Live data from Hacker News

Zoom Acquires Keybase

keybase.io

511–520 of 751 posts

Re: Zoom Acquires Keybase

#512

Earlier quoted context omitted.

Which already did some things wrong even though Keybase is around for a few years.

Care to elaborate? Just curious...

https://news.ycombinator.com/item?id=22997245 and requiring gnome-keyring on Linux are issues for me.

Re: Zoom Acquires Keybase

#513
post #40

Given the security concerns around Zoom, and the apparent lack of QC that might have prevented those concerns, this news is appalling. I love Keybase, it's used by many people, but I suspect it will now die a quick death. More accurately I suspect it will slide into a coma - not quite dead, but not in wide use anymore either.

why not look at the problem the other way around? I don't have much respect for zoom's security practices, while I do have much respect for the keybase team. Perhaps this is Zoom's way of admitting that there is no way they can just solve the problem internally by keeping doing what they're doing and they need to get some fresh blood and build upon good practices designed outside their current culture.

I agree. I'd bet all the cash in my wallet that this was Zoom doing a talent acquisition, to bring a team of crypto experts on board.

Re: Zoom Acquires Keybase

#514

Earlier quoted context omitted.

Is wayland support even a femto blip on Zoom's radar ?

They do keep saying "multiplatform", but I guess that's Windows/macOS/iOS/Android, not Linux. They're not the only ones though, this is what most companies call "on any device".

the problem is wayland. not linux with X11.

Re: Zoom Acquires Keybase

#515

Earlier quoted context omitted.

Zoom is only a pariah on Hacker News.

microsoft too. people here still talk about "Embrace, extend, and extinguish" every time there's any good microsoft news.

It's far easier falling back on tired memes and muscle memory, than rewiring biases.

Re: Zoom Acquires Keybase

#516

Earlier quoted context omitted.

It seems that we live in an era where if you made bad decisions in the past, you can never be trusted to make good decisions ever again. Even if you own your bad decisions and show lots of improvement. Nope. Once a pariah, always a pariah.

Zoom is only a pariah on Hacker News.

I have heard from multiple friends that their employers banned Zoom after the negative press. And that's quite a few non-tech companies too.

Re: Zoom Acquires Keybase

#517

It's kinda ironic that Keybase disappears into Zoom the day after Matrix/Riot enabled end-to-end encryption by default, with cross-signed device verification similar to Keybase's concept of connected keys - see https://blog.riot.im/e2e-encryption-by-default-cross-signing... . In other words, a fully open source (and open standardised) alternative continues to exist in the form of Matrix. [disclaimer: project lead for…

The thing I like about Keybase is that keys are always generated client-side and never leave the client, and all of the functionality associated with adding/removing devices is done in a way so that there's no way for a server to tamper with it (aside from denying service). Is that true in Matrix? Several services advertise themselves as "end-to-end" encrypted, but then when you poke harder it turns out either there…

Yes, Matrix is properly end-to-end encrypted (with all keys generated clientside) and has been independently audited as such: https://www.nccgroup.trust/us/our-research/matrix-olm-crypto.... We have gone to huge efforts to prevent MITMs via device verification and cross signing - which specifically addresses both problems of a) losing chat history when you move between devices (via https://github.com/uhoreg/matrix-doc/blob/e2e_backup/proposa...) and b) requiring cross-signing when you log in on a new device, to spread trust to new logins, as per https://github.com/uhoreg/matrix-doc/blob/cross-signing2/pro....

All keys are stored clientside, with the exception of if you enable serverside key backup, when they are then encrypted and optionally stored serverside to allow you to recover your history if you lose all your devices.

Re: Zoom Acquires Keybase

#519
post #372
post #319

Earlier quoted context omitted.

Keybase was dead as soon as they took VC money. Their original purpose — tying identities to keys — could have been a nice small non-profit. But there aren't fortunes to be made from managing GPG keys, so they had to pivot into shark jumping.

We have letsencrypt and permanent.org as non-profits. An idea of a identity and key non-profit sounds like another critical piece we would need for a free, open web

Seems a bit early to call 'permanent.org' a critical piece, even if it succeeds all it's doing is cloud storage.

Re: Zoom Acquires Keybase

#520

For years people have been begging Keybase to allow them to pay them for the service and Chris Coyne always refused. Now they've lost their independence and they're owned by a communication company that has [edit: the majority of] its dev team in China. I use Keybase to talk to my friend in China since it's one of the few services they don't block. This is a pretty disappointing outcome.

I am curious: do they block Zoom?

Well yes but no. The block zoom.us but there is zoom.cn

This is likely related to both nations having rules that allow only their own agencies to wiretap.

Post reply on HN