Live data from Hacker News

Ask HN: Keybase Alternatives?

news.ycombinator.com

201–210 of 237 posts

Re: Ask HN: Keybase Alternatives?

#202
post #123

Earlier quoted context omitted.

Just a quick note on WKD since I've been bitten by this a few days ago: as soon as you set it up, some people will start using your keys automatically, without even knowing it (eg. it seems that ProtonMail automatically uses keys found on a WKD to encrypt outgoing mails). While in itself it's not a bad idea, you'd better prepare for this to avoid looking stupid like me, when you receive a casual encrypted mail and yo…

> ...when you receive a casual encrypted mail and you're not able to read it (my private keys are air-gapped... Could you elaborate on why you put your public key in well-known and also how (and for what purposes) you use your air-gapped private key? As an average user, I’ve always been worried about private keys being stolen or lost.

I'm trying to get my public key available to others by more reliable sources than the traditional PKS, mostly because I'm signing git commits and Linux packages. I've an encryption key as well that I use to encrypt server backups, but I'm not expecting it to be used much for emails (actually, every single email I've received with sensible information was /not/ encrypted — people just don't understand / care).

Not all my private keys are air-gapped, but the encryption key is, since I don't need to decrypt my backups, and don't expect to receive encrypted email very often, so why take the risk? I have an old laptop which is not connected to any network and that I only use for this now: I plug the USB key with the private key, decrypt / sign whatever I need to and that's all. It takes me a lot of time, but I don't do that more than a few times every year.

Re: Ask HN: Keybase Alternatives?

#203
post #80

Earlier quoted context omitted.

> China is an authoritarian one-party state. There might be a difference, but it's pretty slim. China is a culture with a very long history, like all cultures, and a diasporic population, not to mention all of the Chinese people under the rule of the Republic of China on Taiwan. Confusing the PRC with the entirety of Chinese people, Chinese culture, and China as a whole is rather similar to refusing to distinguish be…

Nobody is confusing Chinese people with the PRC. Stop muddying the waters of an important and policy impacting conversation.

Someone in this very thread is:

https://news.ycombinator.com/item?id=23111557

Re: Ask HN: Keybase Alternatives?

#204
post #166

Earlier quoted context omitted.

> Now you're just splitting hairs. No, I am not. I am hitting on something which makes some people angry. There's a difference. As long as the Republic of China is independent, this isn't hair-splitting. > The same concerns could be had for software developed in the U.S. Of course not. The US isn't an authoritarian regime.

Try to effect some justice, and you'll quickly learn how authoritarian the US is.

I have, and you're wrong.

Re: Ask HN: Keybase Alternatives?

#205
post #8

I am also curious here. I have used and advocated strongly for Keybase with a couple of local government clients to send sensitive files back and forth (not sensitive in the sense of national security, but more to preserve privacy and store encrypted at rest). But I want to get ahead of the concern that Keybase is now owned by a Chinese company, which instantly compromises it. PGP is dead on arrival, since it's an ov…

Zoom is not a Chinese company. The founder merely was born in China. He is US citizen. I am very put off by this anti-China rhetoric. Everything that even has a remote connection to China is now under suspicion. This is madness.

C'mon: Hong Kong, persecution of Uighurs and Falun Gong and political prisoners and artists and journalists and anyone who talks about Taiwan or the Tienanmen Square Massacre, IP theft, cyber attacks, political aggression in the South China Sea ("Nine-Dash Line"), not to mention trying to expend their censorship apparatus internationally!

Re: Ask HN: Keybase Alternatives?

#206

Earlier quoted context omitted.

Cheers, glad you're open to new perspectives. A few additions: The man who got burned didn't die. He got hospitalized for a few months. He is now recovered, but with scars and trauma. Here is an interview with his wife back when he was still in coma: https://www.scmp.com/news/china/society/article/3038421/wife... FYI, SCMP is based in HK, though they are partly owned by a mainland company. Still, I find that SCMP as…

> The threats are not theoretical, as I've found out recently. A big threat comes from... The US. The US regularly stages coups against governmentd they don't like. Even democratic governments. Democratic Iran in the 60s. And just now, Venezuela. Part of the reason why the CCP top leadership is so secretive, and why they are msking society more controlling, to to protect against US lead coups. Yeah if you wonder why…

Stop trying to justify genocide.

Re: Ask HN: Keybase Alternatives?

#207

Earlier quoted context omitted.

am I right that it's Google apps FOSS alternatives?

Yes :) I launched it last June but it was a webApp. Time have passed and the project has switched to native apps to offer what Google (and the web) can't offer: offline first and end-to-end encryption. So it offers the same services as Google, but with better (in my opinion) features.

can I get beta invite?

Re: Ask HN: Keybase Alternatives?

#208
post #94

Earlier quoted context omitted.

Just a quick note on WKD since I've been bitten by this a few days ago: as soon as you set it up, some people will start using your keys automatically, without even knowing it (eg. it seems that ProtonMail automatically uses keys found on a WKD to encrypt outgoing mails). While in itself it's not a bad idea, you'd better prepare for this to avoid looking stupid like me, when you receive a casual encrypted mail and yo…

Using WKD is also a good way to solicit useless “security”-related emails from people running questionable automated scanners.

I think you confused this with security.txt standard. WKD is not enumerable (unless explicitly configured like that) so the issue doesn't exist.

Re: Ask HN: Keybase Alternatives?

#209
I'm a light user of Keybase and used it primarily for validation & signing. The social identity verification was quite nice. It seems that's what most of the users here were using it for.

My suspicion is while we're not likely to see much new development from Keybase, the existing capabilities aren't likely to go away for some time.

The premise of validation/signing isn't a technically complex approach and I'm sure someone can create and FOSS it. The question however is - what features would you want integrated and what things did you find annoying?

Re: Ask HN: Keybase Alternatives?

#210

Earlier quoted context omitted.

Nobody implied this. Clearly stated was the concern of the majority of development being in the PRC impacting US government use of Keybase.

That was after the edits/updates.

Edits and updates I made within minutes. The replies to my comment ultimately forced me to be more thoughtful in my words, resulting in me being able to better lay out my thoughts.

I specifically left my original comments in there because I don't want to pretend that I said anything perfectly right from the beginning, without the help of others.

Post reply on HN