Live data from Hacker News

Zoom Acquires Keybase

keybase.io

641–650 of 751 posts

Re: Zoom Acquires Keybase

#641
post #325

Earlier quoted context omitted.

https://pgp.mit.edu/

Linking to this is evidence that you don't understand the entire value of Keybase. PGP sucks.

Why? PGP works. (That alone puts it above its supposed alternatives.) It has existed for 30 yrs. That's 30 years of being exploited and patched.

PGP (GnuPG at least) is lightweight. I don't need an Electron dependency or a multi-megabyte chat room in the same application (address space too?) that supposedly keeps my private keys safe.

PGP is spoken by everyone, every programming language, having implementations on even ancient operating systems and architectures. Every email client worth its salt can use PGP. Emacs can decrypt and encrypt GnuPG-encrypted files seamlessly; other editors have plugins to do the same.

Re: Zoom Acquires Keybase

#642
post #641

Earlier quoted context omitted.

Linking to this is evidence that you don't understand the entire value of Keybase. PGP sucks.

Why? PGP works. (That alone puts it above its supposed alternatives.) It has existed for 30 yrs. That's 30 years of being exploited and patched. PGP (GnuPG at least) is lightweight. I don't need an Electron dependency or a multi-megabyte chat room in the same application (address space too?) that supposedly keeps my private keys safe. PGP is spoken by everyone, every programming language, having implementations on ev…

It sucks because the UX is so bad that people don’t use it, even when their lives depend on it. [0]

Even when they do use it, it’s easy to mess up.

The biggest flaw though is that in person key signing parties were never a viable or realistic thing for identity verification and web of trust based on that works poorly as a result. The use of multiple signed public social media accounts for identity instead as a way to fix this was Keybase’s main innovation.

For UX, even Snowden couldn’t get Greenwald to set up PGP and after multiple attempts Snowden eventually gave up and tried Laura Poitras with better results, the burden on the user is too high.

[0] https://moxie.org/blog/gpg-and-me/

Re: Zoom Acquires Keybase

#643

Earlier quoted context omitted.

Isn't the US actually at least as bad if not worse? Thanks to Edward Snowden we know without speculation that the US "is hostile and leverages their power to censor/collect communication information from companies and their people without checks on this power" (ok, supposedly there is secret judges that secretly check on this power, but that doesn't really do any good does it?). The USA also "pressure companies to ha…

People don't get disappeared for actively disagreeing with the government.

Not until the second term.

Re: Zoom Acquires Keybase

#644
post #25

> Zoom does not and will not proactively monitor meeting contents, but our trust and safety team will continue to use automated tools to look for evidence of abusive users based upon other available data. > Zoom has not and will not build a mechanism to decrypt live meetings for lawful intercept purposes. > We also do not have a means to insert our employees or others into meetings without being reflected in the part…

Well, yeah, duh. What do you expect them to do? Hire a PMC and fight a war with the police when they come around to raid the server room? Go into hiding so that the security agency can't steal the upgrade signing key from them? We can't expect all of the internet to operate like Wikileaks and The Pirate Bay. If the justice system is broken, then the people aren't safe.

> We can't expect all of the internet to operate like Wikileaks and The Pirate Bay.

Why not? That's just what it takes.

> If the justice system is broken, then the people aren't safe.

It is, and they are. After 50 years under the heel of the war on drugs, how is it not 100% obvious?

Re: Zoom Acquires Keybase

#645
post #40

Earlier quoted context omitted.

why not look at the problem the other way around? I don't have much respect for zoom's security practices, while I do have much respect for the keybase team. Perhaps this is Zoom's way of admitting that there is no way they can just solve the problem internally by keeping doing what they're doing and they need to get some fresh blood and build upon good practices designed outside their current culture.

It seems that we live in an era where if you made bad decisions in the past, you can never be trusted to make good decisions ever again. Even if you own your bad decisions and show lots of improvement. Nope. Once a pariah, always a pariah.

The shit that we're complaining about happened like three weeks ago!

