Live data from Hacker News

Zoom Acquires Keybase

keybase.io

151–160 of 751 posts

Re: Zoom Acquires Keybase

#151
post #142

Earlier quoted context omitted.

It seems that we live in an era where if you made bad decisions in the past, you can never be trusted to make good decisions ever again. Even if you own your bad decisions and show lots of improvement. Nope. Once a pariah, always a pariah.

Zoom's decisions did not feel like mistakes so much as an expression of their values. The company repeatedly prioritised ease of use while doing the absolute minimum on the security front. Are there any grounds to believe that that calculus has changed?

No, but now they see that the minimum is not where they had thought. As someone who does security professionally, of course a business wants to do the minimum necessary for security. The point of security systems is to break things that would otherwise work.

TLS is there to break sessions that would work under TCP. GPG is there to tell you to discard some mail.

Re: Zoom Acquires Keybase

#152
post #80
post #60

Earlier quoted context omitted.

I don’t necessarily read it that way. Keybase is 100% functional and has worked well for a long time. Zoom needs people who know how to make modern client software and chat if they want to compete with the Slacks and Teams, etc. You can’t even screen share on wayland... it’s that bad. If keybase ultimately gets secure video, and zoom a security architecture overhaul, how is that a bad thing?

Zoom is actually one of the view applications that can screen share on Wayland I believe it's only enabled for a few distros though

Does it work with the browser version?

Re: Zoom Acquires Keybase

#153
post #93

Earlier quoted context omitted.

As someone who works at an open-source-focused business, I respectfully disagree. Unlike proprietary software, open source software doesn't depend on the broken window fallacy. As a result, it's really hard to make open source profitable. There's lots of different avenues to get there, and I don't like to fault someone for their efforts if the bulk of their work goes towards improving open source software, as I think…

Possibly, but in this case I didn't expect them to make Keybase profitable, if anything I expect the opposite. I expect Keybase to be a FOSS, foundation for profitable extensions that the company builds and sells. Arguably I think they agree with me, about the extensions at least. As seen by their seemingly random directions of feature extensions that Keybase was prone to. My issue is not that they chose random featu…

Maybe "losing Ubuntu if Canonical went under" is a better analogy then?

Re: Zoom Acquires Keybase

#154
post #107

Earlier quoted context omitted.

If Keybase acquired Zoom (haha), then, sure. This is a PR move for a public company. They'll probably gut Keybase, move their Chinese server generated AES128 keys to AES256 keys generated by you and uploaded to their Chinese server, then call it a day. I can't think of a single instance where acquisition of a smaller company like this resulted in an improved version of the original product. How many of us are running…

> Facebook purchasing Whatsapp, another service that formerly stressed encryption, resulted in things like plaintext backups of your texts on Facebook servers being aggressively promoted as soon as you loaded the app. Ia that the case? AFAIK WhatsApp gained proper end to end encryption after being bought by Facebook and pushes for backups to Google (and maybe iCloud?) servers. Wikipedia writes: > WhatsApp was initial…

Whatsapp announced encryption to the world in 2012. OWS helped secure their app further after the 2014 acquisition by FB, but encryption was something stressed by Koum and Acton from the get-go. Integration of E2EE into Whatsapp/FB Messaging is one of the few examples of Zuck being on the right side of things.

Long term it ended up pretty good, with Koum and Acton taking their acquisition money bags and pouring them into FOSS projects like FreeBSD and the Signal Foundation. Maybe malgorithms will do the same.

https://en.wikipedia.org/wiki/Timeline_of_WhatsApp

> pushes for backups to Google (and maybe iCloud?) servers.

Yeah, I was incorrect. They backup to Google servers. Not sure if that's better or worse. :)

Since then, FB has offered willingness to cooperate with foreign governments to break encryption. I guess we will see what happens with the EARN IT Act.

https://www.bloomberg.com/news/articles/2019-09-28/facebook-...

RHL might be a bad example too, since Fedora is still pretty prominent, even if not often used compared to debian or debian-based distros these days.

Re: Zoom Acquires Keybase

#155
post #78

Honest question, why does Zoom’s security reputation matter more than Keybase’s? There’s so much pessimism in here but I really don't get it. I disliked zoom long before any of the security issues because frankly it’s rough, unpolished, software that’s never really worked well for me. I, for one, would be excited to get a functional Zoom with better security integrated into Keybase as an option for UI so that you hav…

One scenario in which Zoom's rep matter more, to me, is that they keep keybase alive, but now Zoom's slop infiltrates keybase.

In one way, good job Zoom for looking into security. In another way, I'm still looking at this awful UX that's buggy as hell and thinking it's gonna be a real slog for the keybase team to overcome that momentum.

Re: Zoom Acquires Keybase

#157
Everyone here saying Keybase is dead... why hasn't anyone mentioned that Keybase is open-source? New BSD (3 Clause) License. [1]

So regardless of what happens to it with Zoom, the community can fork it and continue developing it, no?

So if people don't want it to be dead... it's not dead. That seems like great news, right? (And great foresight?)

[1] https://keybase.io/docs/the_app/source_code

Re: Zoom Acquires Keybase

#158

It's kinda ironic that Keybase disappears into Zoom the day after Matrix/Riot enabled end-to-end encryption by default, with cross-signed device verification similar to Keybase's concept of connected keys - see https://blog.riot.im/e2e-encryption-by-default-cross-signing... . In other words, a fully open source (and open standardised) alternative continues to exist in the form of Matrix. [disclaimer: project lead for…

Hi! I use Matrix a lot, but a privacy-sensitive group of my friends recently switched to Keybase largely due to the per-room/per-message retention policies. This might be a good opportunity to convince them to jump ship, and I know something similar has been in the works for Matrix, but do you know where it is on the list of priorities?

(Congrats on the cross-signing release though, it's been a long time coming and it's been working really well!)

Re: Zoom Acquires Keybase

#159

Earlier quoted context omitted.

It bothers me that they even tried, honestly. Keybase seems like something that should be small, isolated, FOSS, supported by a foundation, etc. They could have built a business _around_ Keybase I'd imagine, but all they managed to do with this is invalidate Keybase and make people like myself, who feared their business motivations, feel vindicated for being paranoid. I'll never blame anyone for wanting to make money…

keys.pub doesn't have the single most useful feature Keybase has: The ability to verifiably establish a secure channel with anyone given their Twitter/Github/whatever username.

Their homepage advertises 'keys pull username@github' as an example. Is the missing piece you describe here simply the command 'keys chat username@github'?

Re: Zoom Acquires Keybase

#160

Earlier quoted context omitted.

Ghost (blogging software) chose to incorporate as a Company Limited by Guarantee [1], which doesn't have shares and can't be acquired that way: https://ghost.org/changelog/moving-to-singapore/ [1] https://en.wikipedia.org/wiki/Private_company_limited_by_gua...

Sweet, i kind of knew it already existed, but this type of structure is just so damn rare. I guess most founders are really just motivated by the pot of gold at the end of the rainbow :/

It only really works for bootstrapped non-profits, and for projects that are entirely volunteer-driven. No VC would be able to invest in something like this (unless it's a grant like what YC does for non-profits [1]).

Even Mozilla Foundation [2] was spun off from Netscape, and heavily supported by AOL in its early years.

[1] https://www.effectivealtruism.org/articles/why-nonprofits-sh...

[2] https://en.wikipedia.org/wiki/Mozilla_Foundation#History

Post reply on HN