Keybase raises $10.8M
91–100 of 126 posts
Re: Keybase raises $10.8M
#92Earlier quoted context omitted.
Referral trees let you control abuse; if someone suddenly spawns lots of accounts via nested referrals for abuse, you can just cleave off the appropriate subtree.
Really? How can they publicly state that they promote security and open source tools while denying anyone access who like to use the service?
Now what I don't understand is there are existing large WoT in GPG keys and they "shoulda" given like 1000 invites to anyone with a debian.org developer key because thats a community of deeply connected very long term WoT (well, more or less).
Find someone in your existing WoT who is on keybase and they probably have invites and will give one. I have invites. I will give them out to anyone in my existing WoT who asks. If they aren't in my WoT then theres no point for them to ask, or me to give. Even friend of friend or more distant, not just signed each others keys.
This also creates a dilemma where I have to keep a stockpile of invites in case some I closely connect to "needs" an invite. So FoFoFoF of some guy I met at a HOPE conf might not get one of my invites because I need to save it in case my coworker finally gets off his butt and signs up and he needs my invite. This is rollout mistake two, I should be able to request via a form or something "I have a really good excuse now gimme an invite". However they're AFAIK randomly granted over time or something.
Re: Keybase raises $10.8M
#93I just looked at the source of the page: A) external CSS which might leak about a visitor to Google B) No Google Analytics or other 3rd party hosted script tags on Keybase. And this has the added bonus that we'll never be able to serve ad code. \o/ \o/ chris max ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~--> No 3rd party JS: good. Still leaking visitor info: bad.
hah, I forgot about that note. Good point - our stance was to protect from targeted code injections (by a coerced or hacked Google). But of course you're right, there's no point letting Google know at all. I've made an issue to move font/css hosting off Google.
Re: Keybase raises $10.8M
#94Why the invite thing? Really? Why shorten artificially on who you let in?
Re: Keybase raises $10.8M
#95Re: Keybase raises $10.8M
#96Do they have any sort of monetization plan or strategy?
Re: Keybase raises $10.8M
#97Pretty strong language there (and definitely not provably true or fale), but I guess bold phrasing is what SV is known for.
Re: Keybase raises $10.8M
#98Re: Keybase raises $10.8M
#99It is not possible to deploy this to the mainstream who probably need encryption the most. Keybase's mission iirc is to bring encryption to the masses without having to learn about encryption. It is imo the best alternative to the status quo, i.e: no encryption.
Re: Keybase raises $10.8M
#100Keybase is the wrong way to do a PKI directory. First, people should have multiple keys/identities by default; multiple identities should be the normal thing everyone does. Single identities will be used by governments to control people. They'll also work against normal communication patterns where people speak differently to different groups (think parents, friends, coworkers.) Second, matching a name with social me…
Key management is tough. OAuth and tokenisation are great solutions for authentication but applications like GPG and crypto-currencies will likely still require "proper" crypto. Smartcards feel like the now-old'n'clunky prototype/PoC implementation of something better. I can't help feeling like the banks and telcos could contribute to a solution if they could work more collaboratively.
I don't think the end solution is a proprietary, for-profit one. It needs to be open and accessible to everyone, instead of fragmented into competing walled gardens.