Live data from Hacker News

Keybase raises $10.8M

keybase.io

91–100 of 126 posts

Re: Keybase raises $10.8M

#92
post #74

Earlier quoted context omitted.

Referral trees let you control abuse; if someone suddenly spawns lots of accounts via nested referrals for abuse, you can just cleave off the appropriate subtree.

Really? How can they publicly state that they promote security and open source tools while denying anyone access who like to use the service?

You're not really using the service, you're connecting to "the" web of trust (Are there disconnected non-contiguous islands on keybase? Only the admins know, probably). That makes me feel "meh" about giving out my invites to random HN users. I mean, if you're not going to connect to me, or the rest of the WoT, then what value do "we" get from you joining, and if you're not going to connect to me, or the rest of the WoT, then what value do you get from my invite?

Now what I don't understand is there are existing large WoT in GPG keys and they "shoulda" given like 1000 invites to anyone with a debian.org developer key because thats a community of deeply connected very long term WoT (well, more or less).

Find someone in your existing WoT who is on keybase and they probably have invites and will give one. I have invites. I will give them out to anyone in my existing WoT who asks. If they aren't in my WoT then theres no point for them to ask, or me to give. Even friend of friend or more distant, not just signed each others keys.

This also creates a dilemma where I have to keep a stockpile of invites in case some I closely connect to "needs" an invite. So FoFoFoF of some guy I met at a HOPE conf might not get one of my invites because I need to save it in case my coworker finally gets off his butt and signs up and he needs my invite. This is rollout mistake two, I should be able to request via a form or something "I have a really good excuse now gimme an invite". However they're AFAIK randomly granted over time or something.

Re: Keybase raises $10.8M

#93

I just looked at the source of the page: A) external CSS which might leak about a visitor to Google B) No Google Analytics or other 3rd party hosted script tags on Keybase. And this has the added bonus that we'll never be able to serve ad code. \o/ \o/ chris max ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~--> No 3rd party JS: good. Still leaking visitor info: bad.

hah, I forgot about that note. Good point - our stance was to protect from targeted code injections (by a coerced or hacked Google). But of course you're right, there's no point letting Google know at all. I've made an issue to move font/css hosting off Google.

Thank you very much - great reaction.

Re: Keybase raises $10.8M

#97
> Chris Dixon championed the deal; he’s known for his visionary investments, ranging from Soylent to Oculus to Airware.

Pretty strong language there (and definitely not provably true or fale), but I guess bold phrasing is what SV is known for.

Re: Keybase raises $10.8M

#99
>server-side PKI system that individuals and companies can host themselves

It is not possible to deploy this to the mainstream who probably need encryption the most. Keybase's mission iirc is to bring encryption to the masses without having to learn about encryption. It is imo the best alternative to the status quo, i.e: no encryption.

Re: Keybase raises $10.8M

#100
post #50

Keybase is the wrong way to do a PKI directory. First, people should have multiple keys/identities by default; multiple identities should be the normal thing everyone does. Single identities will be used by governments to control people. They'll also work against normal communication patterns where people speak differently to different groups (think parents, friends, coworkers.) Second, matching a name with social me…

I think each identity is going to need multiple keys too. The key in the secure element on my smartphone may well be different to the key on my Yubikey. There will also need to be a robust mechanism for revoking keys, if/when they are compromised/lost.

Key management is tough. OAuth and tokenisation are great solutions for authentication but applications like GPG and crypto-currencies will likely still require "proper" crypto. Smartcards feel like the now-old'n'clunky prototype/PoC implementation of something better. I can't help feeling like the banks and telcos could contribute to a solution if they could work more collaboratively.

I don't think the end solution is a proprietary, for-profit one. It needs to be open and accessible to everyone, instead of fragmented into competing walled gardens.

Post reply on HN