The fatal problem with this plan is that all end user devices are by now hopelessly compromised. Take a look at the Snowden documents, which are now years behind the state of the art. It doesn't matter if your crypto is both bulletproof and easy to use. They'll just break into your phone or your laptop through a side channel and read the key. And you won't even notice.
Keybase raises $10.8M
31–40 of 126 posts
Re: Keybase raises $10.8M
#32From my limited following keybase.io it seems like this is mostly hobby project. How does one get investment for this kind of projects? Do you need to know someone already? Or do you decide to pull a plunge and create business plan and present it on one of these demo days organized for investors? I feel like there is a huge gap between potent, but still hobby, project and series A funding.
Re: Keybase raises $10.8M
#33The fatal problem with this plan is that all end user devices are by now hopelessly compromised. Take a look at the Snowden documents, which are now years behind the state of the art. It doesn't matter if your crypto is both bulletproof and easy to use. They'll just break into your phone or your laptop through a side channel and read the key. And you won't even notice.
Have it ocurred to you that different people have different threat models? Yes, if a powerful state actor really is after you, they will most probably find a way sooner or later. Crypto is still useful for lots of use cases. E.g. protecting data from competitors, stalkers or identity thiefs.
It's far more likely that you'll run into someone trying to steal your credit card than an intelligence agency, but they'll be using the same exploit to get into your phone.
Re: Keybase raises $10.8M
#34Re: Keybase raises $10.8M
#35Congrats! Increasingly pessimistic as a British subject that I'll ever be able to use something like this without attracting the attention of my own government though.
And intelligence agencies have been known to retain encrypted content for longer (in theory, forever): http://www.darkreading.com/risk-management/want-nsa-attentio...?
The older I get the more impressed I am with how prescient Scott McNealy was when he said: "You have zero privacy anyway. Get over it."
Re: Keybase raises $10.8M
#36> The Node reference client to our PGP directory will be retired. (PGP support will continue, of course.) Can anyone from Keybase shed light on the reasoning behind this? It sounds like you are moving away from programmer-friendly API libraries and into GUI apps. Even if they're open source, as a developer I really liked your up-front API. Will you still be providing those APIs?
Oh, a clarification: the Node client will be replaced by the Go version. The `keybase` command line app will be a superset of what's available in the Node client now. Sorry. So yeah - still providing those API's. PGP support will continue, always, it's just that you won't need to have PGP on all your devices -- just the ones you use PGP on. Your PGP key will be part of a family of keys you're known by. If you install…
Re: Keybase raises $10.8M
#37The fatal problem with this plan is that all end user devices are by now hopelessly compromised. Take a look at the Snowden documents, which are now years behind the state of the art. It doesn't matter if your crypto is both bulletproof and easy to use. They'll just break into your phone or your laptop through a side channel and read the key. And you won't even notice.
This is news to me. Are there known side channel vulnerabilities for an arbitrary ubuntu desktop?
Re: Keybase raises $10.8M
#38The fatal problem with this plan is that all end user devices are by now hopelessly compromised. Take a look at the Snowden documents, which are now years behind the state of the art. It doesn't matter if your crypto is both bulletproof and easy to use. They'll just break into your phone or your laptop through a side channel and read the key. And you won't even notice.
Re: Keybase raises $10.8M
#39Earlier quoted context omitted.
Have it ocurred to you that different people have different threat models? Yes, if a powerful state actor really is after you, they will most probably find a way sooner or later. Crypto is still useful for lots of use cases. E.g. protecting data from competitors, stalkers or identity thiefs.
This sort of thing may have been limited to powerful state actors a few years ago, but now Pandora's Box has been opened. Many other actors are now actively exploiting the holes deliberately created in the entire stack of computer security infrastructure over the past 20 years by those state actors. It's far more likely that you'll run into someone trying to steal your credit card than an intelligence agency, but the…
Re: Keybase raises $10.8M
#40Hopefully they'll be able to address this then: http://i.imgur.com/3VAMerv.png (from https://twofactorauth.org/ )