Zoom Acquires Keybase
191–200 of 751 posts
Re: Zoom Acquires Keybase
#192It's kinda ironic that Keybase disappears into Zoom the day after Matrix/Riot enabled end-to-end encryption by default, with cross-signed device verification similar to Keybase's concept of connected keys - see https://blog.riot.im/e2e-encryption-by-default-cross-signing... . In other words, a fully open source (and open standardised) alternative continues to exist in the form of Matrix. [disclaimer: project lead for…
Re: Zoom Acquires Keybase
#193Now I don’t even know if I can trust Keybase, and am trying to figure out if I should delete my account. Does anyone have any persuasive arguments for/against?
Re: Zoom Acquires Keybase
#194Everyone here saying Keybase is dead... why hasn't anyone mentioned that Keybase is open-source? New BSD (3 Clause) License. [1] So regardless of what happens to it with Zoom, the community can fork it and continue developing it, no? So if people don't want it to be dead... it's not dead. That seems like great news, right? (And great foresight?) [1] https://keybase.io/docs/the_app/source_code
Time and time again I forget about it and when I check the website it seems to be doing something different - but it all sounded very centralized, first the gpg keys, then the file-sharing and chat - it doesn't seem to be federated.
So unless some entity steps up as the de-facto api-compatible replacement, I don't see how having the code alone would help, unless you want a chat solution for a handful of users?
Re: Zoom Acquires Keybase
#195Earlier quoted context omitted.
They aren’t. They are making a lot of money which is what the business was made for. The post is actually refreshingly honest that keybase is now abandoned and will probably die at some point. The idea that companies were stupid enough to place their internal identity on some random 3rd party is so incredibly stupid that it’s hard to feel too bad for anyone. Congrats Keybase!
> They are making a lot of money which is what the business was made for. I miss the days when businesses existed not just to serve investors but also their employees and the common good. It's like a 1%-er meta profit model where the actual business is in buying and selling the business and the core business is really just a temporary front that is designed to never make a profit, just create fancy looking charts and…
Re: Zoom Acquires Keybase
#196Earlier quoted context omitted.
> They are making a lot of money which is what the business was made for. I miss the days when businesses existed not just to serve investors but also their employees and the common good. It's like a 1%-er meta profit model where the actual business is in buying and selling the business and the core business is really just a temporary front that is designed to never make a profit, just create fancy looking charts and…
> I miss the days when businesses existed not just to serve investors but also their employees and the common good Uh when was this? For-profit businesses have always been created for the primary purpose of making money. Any side effect like employee well being happened to coincide with what maximized profits at the time or due to regulation.
Here is a link that showed up in google for me when I tried to find support of this claim: https://www.washingtonpost.com/opinions/harold-meyerson-the-...
Re: Zoom Acquires Keybase
#197So it will be harder for us to get at your stuff than is is presently, but we will still be able to if we bother to do the work.
>We are also investigating mechanisms that would allow enterprise users to provide additional levels of authentication.
So they will offer completely secure communications if you are at the paid level.
Re: Zoom Acquires Keybase
#198It's kinda ironic that Keybase disappears into Zoom the day after Matrix/Riot enabled end-to-end encryption by default, with cross-signed device verification similar to Keybase's concept of connected keys - see https://blog.riot.im/e2e-encryption-by-default-cross-signing... . In other words, a fully open source (and open standardised) alternative continues to exist in the form of Matrix. [disclaimer: project lead for…
Let's say you're in a position that I think may here are: You would prefer to use IM in a secure way. Let me qualify "secure" for this purpose meaning: Encryption of communication in rest and transit; not relying on a single infra/network/service provider; being able to communicate with new peers easily without having to sign up with new providers; not requiring sign-ups leaking PIIs such as phone numbers; being able to sync message history across devices; all of this should hold for group conversations.
matrix.org seems to be on the right track towards that. Feature-wise there's some missing pieces in terms of federation but the roadmap looks like the ambition is right.
But in practice, it's realistically years until you can meet a random person in a bar and ask to join you on matrix to stay in touch, so many of us will still keep our accounts on the not-as-great platforms such as FB, Skype, WhatsApp, Signal.
Given that, wouldn't it be nice to facilitate using those platforms in a way that 1) absolves you from the behavioral tracking that comes with most of the first-party web- and smartphone apps and 2) integrates them in the same UI?
There are, of course, solutions to this end. Bitblbee (IRC gateway), libpurple (pidgin, finch), third-party clients like franz. I'm sure there are many here who have or are using libpurple or bitlbee for this.
But matrix also has bridges!
I'm thinking one potential way that matrix could really get traction and seed the network infrastructure would be just that. Given stable gateways for the IM networks people already use, it's suddenly a much easier sell to get enthusiasts and power-users to self-host matrix servers just to solve their own bridging needs and get a unified flow for disparate protocols.
As that grows, eventually there's a large spread-out flora of matrix servers that can become part of something larger.
I think if there's one thing that can make matrix succeed in it's mission, it's stable, feature-complete (or at least ticking the important boxes for the majority) bridges to mainstream services such as Facebook, Whatsapp, Signal, LINE, Skype, Google and Keybase.
I think this should be a focus for Matrix, and amazing it would be to have these be the fruit of voluntary contributors, some funding is likely required if it's to be sustainable as proprietary protocols and endpoints will inevitably break.
What's your take on that? I realize it's a long comment and I'm in a bit of a rush, but I'd be really curious to hear how you think about these things.
Re: Zoom Acquires Keybase
#199Most people here seem to be making a self fulfilling prophecy of keybase's death.
But I like to think that Zoom intends to reuse large parts of keybase codebase:
> Logged-in users will generate public cryptographic identities that are stored in a repository on Zoom’s network and can be used to establish trust relationships between meeting attendees. An ephemeral per-meeting symmetric key will be generated by the meeting host. This key will be distributed between clients, enveloped with the asymmetric keypairs and rotated when there are significant changes to the list of attendees. The cryptographic secrets will be under the control of the host, and the host’s client software will decide what devices are allowed to receive meeting keys, and thereby join the meeting. We are also investigating mechanisms that would allow enterprise users to provide additional levels of authentication.
Will the founders be interested in releasing parts if not all of the server code to the public? I believe the founders' mission is still achievable and can be carried out, should they be willing to release the code in public.
Re: Zoom Acquires Keybase
#200Oh wow, I had a guest lecture from Max Krohn yesterday in which I asked about how Keybase was being funded; no mention of this at all!
Possibly because of the confidentiality agreements everyone signs at the start of an acquisition?