Re: Zoom Acquires Keybase

#646

Earlier quoted context omitted.

Secure filesharing and chat, for starters. Secure digital wallets tied to identity. It was a wallet platform I'd actually be interested in.

Encrypted git repos with ties to team chat...

That's what I've been using it for lately, it was becoming my main Git platform. I'm sad that this looks like the end of that.

Re: Zoom Acquires Keybase

#647

I would participate in (and could provide resources to) the creation of an open foundation that had as one of its goals the writing of an open source keybase API[0] compatible server. If anyone else is interested, please contact me directly (email in my profile). [0] https://keybase.io/docs/api/1.0

Maybe try approaching the keys.pub devs?

Re: Zoom Acquires Keybase

#648

Earlier quoted context omitted.

At this point, I'm confused, and I'm not sure what point you or the other commenter are looking for me to concede. Zoom is paying some security consultants, pushed out some product updates, and bought Keybase, so it's a story book ending?

Just as your comment was aiming to narrowly point out a logical fallacy in the parent comment, I'm pointing out a flaw in your own: I disagree with your claim that investing in security practices is just theater, and that more concrete efforts in the same direction are irrelevant. The concrete efforts are Bayesian evidence that the newer investments are more than theater.

I didn't claim that. I believe in investing in security. I'm a security professional.

Re: Zoom Acquires Keybase

#649

Earlier quoted context omitted.

At this point, I'm confused, and I'm not sure what point you or the other commenter are looking for me to concede. Zoom is paying some security consultants, pushed out some product updates, and bought Keybase, so it's a story book ending?

I am not looking for you to concede anything. You said nothing has been done to show you that the calculus of their priorities has changed and I listed some things that could possibly show that. It’s up to you if you believe that is significant enough to convince you. Frankly, I don’t care if it does or not. I was just providing some visible signs of investment.

I didn't see you respond to my comment in this thread unless you post under two different accounts.

Re: Zoom Acquires Keybase

#650

Earlier quoted context omitted.

Is this a joke? The bulk of the labor movement happened before 1970, and it was not because workers were so well-treated and well-compensated that they had a lot of free time on their hands. I'm a big fan of business and entrepreneurship, but let's be clear here: there is a reason we invented government. There was never a time when we could 100% count on the beneficence of business leaders to advance social goals. Ed…

Of course, there have always been bad businesses. The difference between pre-1970 and now, is that we've not only socially legitimized the maximization of profit, we've also all but legally mandated it. Now even "decent" business leaders like the CEO of Costco have to continually answer to their shareholders as to why they're not lowering wages and reducing benefit--and in Costco's case, the shareholders may try to t…

> The difference between pre-1970 and now, is that we've not only socially legitimized the maximization of profit, we've also all but legally mandated it.

I'm sorry, but this is just not true. If it was legally mandated, then the Costco CEO would not have been able to resist such shareholder demands. Your example proves the opposite of what you think it does.

Nothing has changed in the legal structure of corporate governance since 1970. Do you think that investors never demanded greater returns from business leaders prior to 1970?

They can still demand all they want, but the law remains clear today that corporate directors and managers have the power to run the business as they see fit, and shareholders' sole remedy for their disappointment, in the absence of outright fraud or gross negligence, is to sell their stock.

In February 2014, Tim Cook was the CEO of one of the most valuable companies in the world. At Apple's shareholder meeting, he directly told his shareholders that he does not even consider ROI in some of his decisions. Legal consequences to Apple and Tim Cook for this statement? Zero. He's still CEO. Because there is no legal mandate to maximize corporate profits.

Honestly, by buying into this myth that the law changed in the 1970s, you're lending power to a fake idea that you seem to be opposed to. There is a group of people who wish such a mandate existed, and by acting like they're right, you're kind of helping them.

Business leaders might make anti-social decisions because they feel competitive pressure to succeed in a marketplace where customers are free to choose and are price-sensitive. That's not nearly the same thing as saying that corporate governance law forces them to make such decisions. It doesn't.

Post reply on HN