Hacker News new | ask | show | jobs
by gbriel 2236 days ago
Hi all,

I'm the author of keys.pub.

Can the mods change the title of this post at all? This project is meant to be supportive of ideas from Keybase and to promote Saltpack and this title is weirdly disparaging. (Edit: Title was changed, thanks!)

Thanks everyone for the feedback. This project is in its early stages but the goal is to make it easier to manage and securely store keys and secrets.

I'm currently working on hardware key support and FIDO2 integration, so be on the lookout for that.

7 comments

You can reach the mods at hn@ycombinator.com
You might want to put some sort of identifying information about yourself somewhere, on the site or the github project? Maybe a key of some kind? :-)
You're right - Key Management is (very) hard. It looks like you have some nice primitives there, personally I'd love to see you take a few weeks to discuss /gather feedback and refine your plans before copying the flawed Keybase approach wholly. I'm especially skeptical of the idea of linking 3rd party accounts into a global identity descriptor. Iirc there's also been some good Keybase criticism in previous HN threads.
What are the algorithms used for encryption? What are the defaults, do they now match the currently best known approaches?

Also why can't I use the application to do symmetric encryption? Namely the problem with GPG is that its defaults are still ancient (maybefor compatibility with whatever, I don't remember the excuse) and to reach the currently best settings one has to jump many, many hoops, even for simple task of symmetric encryption.

Sure, no problem. I've used the HTML doc title but I had to shorten it to fit 80 chars. If there's a better—more accurate and neutral title—let us know.

(Submitted title was "Keys.pub – Keybase Without the Cruft".)

Edit: I changed the title to something the author suggested in an email. Before that it was "Keys.pub – Manage keys, sigchains, identities, signing, encryption, passwords".

That's great, thank you.
Your project is very cool. Could you help me fix my account though? I messed up two of the IDs: mfrager@github & mfrager@reddit. Will these be automatically purged from the keys.pub server after a certain amount of time for being invalid?
You can revoke, and generate them again, perhaps?
I was able to do that, yes.
I am indeed glad I saw this comment, because as someone who likes Keybase, when I saw the title, I was like "ugh". Hopefully dang or sctb will edit it soon!