Live data from Hacker News

Zoom Acquires Keybase

keybase.io

691–700 of 751 posts

Re: Zoom Acquires Keybase

#691
post #681
post #667

Earlier quoted context omitted.

Thanks for this! Besides upvotes, HN should have a hall of fame for comments this good. It reminds me of 1 Corinthians 15:33 quoting the Greek poet Menander: Do not be misled: “Bad company corrupts good character.”

How does good character develop in the first place then..?

I always try to work with people smarter than me, more ethical than me, and more productive. When we associate with people we want to fit in with, we adapt to be more like them. We can adapt in bad ways, but we can also adapt in good ways.

Essentially, on some level we never stop the role-model based adaptation we did as children, when we modeled our behavior on what our parent(s) did.

Re: Zoom Acquires Keybase

#692

Earlier quoted context omitted.

The power depends on the board structure and the ownership. But even if a founder owns 51% of the company, and so in theory can do anything, they still have an obligation to do right by the minority shareholders. This is generally known as fiduciary duty, and is a complex area of law. Here's a short summary: https://www.nolo.com/legal-encyclopedia/fiduciary-responsibi... In a case like this, a founder can't just give…

> they still have an obligation to do right by the minority shareholders Fiduciary duty is extremely rare to be the subject of a suit against a, let's say, CEO. It's a complex area of law because it isn't actually a law, nor specified anywhere, and not a requirement for corporate existence. So, it's a set of court decisions that future cases are built upon, but in general a house of cards in that it could be invalida…

I agree with you that maximizing profit as the sole metric is a myth, which is perhaps why I didn't mention it.

However, in practice if one has taken $10m from investors looking for a big payday, one can't just do any old thing. Doing something sufficiently contrary to the interests of minority shareholders could certainly result in a lawsuit. Could the shareholders win? Who knows! As you say, it's a murky area. But winning in that case isn't what matters. The lawsuit will tie the company up for years, forcing significant spending. And if they include the CEO in the lawsuit, it will mean personal expense and an enormous headache. So in practice, the Keybase execs couldn't just say, "Fuck it, we won't sell to Zoom, everything is open source now." Not without talking it through with the investors, anyhow.

Re: Zoom Acquires Keybase

#693

Earlier quoted context omitted.

Losing their independence was from the beginning the most likely outcome of building something that's hard to monetize like Keybase on the VC funding model. FWIW, I doubt Keybase offering a paid plan would have raised revenue that's significant compared to their burn, so Chris was probably right to not spend resources figuring out a paid offering. For raising their next round, having $5K in revenue from a paid plan f…

How much power do the VCs typically have? Don't founders often have the ability to overrule and make their own decisions? Chris is already financially independent from the OKCupid sale, he could have open sourced the server code and/or reduced the overall burn to pivot to paid accounts. Though the weird Stellar wallet addition implied some vision/product issues anyway. Of course it's easy and probably unfair for me t…

You can downvote here?

Re: Zoom Acquires Keybase

#694
I love(d) the idea of Keybase but I always had in the back of my mind that it was too good to be true. I'm guessing this will be the end as they announce in a few months that Keybase is being retired as it's "best security features" have been integrated into Zoom. Seems to happen to just about every good product that isn't fervently open-source.

Re: Zoom Acquires Keybase

#695
post #266
post #142

Earlier quoted context omitted.

Zoom's decisions did not feel like mistakes so much as an expression of their values. The company repeatedly prioritised ease of use while doing the absolute minimum on the security front. Are there any grounds to believe that that calculus has changed?

This is a good point. But I do think that company values do change. Zoom is getting the shining light of attention globally. Even human beings, in these situations, start to act more conscientiously, and then believe their own morality after the fact! I believe the keybase acquisition demonstrates this a bit - because they will get zero public goodwill from this - nobody on Main St. knows are cares what Keybase is, t…

The CEO of Zoom is a naturalized U.S. citizen. He is ethnically Chinese but by all means he is no longer legally a Chinese citizen.

Source: https://en.wikipedia.org/wiki/Eric_Yuan

Re: Zoom Acquires Keybase

#696

Earlier quoted context omitted.

It seems that we live in an era where if you made bad decisions in the past, you can never be trusted to make good decisions ever again. Even if you own your bad decisions and show lots of improvement. Nope. Once a pariah, always a pariah.

Zoom is only a pariah on Hacker News.

About half of my employer's clients (in manufacturing) have banned use of zoom and block it at the firewall.

Re: Zoom Acquires Keybase

#697

Earlier quoted context omitted.

They do keep saying "multiplatform", but I guess that's Windows/macOS/iOS/Android, not Linux. They're not the only ones though, this is what most companies call "on any device".

Zoom works without a hitch on Ubuntu here. Even plays nicely with the tiling WM with multiple workspaces (somehow, a thumbnail window follows you through as you flip through workspaces).

Not even close to working properly on swaywm. Maybe you tiling WM does something special for Zoom?

Screen sharing only works on Xorg, and screen scaling doesn't work (so it's super blurry on hidpi).

I've never seen that thumbnail window either -- though I don complain on that item, I prefer not having something like that.

Re: Zoom Acquires Keybase

#699

Earlier quoted context omitted.

If people have bad passwords, that makes brute force recovery of the private key on a Keybase server plausible, right? At least a lot more so than the whole key from scratch. I'd assume that a machine generated key has more entropy than any password that a human can memorize. If sharing a password-protected private key is perfectly safe, why bother having them? Why don't PGP users just password protect everything? Ab…

I think people are confusing things a bit here. Sure, you can protect your pgp key with a password, but I don't think that adds a whole lot of security to your uploaded private keys. When you upload a pgp key to keybase, it encrypts the key again, using your keybase device key. So its double encrypted, basically. The keybase model revolves around devices. Device keys are private keys that are tied to a particular dev…

Thank you. If that's true I wish they would have just said so when people started complaining about it on Github. Everybody seems to have a different take on this.

Assuming what you're saying is correct, it seems much more sensible. It almost makes the PGP key seem superfluous, though I suppose it help with legacy this way.

It still seems not ideal, in that having one device compromised would give away your main private key and thus your whole identity. It would be nice to have it be some sort of subkey situation. I'd have to think about how that would work.

Re: Zoom Acquires Keybase

#700

Earlier quoted context omitted.

I agree. I'd bet all the cash in my wallet that this was Zoom doing a talent acquisition, to bring a team of crypto experts on board.

You are probably right but I wouldn't discount the keybase server/client IP and user base completely. If Zoom could use keybase for identity verification and adding participants to a call via social graph connections of everyone on the call that could radically improve the UX of onboarding and securing a meeting to only approved participants.

It's possible, though I think it's optimistic. Nobody really has a problem with Zoom's UX as it is now. The only people complaining about Zoom are us techies who know about the security issues. So my guess is they're just gonna quietly work on the security stuff in the background with this new team, and leave the UX largely as-is.
Post reply on HN