Earlier quoted context omitted.
I'm not OP, but feel similarly about Keybase. When it originally launched, it marketed itself as directory where you could link your social accounts using cryptographic proofs, so that anyone who was wondering if "@lutoma" on twitter and "lutoma" on Hacker News are the same person could easily check. I.e. pretty much what Keyoxide now seems to aim to do. Simple enough and reasonably useful. But then at some point the…
Seems like the problem is that their core service simply did not make any money
Keyoxide: A privacy-friendly platform to establish your decentralized identity
11–20 of 60 posts
Re: Keyoxide: A privacy-friendly platform to establish your decentralized identity
#12I really like the general idea of decentralized identity. Personally I'd prefer to keep my identities on different apps/platforms mostly (99%) separate. It seems to me that giving an adversary a map (especially usernames and email identities) of your online presence is a bad idea especially if they get access to one account and get some private details they may be able to use to socially engineer their way into other…
Re: Keyoxide: A privacy-friendly platform to establish your decentralized identity
#13It'd be cool to see this without PGP. Signatures via signify/minisign are superior in every way.
If not, I don't see how you can claim it is superior in every way, because here are at least two ways in which PGP/GPG are by far superior.
Re: Keyoxide: A privacy-friendly platform to establish your decentralized identity
#14It'd be cool to see this without PGP. Signatures via signify/minisign are superior in every way.
> are superior in every way. Besides the fact that a signify/minisign are a raw key instead of being padded with identity information, in what way are they actually better? Similarly, minisign makes no claims at identity at all. You get a random string, and the user is responsible for knowing which key is for what user. The minisign public key contains nothing but the key. To me, that is a horrible user experience. A…
Re: Keyoxide: A privacy-friendly platform to establish your decentralized identity
#15It'd be cool to see this without PGP. Signatures via signify/minisign are superior in every way.
Excuse me, but does your alternative provide toolchains and user interfaces for every major platform in existence today, including Mac, *nix, iOS, Android, Windows, a library for every major language in existence, and 25 years of attempts to break it? If not, I don't see how you can claim it is superior in every way, because here are at least two ways in which PGP/GPG are by far superior.
As for 25 years to break it, well, go look at CVEs for GnuPG. There have been many.
Re: Keyoxide: A privacy-friendly platform to establish your decentralized identity
#16Re: Keyoxide: A privacy-friendly platform to establish your decentralized identity
#17It'd be cool to see this without PGP. Signatures via signify/minisign are superior in every way.
Re: Keyoxide: A privacy-friendly platform to establish your decentralized identity
#18Earlier quoted context omitted.
Excuse me, but does your alternative provide toolchains and user interfaces for every major platform in existence today, including Mac, *nix, iOS, Android, Windows, a library for every major language in existence, and 25 years of attempts to break it? If not, I don't see how you can claim it is superior in every way, because here are at least two ways in which PGP/GPG are by far superior.
I dunno about windows but minisign is on Mac and Linux, yes. As for 25 years to break it, well, go look at CVEs for GnuPG. There have been many.
Is it also available for iOS and Android? FreeBSD?
Are there libraries for Perl and PHP?
Re: Keyoxide: A privacy-friendly platform to establish your decentralized identity
#19- on each platform, include your pgp key id in the "bio"/"about" of your profile
- in your pgp key, include your profile URLs on each platform as an identity.
(In DNS, CERT RR exists for this purpose already.)