Live data from Hacker News

Keys.pub – Manage cryptographic keys and user identities

keys.pub

41–50 of 92 posts

Re: Keys.pub – Manage cryptographic keys and user identities

#41

I think it might be a good idea to use something like IPFS to distribute keys. Now that cloudflare seems to want to support it officially, the only exception to why they might not are the same kind of lawsuits that brought down the pirate bay but cloudflare has opted to offer content blacklisting/cache refuse in their terms of service so I'm not sure how that's going to work out, but so far since 2018 nothing seems t…

I want to add to that the ethereum name service, https://www.increaseo.com/eth-domains-ipfs/ could also potentially play a role in a means to efficiently and reliably distribute public keys in conjunction with IPFS? Seems worth considering at least.

and it's not the fastest thing but in theory it's simple enough that you can just do something like this:

ipfs add test.asc added QmX1yKeerXb9vSYoQXcZuuw1QFTu5UxDCec4hY9htjRYE7 test.asc

and retrieve it https://cloudflare-ipfs.com/ipfs/QmX1yKeerXb9vSYoQXcZuuw1QFT...

if you have an ENS name you can access it this way: https://cloudflare-ipfs.com/ipns/atmarketplace.eth/

Re: Keys.pub – Manage cryptographic keys and user identities

#42
post #33

I, for one, am happy Keybase user, excited about their new features and can see it already becoming a much better (but not ideal) alternative to Signal for private IM (proper encryption, every device is first-class, usable CLI, no phone-number bullshit, good team chats, etc). But I do see that the same reason I am optimistic is the same reason many users are disappointed and they're right - Keybase seems to have pivo…

Keybase jumped the shark with their crypto coin offering.

I keep hearing people say this, but I don't understand it. It was a fun little giveaway experiment funded by someone else, in the spirit of the company's focus on cryptography.

I don't visit the cryptocurrency tab anymore, and it's not like it gets in the way or anything.

Re: Keys.pub – Manage cryptographic keys and user identities

#43
Hi all,

I'm the author of keys.pub.

Can the mods change the title of this post at all? This project is meant to be supportive of ideas from Keybase and to promote Saltpack and this title is weirdly disparaging. (Edit: Title was changed, thanks!)

Thanks everyone for the feedback. This project is in its early stages but the goal is to make it easier to manage and securely store keys and secrets.

I'm currently working on hardware key support and FIDO2 integration, so be on the lookout for that.

Re: Keys.pub – Manage cryptographic keys and user identities

#44
post #43

Hi all, I'm the author of keys.pub. Can the mods change the title of this post at all? This project is meant to be supportive of ideas from Keybase and to promote Saltpack and this title is weirdly disparaging. (Edit: Title was changed, thanks!) Thanks everyone for the feedback. This project is in its early stages but the goal is to make it easier to manage and securely store keys and secrets. I'm currently working o…

You can reach the mods at hn@ycombinator.com

Re: Keys.pub – Manage cryptographic keys and user identities

#45
post #43

Hi all, I'm the author of keys.pub. Can the mods change the title of this post at all? This project is meant to be supportive of ideas from Keybase and to promote Saltpack and this title is weirdly disparaging. (Edit: Title was changed, thanks!) Thanks everyone for the feedback. This project is in its early stages but the goal is to make it easier to manage and securely store keys and secrets. I'm currently working o…

I am indeed glad I saw this comment, because as someone who likes Keybase, when I saw the title, I was like "ugh". Hopefully dang or sctb will edit it soon!

Re: Keys.pub – Manage cryptographic keys and user identities

#46

Earlier quoted context omitted.

That's fair, my question was more about the cryptocurrency feature specifically. "General bloat" I can understand, if you only care about the keys. It seems to me, though, that the key part is just the first step in an entire featureset: Once you have a reliable way to get trusted encryption keys for any person, you can build a whole lot of useful functionality on top of that, which is what they've been doing. Person…

It would be possible to build an ignorable cryptocurrency feature, and if that had been the case, I probably wouldn't have noticed or cared. Instead Keybase tied into the launch of a questionable currency which involved giving the currency to people as a marketing tool and then resulted in a spree of attackers, disclosure attacks and other problems. There's a difference between "Hey, we've built in a small wallet fea…

I haven't found a use for it yet, but I'm not upset that they gave me money. It's the only crypto I've ever owned, but it's mine I guess?

Also, my understanding is (at least in the US) that you don't need to declare gifted cryptocurrency until/unless you realize it's value by either selling it or sending it to someone else as payment for a service.

Re: Keys.pub – Manage cryptographic keys and user identities

#47

I was a very early user of Keybase and I've been super disappointed in the direction they've gone. They've had some neat ideas along the way but packing them onto the key service and the cryptocurrency missteps have caused me to shy away from them. This looks like a good start for a real competitor. Obviously it's early but I'm seeing the right things.

I haven't followed them too closely for a while but wasn't the cryptocurrency misstep an answer to critics about the safety of keybase as keeper of the database[0]?

Now that I'm looking it although their docs don't mention anything[1] I'd assume it's related to their funding[2].

[0]: https://keybase.io/docs/server_security/merkle_root_in_stell...

[1]: https://keybase.io/docs/server_security/merkle_root_in_stell...

[2]: https://keybase.io/blog/keybase-stellar

Re: Keys.pub – Manage cryptographic keys and user identities

#49

Earlier quoted context omitted.

I see this from a lot of people and I'm puzzled, can you not just avoid using the features you don't like? I don't see anyone going "I used to use VS Code but they added a database viewer so I stopped".

The keybase client went from a small CLI to a persistently connected app that ties into a filesystem, cryptocurrency platform, chat ecosystem and more. Nothing is free. Adding features takes up resources, adds complexity and errors and increases attack surface. Sometimes that's an OK tradeoff - I like being able to see images in my email client. Sometimes the tradeoff is not worth it - my text centric IDE has no busi…

What if there was a lightweight keybase cli that only did the basics (official or community)?

Re: Keys.pub – Manage cryptographic keys and user identities

#50
post #27

Earlier quoted context omitted.

That's fair, my question was more about the cryptocurrency feature specifically. "General bloat" I can understand, if you only care about the keys. It seems to me, though, that the key part is just the first step in an entire featureset: Once you have a reliable way to get trusted encryption keys for any person, you can build a whole lot of useful functionality on top of that, which is what they've been doing. Person…

The entire cryptocurrency airdrop thing has caused lots of noise, triggered campaigns to try and hack/social engineer accounts that would qualify the attacker to grab more cryptocurrency, ... It makes it vastly less likely I'll recommend Keybase with those associations, which diminishes the value of the "key part". (Not recommending it both because it makes me question the long-term priorities of the product and beca…

Isn't Keybase built exactly for this though? To be able to look at the connected accounts/proofs, and know that a given Keybase user has proven control of those accounts? An attacker looking for crypto may have hacked someone's HN or GitHub. However, with Keybase, you can establish someone you want to talk to has linked their Twitter and their web domain and the like, whereas an attacker probably does not have access to all of their various identities around the Internet.
Post reply on HN