Hacker News new | ask | show | jobs
by p4bl0 4034 days ago
The last paragraph of the linked post describes more or less what keybase [1] is.

[1] https://keybase.io/

2 comments

I'm not a fan of Keybase because they encourage a lot of unsafe behaviour:

1. They tell you to trust webpages which claim that their code does not send passwords or private keys to the server – something which would be extremely hard to verify now and even were you to do so now, could silently change in the future:

https://www.dropbox.com/s/teikzwftimeu8nc/Screenshot%202015-...

https://www.dropbox.com/s/1xlvpd8drhix0tj/Screenshot%202015-...

2. They encourage blindly copying and pasting complex commands into a shell:

https://www.dropbox.com/s/5rv7p4mks0qdr7f/Screenshot%202015-...

I have no reason to believe they're doing any of this in malice but it's not good because it encourages people to believe claims which could be made by any phisher and encourages practices which put you at risk if Keybase is ever compromised.

The answer to this, of course, would be a browser-managed crypto API which could provide unspoofable UI indicating that e.g. a private key will never leave the client but in the absence of such an API it feels irresponsible to make similar claims which aren't actually possible.

A little of topic, but if someone would like a invite to keybase let me know :-)
From their CEO[1]:

Heck. In honor of FB's move, Keybase signups are open for the next 24h. Please one account per person. Use invite code: shit-yeah-facebook

[1] https://twitter.com/malgorithms/status/605807605659758592

Hijacking: tweet at me if you can't seem to get the invite from any of the other kind people.

https://keybase.io/justinas

And that is why I have no interest in keybase.io

Well that and they don't solve the only really interesting problem with GPG: how to send a secure email to somebody who doesn't yet have a private key.

For anyone late, I have 9 invites. My details are on keybase: https://keybase.io/lekevicius
And if there's anyone even later, I've got a few as well: https://keybase.io/oddevan