Live data from Hacker News

Keybase iOS Has a Backdoor?

sneak.berlin

11–20 of 56 posts

Re: Keybase iOS Has a Backdoor?

#11
So basically:

- You can send a message to anyone with the iOS Keybase client, asking it to sign a message saying that a certain XLM address is theirs

- Your client will happily and automatically do so and add it to your Keybase profile page, no interaction needed

I base this summary on the statements "Keybase updated their iOS client to sign an attestation, as a user, that a given stellar address belongs to them, even if it does not. This is done without any user interaction" and "There is no option to remove this payment address from my Keybase profile". Did I get that right? It seems kinda weird, but given the partnership, I guess this is the way to roll that out quickly.

So the point of Keybase is tying profiles together, like HN and GitHub account, Powerdraincurrency addresses, PGP key, etc., all with cryptographic proofs. It would be pretty weird indeed if any of the Keybase clients chose to cryptographically sign a proof for a random GitHub account upon being asked to do so, no matter whether is really is your GitHub account. I can see why the author calls this a backdoor.

But what everyone expected to read is a way for Keybase to read your messages (Keybase chat) or your files (Keybase filesystem) or something. This is not the case in any way, as far as I can tell. The "backdoor" headline is somewhat clickbaity (the owner of Keybase would probably consider it slander though it's not a good PR move to actually say that), even if I see what the author means.

Re: Keybase iOS Has a Backdoor?

#12

Signing an attestation without user consent is certainly a huge breach of Keybase’s trust, but describing this as a “backdoor” feels inaccurate.

https://keybase.io/blog/2014-10-08/the-horror-of-a-secure-go...

Keybase uses the term "backdoor" in their blog to describe an app using a key to sign another key as valid (violating user intent/consent).

Re: Keybase iOS Has a Backdoor?

#14
post #10

Keybase has a built in business model that they don't want to take advantage of for some unknown reason. They made a combo of services that are a "more private" business dropbox, slack and git hosting, which are all business that charge money. I don't understand why they don't charge money for it? Is it because all of their implementations are currently slow and they don't want to be subject to the SLAs that business…

I too would pay even just for more storage, and an ability to manage E2E encrypted emails through them. @keybase.io / .com(?) emails would be awesome, especially if it could cross-contact a protonmail email (anyone able to send emails to protonmail accounts outside of protonmail, encrypted and decrypt the responses yet? never looked into this).

Re: Keybase iOS Has a Backdoor?

#15
post #2

Gotta say, I didn’t expect Keybase to do this after they announced their partnership back in 2018[0] Automatically attesting keys with no user consent? Not good. This implies you are happy and willing to add arbitrary attestations to a users profile. For now you presumably have a rationale. But this is a can of worms I don’t think should have been opened. [0] https://keybase.io/blog/keybase-stellar

Looking at the issues is interesting: https://github.com/keybase/client/search?l=Go&p=1&q=xlm&type... and https://github.com/keybase/keybase-issues/issues?utf8=%E2%9C... - apparently running a crypto airdrop is still a way to get user numbers up...

Re: Keybase iOS Has a Backdoor?

#16
post #12

Signing an attestation without user consent is certainly a huge breach of Keybase’s trust, but describing this as a “backdoor” feels inaccurate.

https://keybase.io/blog/2014-10-08/the-horror-of-a-secure-go... Keybase uses the term "backdoor" in their blog to describe an app using a key to sign another key as valid (violating user intent/consent).

Your post would benefit from this information.

Re: Keybase iOS Has a Backdoor?

#17
post #10

Keybase has a built in business model that they don't want to take advantage of for some unknown reason. They made a combo of services that are a "more private" business dropbox, slack and git hosting, which are all business that charge money. I don't understand why they don't charge money for it? Is it because all of their implementations are currently slow and they don't want to be subject to the SLAs that business…

I too would pay even just for more storage, and an ability to manage E2E encrypted emails through them. @keybase.io / .com(?) emails would be awesome, especially if it could cross-contact a protonmail email (anyone able to send emails to protonmail accounts outside of protonmail, encrypted and decrypt the responses yet? never looked into this).

> anyone able to send emails to protonmail accounts outside of protonmail, encrypted and decrypt the responses yet? never looked into this

Yes. It's dead simple. Get your protonmail keys here [0], and on the contacts page, click the cog next to the user's email address to import public keys.

[0] https://mail.protonmail.com/keys

Re: Keybase iOS Has a Backdoor?

#18
post #16
post #12

Earlier quoted context omitted.

https://keybase.io/blog/2014-10-08/the-horror-of-a-secure-go... Keybase uses the term "backdoor" in their blog to describe an app using a key to sign another key as valid (violating user intent/consent).

Your post would benefit from this information.

Updated.

Re: Keybase iOS Has a Backdoor?

#19
Not every keybase user has a stellar attestation. When it happened to me I think I had to take some action. I don't remember the exact language. Anyone have that detail?

Re: Keybase iOS Has a Backdoor?

#20
Hold on, I'm confused.

This isn't allowing anyone to arbitrarily add any Stellar key to somebody else's profile or anything, is it? (And thus redirect actual money?)

It's just generating a new Stellar profile/key for each Keybase user automatically, and affirming that it belongs to each Keybase user?

Hardly seems like a backdoor, just a mildly annoying/unwanted marketing partnership. Actually not even partnership -- since Stellar is now funding Keybase, just cross-product promotion? [1]

[1] https://keybase.io/blog/keybase-stellar

Post reply on HN