Live data from Hacker News

Keybase's mission is to make encryption mainstream

observer.com

11–20 of 84 posts

Re: Keybase's mission is to make encryption mainstream

#11
post #5

Tangent, but the article mentions using Google Authenticator -- I was going to start using that recently, but the reviews indicated it had some really big problems with restoring when you get a new phone etc and Google isn't really maintaining it. https://itunes.apple.com/us/app/google-authenticator/id38849... Can anyone comment on their 2fa approach to google?

I just changed phones and found this really simple. You can just store a phone number with Google and receive an SMS key if you forgot to print off a key before changing phones.

Everything seems to be working pretty well for me and I noticed improvements since last using the app 1+ years ago, but obviously can't guarantee it's still being updated.

Re: Keybase's mission is to make encryption mainstream

#12
post #5

Tangent, but the article mentions using Google Authenticator -- I was going to start using that recently, but the reviews indicated it had some really big problems with restoring when you get a new phone etc and Google isn't really maintaining it. https://itunes.apple.com/us/app/google-authenticator/id38849... Can anyone comment on their 2fa approach to google?

[deleted]

Re: Keybase's mission is to make encryption mainstream

#13
> In order to give everyone confidence that the people shown in the Keybase are who they say they are, Keybase encourages users to attest to their identity cryptographically on social media. Keybase is its own social network, but it’s not one for sharing pictures of food or sad status updates. It’s a place for Mary to say “This really is Bill” and for Bill to say “this really is Mary.” With enough attestations like that, it becomes really hard for people to pose as someone they are not.

Doesn’t this sound like a nightmare in terms of social engineering attacks?

Re: Keybase's mission is to make encryption mainstream

#14
post #5

Tangent, but the article mentions using Google Authenticator -- I was going to start using that recently, but the reviews indicated it had some really big problems with restoring when you get a new phone etc and Google isn't really maintaining it. https://itunes.apple.com/us/app/google-authenticator/id38849... Can anyone comment on their 2fa approach to google?

Always save the keys (or the scanner code) whenever you add them to Authenticator. Then, when you get a new phone (or whatever) you can just re-import the keys.

It's pretty stupid that Google doesn't allow for any way of getting the keys out of it's 2FA app. Your only transition path is backup/restoring an entire device to a newer one of the same OS.

There's no direct path to migrate from say an iPhone to an Android based phone without manually adding each 2FA entry to the new device.

Re: Keybase's mission is to make encryption mainstream

#15
post #11
post #5

Tangent, but the article mentions using Google Authenticator -- I was going to start using that recently, but the reviews indicated it had some really big problems with restoring when you get a new phone etc and Google isn't really maintaining it. https://itunes.apple.com/us/app/google-authenticator/id38849... Can anyone comment on their 2fa approach to google?

I just changed phones and found this really simple. You can just store a phone number with Google and receive an SMS key if you forgot to print off a key before changing phones. Everything seems to be working pretty well for me and I noticed improvements since last using the app 1+ years ago, but obviously can't guarantee it's still being updated.

That might work with Google itself but TOTP based 2FA codes aren't specific to Google. They can be used out of band by anyone and the SMS approach wouldn't apply to anybody else.

Re: Keybase's mission is to make encryption mainstream

#17

> Two veteran entrepreneurs are running a little startup built around making it easy to build web and mobile applications from day one that make data impossible for a digital trespasser to read. In fact, it encrypts data in such a way that even if you use some company’s service, that company can’t see what you’re doing with it. Is it? Not that I'm questioning Keybase, I just had no idea they were offering some type o…

Well, kbfs is end-to-end encrypted, versus something like Dropbox (for example), which is only encrypted in transit, and unencrypted at rest. And of course, you have to trust Dropbox when they say employees don't have access to your storage unless they have a good reason. But there's nothing you can do to prevent Dropbox employees (or a government, or someone that has unauthorized access) from deciding there's a good reason to access your data, because it's not encrypted end-to-end like kbfs [0].

[0] https://github.com/keybase/kbfs

Re: Keybase's mission is to make encryption mainstream

#18
If there's anyone working on an Open Source Slack (or Keybase) alternative, hit me up. I run a UI design agency and we'd love to help design a better interface for an open solution that we and others can use. Find my details in my profile, or go to http://fairpixels.pro

Re: Keybase's mission is to make encryption mainstream

#19
They don't really address the fact that every single Slack "leak" is from someone already part of the team taking screenshots of the conversation. How does any kind of encryption help that?

Also doesn't mention everything you lose out on with this approach - like searching through message history.

It's a neat product I guess, but mentioning Slack in every single line seems more to get eyeballs than a valid comparison.

Re: Keybase's mission is to make encryption mainstream

#20

> In order to give everyone confidence that the people shown in the Keybase are who they say they are, Keybase encourages users to attest to their identity cryptographically on social media. Keybase is its own social network, but it’s not one for sharing pictures of food or sad status updates. It’s a place for Mary to say “This really is Bill” and for Bill to say “this really is Mary.” With enough attestations like t…

If your social account (twitter/..) gets taken over, you'll have to publish a new proof on it, which will then need to be attested by multiple people, before it becomes trustworthy anywhere.
Post reply on HN