Live data from Hacker News

Introducing Keybase Chat

keybase.io

191–200 of 201 posts

Re: Introducing Keybase Chat

#191
post #121

Warning to all OS X users: The Keybase Chat desktop app does a number of shady things that ultimately led me to delete it from my system. I am writing this purely as a public service announcement, to those who worry about installing unknown apps on their Macs. The Keybase Chat app: (1) Requires administrator privileges to launch on first run, to install a "Helper Tool". The app does not explain what this tool does, w…

I'm not qualified or interested enough to investigate this but I can tell you that on Windows Trend Micro have blocked keybase as potential malware. It's reported on github and keybase have requested an exception but reading your post one starts to wonder why Trend Micro would get that idea.

Just a heads up that you might want to be careful with trusting Trend Micro too much...

https://bugs.chromium.org/p/project-zero/issues/detail?id=77...

Re: Introducing Keybase Chat

#192

This is the reason I am so excited about Keybase. I can't comment on the integrity of the software but the vision is there. All encrypted everything is where I see the future of the internet. Does anybody know if they are working on a mobile app for at least the chat system? I don't necessarily need the whole desktop app on the phone but encrypted chat would be fantastic. (Currently using Signal but would be open to…

Yes, mobile apps are on the way, it mentions in the faq

Re: Introducing Keybase Chat

#194

Earlier quoted context omitted.

Should be easy since main app is in electron

It's pretty hard to do crypto securely in a browser though without depending on browser extensions and whatnot.

I made a research on this https://sakurity.com/blog/2015/07/28/appcache.html

I'm fine with having a less secure web version and i know its limitations

Re: Introducing Keybase Chat

#195
post #99

Earlier quoted context omitted.

I use pass, of http://passwordstore.org While I didn't try it myself (I just run my own git server), symlinking the directory of that to kbfs (or maybe just create a git repo there and make some magic to locally push stuff) should work.

I saw that recently, after the post on here about the 'pass compatible password management for teams', I forget what it was called. It's actually more along the lines of the latter I wanted to do with Passbase - seeing as it's already using KBFS it would be (relatively) easy to do password sharing, just throw it in a shared private folder. I was thinking more of the shared pizza-order password with room-mates, or gro…

I think it was probably 'gopass', https://news.ycombinator.com/item?id=13551692

Re: Introducing Keybase Chat

#197

Earlier quoted context omitted.

It's in our released downloads at https://keybase.io/download We don't use GitHub releases often.

https://keybase.io/download just points back to github for source. You also haven't tagged anything more recent than that github release: https://github.com/keybase/client/tags If you're not tagging or doing github releases, is there a list of 'stable' versions that distros should consider packaging?

No, sorry. We're still making a new release almost every day, and we have no stable branches, only master.

We'd prefer people to just install our own package.

Re: Introducing Keybase Chat

#198
post #121

Warning to all OS X users: The Keybase Chat desktop app does a number of shady things that ultimately led me to delete it from my system. I am writing this purely as a public service announcement, to those who worry about installing unknown apps on their Macs. The Keybase Chat app: (1) Requires administrator privileges to launch on first run, to install a "Helper Tool". The app does not explain what this tool does, w…

> Installs /usr/local/bin/keybase without asking permission

I'd guess that any installer would be expected to do this, this particular item doesn't sound "shady".

Re: Introducing Keybase Chat

#199

Earlier quoted context omitted.

https://keybase.io/download just points back to github for source. You also haven't tagged anything more recent than that github release: https://github.com/keybase/client/tags If you're not tagging or doing github releases, is there a list of 'stable' versions that distros should consider packaging?

No, sorry. We're still making a new release almost every day, and we have no stable branches, only master. We'd prefer people to just install our own package.

I would fully recommend against people installing packages from outside their distro. especially crypto related ones.

Do you consider master stable? i.e. should we consider packaging every master commit?

Re: Introducing Keybase Chat

#200
post #191

Earlier quoted context omitted.

I'm not qualified or interested enough to investigate this but I can tell you that on Windows Trend Micro have blocked keybase as potential malware. It's reported on github and keybase have requested an exception but reading your post one starts to wonder why Trend Micro would get that idea.

Just a heads up that you might want to be careful with trusting Trend Micro too much... https://bugs.chromium.org/p/project-zero/issues/detail?id=77...

I'm glad you showed me that but unfortunately I'm required to run it by my organisation. And even if I do disable it we have VPN software that requires some sort of AV before you're granted access.
Post reply on HN