Live data from Hacker News

Keybase's mission is to make encryption mainstream

observer.com

21–30 of 84 posts

Re: Keybase's mission is to make encryption mainstream

#21
post #18

If there's anyone working on an Open Source Slack (or Keybase) alternative, hit me up. I run a UI design agency and we'd love to help design a better interface for an open solution that we and others can use. Find my details in my profile, or go to http://fairpixels.pro

There's a few. One's Mattermost: https://about.mattermost.com

My company has been using it for a while.

Re: Keybase's mission is to make encryption mainstream

#22
This is going to sound like a dumb question, but.... how much would encryption help? Even if we encrypted all of our data at rest and on the wire, I feel like a lot of security vulnerabilities wouldn't have been prevented with encryption. If you have any way of interacting with the application or the database, it's basically game over, no? Is there any data on this?

Re: Keybase's mission is to make encryption mainstream

#23
post #18

If there's anyone working on an Open Source Slack (or Keybase) alternative, hit me up. I run a UI design agency and we'd love to help design a better interface for an open solution that we and others can use. Find my details in my profile, or go to http://fairpixels.pro

There's a few. One's Mattermost: https://about.mattermost.com My company has been using it for a while.

We'd love to contribute (with design). Are you aware of anyone interested in collaborating. We're looking for something that we can use ourselves and thus contribute to crafting a better experience around the software.

Re: Keybase's mission is to make encryption mainstream

#24

> In order to give everyone confidence that the people shown in the Keybase are who they say they are, Keybase encourages users to attest to their identity cryptographically on social media. Keybase is its own social network, but it’s not one for sharing pictures of food or sad status updates. It’s a place for Mary to say “This really is Bill” and for Bill to say “this really is Mary.” With enough attestations like t…

If your social account (twitter/..) gets taken over, you'll have to publish a new proof on it, which will then need to be attested by multiple people, before it becomes trustworthy anywhere.

Right. Plus your KB identity will still have all of your other online identities vouching for it. So an attacker would need to commandeer a large fraction of your accounts in order to get people to trust the fraud.

Re: Keybase's mission is to make encryption mainstream

#25
I've come to the belief that crypto and security are a 'feature' and never a product.

As important as these issues are - I find that businesses and consumers don't often opt for these things as a primary choice except in specific circumstances, or for specific consumers with specific needs.

The fact is - I think - most people don't care. Even most startups don't care that much. If their conversations are 'reasonably secure' then they're good with it.

I think HN readers are way to one side on this issue - we care a lot about it. I think our views are different from that of most people.

This could change but I think we're still in this mode.

Re: Keybase's mission is to make encryption mainstream

#26
post #14

Earlier quoted context omitted.

Always save the keys (or the scanner code) whenever you add them to Authenticator. Then, when you get a new phone (or whatever) you can just re-import the keys.

It's pretty stupid that Google doesn't allow for any way of getting the keys out of it's 2FA app. Your only transition path is backup/restoring an entire device to a newer one of the same OS. There's no direct path to migrate from say an iPhone to an Android based phone without manually adding each 2FA entry to the new device.

I think they do this to make it harder for an exploit to just run the command to get the keys. I'm torn whether I think this is really an issue or not though. From a security standpoint it is one less attack vector to get my 2nd factor keys. From a usability standpoint it is annoying when I switch devices. I personally solved this problem by storing my two factor auths on my yubikey neo which is a bit more portable. I don't think there is a way to get the keys off of there either but at least the key itself is portable and works with Android and all my desktops/laptops. I am not sure if they ever figured out iPhones though.

Re: Keybase's mission is to make encryption mainstream

#27

> In order to give everyone confidence that the people shown in the Keybase are who they say they are, Keybase encourages users to attest to their identity cryptographically on social media. Keybase is its own social network, but it’s not one for sharing pictures of food or sad status updates. It’s a place for Mary to say “This really is Bill” and for Bill to say “this really is Mary.” With enough attestations like t…

The quote from the article is the writer jumping through some creative contortion to try to explain keybase prove [1] feature to a layperson.

The idea is to prove control of some social identity; then correspondingly, others on Keybase will have increasing confidence that the person in question who has proven a few third-party accounts is indeed the same person. This doesn't mean that that person is actually-actually George Washington (which is a much more difficult problem to solve), just that the person who purports to be George Washington on Keybase does indeed control some accounts on Facebook, Twitter, etc, so if you would have vested some trust into their Facebook identity, you can vest at least equivalent trust into their corresponding Keybase identity.

[1] https://keybase.io/docs/command_line

Re: Keybase's mission is to make encryption mainstream

#28

This is going to sound like a dumb question, but.... how much would encryption help? Even if we encrypted all of our data at rest and on the wire, I feel like a lot of security vulnerabilities wouldn't have been prevented with encryption. If you have any way of interacting with the application or the database, it's basically game over, no? Is there any data on this?

I’m not sure what threat model you’re proposing. If an attacker has control of your computer or the keybase app, then yes, it’s game over. But encryption removes the hosting entity as what would otherwise be a single point of failure. If you hack keybase the organization, you don’t immediately get access to everyone’s everything (in contrast with Equifax). An attacker would need to infiltrate the codebase and then release a malicious version to everyone that makes their apps decrypt/reroute/whatever the data.

Re: Keybase's mission is to make encryption mainstream

#29
post #5

Tangent, but the article mentions using Google Authenticator -- I was going to start using that recently, but the reviews indicated it had some really big problems with restoring when you get a new phone etc and Google isn't really maintaining it. https://itunes.apple.com/us/app/google-authenticator/id38849... Can anyone comment on their 2fa approach to google?

Always save the keys (or the scanner code) whenever you add them to Authenticator. Then, when you get a new phone (or whatever) you can just re-import the keys.

As an additional note: I strongly recommend storing these keys securely offline. With these keys someone can replicate your 2FA generator, so you really want it not hackable.

Paper in a fireproof safe is excellent for these sorts of things, or a safety deposit box.

Re: Keybase's mission is to make encryption mainstream

#30
post #23

Earlier quoted context omitted.

There's a few. One's Mattermost: https://about.mattermost.com My company has been using it for a while.

We'd love to contribute (with design). Are you aware of anyone interested in collaborating. We're looking for something that we can use ourselves and thus contribute to crafting a better experience around the software.

Definitely, rocket.chat. It's a proper opensource company and their mobile app could use a lot of love.
Post reply on HN