Earlier quoted context omitted.
This is fascinating concept, especially since I've always felt that my PGP key was sitting out there mostly useless since no one I know personally signs their emails or even knows someone who signs emails. However, wouldn't the weak part here be if my twitter (or other public) account was compromised somehow? Or if someone just impersonated me and sent a "unique tweet" pretending to be me? How does HN feel about that…
This is a good question: generally if all you know about someone is their twitter name, and that's it, then a compromise of their twitter account could lead to a compromise of their key announcement. Even this case is mitigated because of the timestamping: a compromise would have to be a public compromise on an ongoing basis, and everyone in the world would have to see the same compromise, including the alleged twitt…
Additionally, doesn't the user signing the statement with his or her private key mean that you need to have his private key to really believe it? I notice on the website it states that encryption/decryption is done with client encrypted keys. If it's client encrypted presumably the signing is happening at the client and an announcement is sent to keybase stating as such. How can you trust the data your getting back from the client is trustworthy or not also compromised?
Forgive me if I'm being boneheaded here, I'm just trying to grasp this so I can say, "Yes, that makes enough sense."