrypted, basically.

The keybase model revolves around devices. Device keys are private keys that are tied to a particular device (your phone, pc, etc) and never leave that device (unless it gets compromised somehow). The only way you can decrypt your data on another device is by registering it using another authenticated device. These keys don't have passwords.

Its basically like encrypting a pgp key with another pgp key, and uploading it somewhere, like people upload all manner of secrets to github or s3 or whatever.

Keybase just provides an easier flow to register new devices and to import and decrypt your secrets (like via a QR code scanned by your phone, for example). Your private keys are as secure as any private, encrypted piece of data that you might send out over the wire, so long as your devices are secure, that is.

If one or more of your devices gets owned, all bets are off, AFAIK. Even if you set a passphrase on your pgp key, all it takes is a key-logger to get it. And since your device is already compromised...

This is where hardware keys win out (yubikey, etc), that require a physical touch to unlock.

DISCLAIMER: I really only have a layman's understanding of crypto.

Re: Zoom Acquires Keybase

#634
post #187

Keybase helped me to identify a trend in the software industry: using a pretty UI to cover up the disruption of an open ecosystem with a closed, centralized replacement. Keybase seemed cool on the face of it - making encryption easier is a laudible goal, and PGP certainly could use the improvement. But, thanks to Keybase, now I ask different questions upfront. Beware the Keybase formula: 1. Integrates with an existin…

it's more about the VC funding than anything else. it is almost always the reason for the death of cool software

The reason for the death of cool software is that nobody pays for software anymore.

Re: Zoom Acquires Keybase

#635

For years people have been begging Keybase to allow them to pay them for the service and Chris Coyne always refused. Now they've lost their independence and they're owned by a communication company that has [edit: the majority of] its dev team in China. I use Keybase to talk to my friend in China since it's one of the few services they don't block. This is a pretty disappointing outcome.

It is funny that Zoom was one of the companies that I flagged in my head as the worst (or rather, most dangerous) up-and-coming tech company and I considered Keybase one of the most promising up-and-coming tech companies. Keybase solves a (to me) nontrivial problem: How to bring private keys into social media. Just a silly example: You don't use the same private-public key exchange in Whatsapp as you would use for yo…

[deleted]

Re: Zoom Acquires Keybase

#639

Earlier quoted context omitted.

This is not a trend, it’s a long standing market strategy: https://en.m.wikipedia.org/wiki/Embrace,_extend,_and_extingu...

Can't it be both a trend and a marketing strategy?

Yes, but in this case it isnt a trend

Re: Zoom Acquires Keybase

#640

Earlier quoted context omitted.

Isn't the US actually at least as bad if not worse? Thanks to Edward Snowden we know without speculation that the US "is hostile and leverages their power to censor/collect communication information from companies and their people without checks on this power" (ok, supposedly there is secret judges that secretly check on this power, but that doesn't really do any good does it?). The USA also "pressure companies to ha…

People don't get disappeared for actively disagreeing with the government.

The just get disappeared into Belmarsh and extradited to who knows where for telling the truth about the US military murdering civilians including journalists from a helicopter gunship.
Post reply on HN