Live data from Hacker News

Zoom Acquires Keybase

keybase.io

441–450 of 751 posts

Re: Zoom Acquires Keybase

#442
post #326

Earlier quoted context omitted.

Thank you. Keybase had investors and I’m sure the premium Zoom offered was unbeatable. Zoom can effectively pay infinity with equity. Those investors knew that this was the best way they’d ever have to realize gains. That’s why they invested in the first place.

Well, when FB bought WhatsApp, its founders stayed on for a bit to vest his shares then founded Signal with his "screw you" money. Maybe some of Keybase's founders can do the same thing.

Founded ‘Signal Foundation‘ with Signal’s creator. Signal was around before FB bought WhatsApp.

Re: Zoom Acquires Keybase

#443

Earlier quoted context omitted.

Their homepage advertises 'keys pull username@github' as an example. Is the missing piece you describe here simply the command 'keys chat username@github'?

No, it's the cryptographic attestation so you know you are getting the right key.

They don't support it? That's weird (maybe a missing feature) given that it's quite easy to add to anything that has signed metadata, see e.g. this for OpenPGP: https://github.com/wiktor-k/openpgp-proofs#openpgp-proofs

Re: Zoom Acquires Keybase

#444

[flagged]

Zoom is a US Based, publicly traded company listed on the NASDAQ [1]. So to that first part, no, that's not correct.

However they have a Chinese subsidiary that does some of their development work along with supporting their in-China services. Any tech company that operates inside of China is legally obligated to private the CCP access to anything and everything they want. This is why most companies has separate, special, dedicated servers for/in China (up to and including AWS [2]).

The reason for the purchase of Keybase is to up Zoom's crypto game. They (Zoom) made a pledge to do significantly better around encryption and user controls, right after they became super popular and started getting targeted for news/abuse/etc.

Sadly it probably doesn't matter what you think of Keybase as this looks like this was probably an Acquihire for the team and their knowledge. Maybe Keybase the product will be totally open sourced, but beyond that it's likely dead.

[1] https://www.nasdaq.com/market-activity/stocks/zm/real-time

[2] https://www.amazonaws.cn/en/about-aws/china/

Re: Zoom Acquires Keybase

#445

Earlier quoted context omitted.

No, it's the cryptographic attestation so you know you are getting the right key.

They don't support it? That's weird (maybe a missing feature) given that it's quite easy to add to anything that has signed metadata, see e.g. this for OpenPGP: https://github.com/wiktor-k/openpgp-proofs#openpgp-proofs

I'm not very familiar with the service, but AFAIK they don't. It would be great if they added it.

EDIT: It looks like it might, from the front page, I will try it out to make sure. If it does, that'll be great!

EDIT 2: It sort of does, but it's on a per-key basis, not an entire identity. You can publish proof on Twitter/Github/whatever, but it's only for one specific key, and it's one key per service, which means you can't only have one identity and multiple services.

Re: Zoom Acquires Keybase

#446

Surprised they took the path of acquiring Keybase and hiring Alex Stamos (ex FB CISO) vs. hiring Moxie Marlinspike and other respectable professionals. Keybase's reputation has become eroded with their recent crypto currency signing nonsense. https://en.wikipedia.org/wiki/Moxie_Marlinspike

Zoom's problems aren't really a matter of having security talent, they're a matter of the company as a whole not prioritizing security. Fixing the former doesn't fix the problem, it just makes for good PR. The latter is a requirement for the former.

Brian Krebs talked about this a bit in the wake of Equifax: https://krebsonsecurity.com/2018/12/a-chief-security-concern...

Assuming Zoom is really trying to fix the problem, it makes a lot of sense to bring in management (and/or teams) who have experience with bringing security into engineering culture, as opposed to individual security experts who may not even want to work for Zoom in the first place.

Re: Zoom Acquires Keybase

#447
post #311

Earlier quoted context omitted.

It seems that we live in an era where if you made bad decisions in the past, you can never be trusted to make good decisions ever again. Even if you own your bad decisions and show lots of improvement. Nope. Once a pariah, always a pariah.

> It seems that we live in an era where if you made bad decisions in the past, you can never be trusted to make good decisions ever again. Even if you own your bad decisions and show lots of improvement. I've seen this turn out for the best literally one time, and that was Microsoft. All the other times the bad company just continues its horrible slide into madness. It doesn't die either, just silently keeps churning…

You see Microsoft’s mediocre reliability making its way into GitHub. Has MSFT changed or are things breaking on the web just more accepted than your desktop?

Re: Zoom Acquires Keybase

#448
post #11

Earlier quoted context omitted.

keys.pub: https://news.ycombinator.com/item?id=22995792 https://keys.pub/

> This project is in development and has not been audited.

Isn't it reassuring, at least, to see that said? Also presumably an opportunity for the right people to help?

Re: Zoom Acquires Keybase

#449

Earlier quoted context omitted.

The statement about lawful intercept can only be considered a blatant lie. It’s a requirement in China and CALEA applies in the US. Europe, India and Australia have their own laws around this.

What makes you think that CALEA applies to Zoom (in the U.S.)? IANAL, but I'm reasonably confident that it does not.

EFF says[1] it applies to Skype, so I think it should apply to Zoom as well.

[1] - https://www.eff.org/issues/calea

Re: Zoom Acquires Keybase

#450

Well, I guess that's it for Keybase. I distinctly remember expressing my worries about them spreading themselves too thin and not really having a clear monetization plan, so an acquihire was the easy way out. Say, anyone got any Keybase alternatives that are focused only on identity management?

https://keys.pub
Post reply on HN