Live data from Hacker News

Keybase raises $10.8M

keybase.io

71–80 of 126 posts

Re: Keybase raises $10.8M

#72
post #50

Keybase is the wrong way to do a PKI directory. First, people should have multiple keys/identities by default; multiple identities should be the normal thing everyone does. Single identities will be used by governments to control people. They'll also work against normal communication patterns where people speak differently to different groups (think parents, friends, coworkers.) Second, matching a name with social me…

you've essentially described what google is trying to do with gnubby/u2f, now hamstrung by FIDO and converging UAF standards. If you are interested a high level explanation is here: https://docs.google.com/presentation/d/16mB3Nptab1i4-IlFbn6v...

the idea being you mint a new keypair per service and the private keys are stored securely on your device (currently yubikeys but soon all devices will have a secure way to store key material (e.g., secure enclave, TEE, secure elements)), public keys get stored on the service you want to authenticate against.

Re: Keybase raises $10.8M

#73
post #50

Keybase is the wrong way to do a PKI directory. First, people should have multiple keys/identities by default; multiple identities should be the normal thing everyone does. Single identities will be used by governments to control people. They'll also work against normal communication patterns where people speak differently to different groups (think parents, friends, coworkers.) Second, matching a name with social me…

I like the idea but I also think it can be fully distributed - something like bitcoin/block chain

Re: Keybase raises $10.8M

#74

Why the invite thing? Really? Why shorten artificially on who you let in?

Referral trees let you control abuse; if someone suddenly spawns lots of accounts via nested referrals for abuse, you can just cleave off the appropriate subtree.

Re: Keybase raises $10.8M

#77

Can someone please send a Keybase invitation to: keybase-please@Safe-mail.net This help would be appreciated.

Just sent you an invite. If anyone else needs an invitation, I still have 8 left. Shoot me an email or reply here if you want one.

Edit: 6 still left.

Re: Keybase raises $10.8M

#78
post #58

Earlier quoted context omitted.

U jelly? I imagine you walk up to Marc and say, "Hey, we are building PGP for the world." Some days later, $10,000,000 pops in to your bank account. Edit: Would be considerate if the down-modders would provide an alternate scenario.

No, I am not jealous or anything. I have bunch of side projects which I never considered "investable" since none of them has clear path to monetization and/or built openly. Therefore I wanted to know what it takes to grow a full scaled business out of currently non-monetizable hobby project.

Sorry, that's just the first impression I got when I read your comment.

I wouldn't say a new company with (presumably) no revenue, but $10 million in funding is a full scale business. Certainly more of a business than a hobby project, but at some point a business needs revenue to qualify as a 'business'.

To be invested in, you need to convince your investors to give you money to do something. You have to explain what you are doing in a way they can understand and once they understand what you are doing, they need to be excited and want to invest (because they are interested in what you are doing or because they think they can make a lot of money off your work).

In this case, the investors are very interested in public key cryptography and Keybase was able to explain to them what they are doing and what they need going forward to build what they are trying to build.

Re: Keybase raises $10.8M

#79
post #62

Earlier quoted context omitted.

Yeah, email's a bit more complicated than twitter. I think for the time being, you want to just encrypt to a file and attach that. Maybe there's a standard (PGP mail?) that keybase could output to a file, but that doesn't tend to play well with the GUI mail clients that people typically use.

Thanks for your answer. The main goal on my case is to use the email address as an identity (since it's currently the closest thing I have for this) and not to send encrypted PGP email messages. That's why I never really understood keybase. You can encrypt with a twitter id but not send a encrypted tweet with GPG anyway, so why can't you encrypt by email ? I assumed the most basic form of identity is an email address…

Well, keybase only uses verified identities like twitter, hackernews, etc as identifiers. As far as I know, there's no way to publicly verify that someone actually owns an email address...

Re: Keybase raises $10.8M

#80
post #31

Earlier quoted context omitted.

Have it ocurred to you that different people have different threat models? Yes, if a powerful state actor really is after you, they will most probably find a way sooner or later. Crypto is still useful for lots of use cases. E.g. protecting data from competitors, stalkers or identity thiefs.

Has it occurred to you that if your device is full of side channels, anyone can use those side channels? How can you create a legitimate-government-only side channel? You could do it by basing all encryption off a master key that only the legitimate government controls. However, there's no way for a legitimate government to force everyone to only communicate with the master key. Any other side channel is going to be…

I have never endorsed ”legitimate-government-only side channels”. I’m trying to nuance the discussion by asserting that not every attacker is equal in their skills and resources.
Post reply on HN