Live data from Hacker News

Zoom Acquires Keybase

keybase.io

711–720 of 751 posts

Re: Zoom Acquires Keybase

#711

Earlier quoted context omitted.

If people have bad passwords, that makes brute force recovery of the private key on a Keybase server plausible, right? At least a lot more so than the whole key from scratch. I'd assume that a machine generated key has more entropy than any password that a human can memorize. If sharing a password-protected private key is perfectly safe, why bother having them? Why don't PGP users just password protect everything? Ab…

I think people are confusing things a bit here. Sure, you can protect your pgp key with a password, but I don't think that adds a whole lot of security to your uploaded private keys. When you upload a pgp key to keybase, it encrypts the key again, using your keybase device key. So its double encrypted, basically. The keybase model revolves around devices. Device keys are private keys that are tied to a particular dev…

Thanks for succinctly clarifying.

At the end of the day, your keybase device key is, itself, simply encrypted with your keybase password. The point I've been trying to make clear is:

> Your private keys are as secure as any private, encrypted piece of data that you might send out over the wire, so long as your devices are secure, that is.

Re: Zoom Acquires Keybase

#712

Earlier quoted context omitted.

Just as your comment was aiming to narrowly point out a logical fallacy in the parent comment, I'm pointing out a flaw in your own: I disagree with your claim that investing in security practices is just theater, and that more concrete efforts in the same direction are irrelevant. The concrete efforts are Bayesian evidence that the newer investments are more than theater.

I didn't claim that. I believe in investing in security. I'm a security professional.

Good catch, that was a misphrasing in my comment. I meant to say _Zoom's_ investments in security, not security investments in general.

Re: Zoom Acquires Keybase

#713

Earlier quoted context omitted.

> was it literally 100% for money or did want of these goods play a role: > cotton, silk, indigo dye, salt, spices, saltpetre, tea, and opium. Surely access to those provides some benefit other than making money, which it also did for them. This is an utterly meaningless distinction. Money is fungible with all of those goods.

I am not sure you are using fungibility completely correctly because the goods have a condition, are perishable, they can be bartered or traded or maybe are fungible with respect to each other but are not literal money and literally interchangeable with money. Anyway, if you want to go down that path you can easily conclude that literally any good or activity is just money, that you live a money-dominated life and we…

Yes, that's exactly the point...it's meaningless to say (as you did) that the EIC wasn't motivated by money but instead motivated by goods. Even leaving aside that they sold those goods for money....the distinction is meaningless, as money is just a store of value and lubricant for the exchange of goods (and services).

Re: Zoom Acquires Keybase

#714
post #82
post #28

I'm seeing a certain pattern here, aren't we all just fooling ourselves? Isn't this just all inevitable? Aren't all these startups just lining up all in the hopes just to get acquired? I guess when we see VC Funded™ on any startup what it _really means_ is that: "We are prioritising a return for our investors even if it means violating our mission statement".

I think it is inevitable, yeah. But, this wouldn't have been a problem if the product itself was decentralized. For example, if it was optional to connect to the Keybase network to begin with. Imagine a keybase-type app that is built on web of trust rather than centralized servers.

Wait what? That's called PGP. And people like to hate on it because it's a decentralized web of trust. The whole point of Keybase is to pave over the problems with web of trust by creating a social identity layer that more accurately reflects how trust relationships actually form.

An open source social identity attestation layer that people can operate and federate. Now that sounds cool!

Re: Zoom Acquires Keybase

#715

Earlier quoted context omitted.

Could you point to examples that support the existence of this alternate history of which I've never heard of?

To be clear, you are asking for examples of historical companies that were profit motivated?

No you’re confused. He’s asking for a history in which there is no company motivated by anything other than profit. Since there exist many companies motivated by things other than profit, no such history can be provided. Hence the GP is wrong. Hence the irrelevance of downvotes on this cunty website

Re: Zoom Acquires Keybase

#716

Earlier quoted context omitted.

I am not sure you are using fungibility completely correctly because the goods have a condition, are perishable, they can be bartered or traded or maybe are fungible with respect to each other but are not literal money and literally interchangeable with money. Anyway, if you want to go down that path you can easily conclude that literally any good or activity is just money, that you live a money-dominated life and we…

Yes, that's exactly the point...it's meaningless to say (as you did) that the EIC wasn't motivated by money but instead motivated by goods. Even leaving aside that they sold those goods for money....the distinction is meaningless, as money is just a store of value and lubricant for the exchange of goods (and services).

It's not a meaningless distinction. The goods are consumable. The British public didn't want access to spices as an investment vehicle. Using them was a quality of life improvement.

Re: Zoom Acquires Keybase

#717

Earlier quoted context omitted.

Yes, this was exactly how I mentally categorized these two companies as well. My first reaction was: it can't be that keybase can it? Huh, well maybe I'd sell my principles for that much money too, oh well. Maybe some keybase employee will end up being a whistleblower sometime soon though.

Well, they are pitching this as bringing secure stuff to the masses. So it's arguably not all that inconsistent with what Chris etc have been saying about Keybase.

Honestly if at this point Zoom hasn't lost all credibility in your eyes I don't know what to say.

Zoom already has end to end encryption according to some of their other press releases and public statements (we know they don't), so why on earth would you believe this one?

Re: Zoom Acquires Keybase

#718

Earlier quoted context omitted.

Well, they are pitching this as bringing secure stuff to the masses. So it's arguably not all that inconsistent with what Chris etc have been saying about Keybase.

Honestly if at this point Zoom hasn't lost all credibility in your eyes I don't know what to say. Zoom already has end to end encryption according to some of their other press releases and public statements (we know they don't), so why on earth would you believe this one?

I guess that it's because I liked Chris and his team, and so I'm trying to be generous.

Re: Zoom Acquires Keybase

#719
post #669

Earlier quoted context omitted.

So, yeah. Zoom did bad stuff. But Keybase is designed so that all those things would obviously be detectable (Keybase client code is open source), and the ways in which the Server could mess with data are much restricted. If that spreads to Zoom, there's a chance it'd be a good service in a year or two. PGP keyservers have a fundamental issue that demands a solution like CT logs or Keybase-style merkle trees. The onl…

They are also kinda buying a social graph of mostly IT and security professionals, sprinkled with some journalists (and not the kind that usually does the "10 things" articles) and general tinfoil hats. My tinfoil hat tells me this information could be somewhat valuable to their Chinese overlords...

Yes, it's Zoom's Chinese connections that rule them out, for me.

Re: Zoom Acquires Keybase

#720

Earlier quoted context omitted.

Hi! I use Matrix a lot, but a privacy-sensitive group of my friends recently switched to Keybase largely due to the per-room/per-message retention policies. This might be a good opportunity to convince them to jump ship, and I know something similar has been in the works for Matrix, but do you know where it is on the list of priorities? (Congrats on the cross-signing release though, it's been a long time coming and i…

Hijacking this: Does anyone know if there’s a Matrix client (out or in dev) that has the UI/UX of old 1on1 messengers (ICQ, MSN) and not chatrooms (IRC, Slack)? Specifically not the weird list of bubbles on the side, but instead a list of accounts/rooms and a window per chat.

I'm not sure I understand, because neither IRC nor Slack have the bubbles thing, that's something you'll see in Facebook Messenger or Whatsapp. Also, Riot doesn't have those bubbles, and has the list of accounts/rooms on the side.

However I'm not aware of any client that opens conversations in different windows.

Post reply on HN