The Git usage was really nice. It's fast and secure. While I didn't use it for most projects (because I want them on github/gitlab for various reasons), it was very useful for backing up machine specific configs and history (using a script and mackup). Knowing that it was well encrypted made me not worry about what was being backed up, if there were credentials, etc.
As for comms, I used the 1:1 chat with a friend for quite a while. While it worked, it's slow. Sending messages is a little slow, sending images is VERY slow. Anytime the app is closed (like constantly on the phone), re-open times were slow (for decryption). Eventually I gave it up and moved those few chats over to Telegram (Because it's secure enough for most conversations).
Telegram is completely cloud based. So all your conversations, except secret chats that are end-to-end encrypted, are stored on Telegram servers in plain text for as long as your account is active. This is why you can get a new device, activate it for your account and get all your conversations back on it from the Telegram servers.
Wire and Signal work differently. They use their servers as a temporary storage to hold your messages until the recipient comes online and then deliver them. Wire also retains the messages for a few days to allow delivery to multiple devices that a user may be using, with each device possibly coming online at different times. Signal doesn't have to support this because it's tied only to a single device, which is your phone.
For example:
- passwords using pass [0] decrypted with Yubikey, and with Password Store [1] on Android (the same repo, the same Yubikey),
- FDE with LUKS decrypted on boot with Yubikey [2],
- encrypted e-mails with Enigmail and K9/OpenKeychain on Android, works with the same Yubikey 4C token! Web Key Directory on own domain for easy e-mail -> key mapping,
- OpenKeychain also has "linked identities" (verifying social profiles) but at this point I consider it barely useful stamp collection,
- for E2E instant messages Conversations [3] with OMEMO.
[0]: https://www.passwordstore.org/
[1]: https://github.com/zeapo/Android-Password-Store
I would LOVE it if I could use keybase to send a copy of my passport to companies (for example) which is nessesary for day to day life, and always done in a redicously insecure way. :(
I just don’t see myself being able to convince some recruiter, or HR person or something to sign up and install keybase just to get a file from me
This made me pretty suspicious, but especially since https://keybase.io/support is just another user claiming to be Keybase support. That's a huge red flag in my book, more so for a security product.
I don't know, but for me this didn't really inspire much confidence.
I've never needed the identity proofs. The teams/chat features are great but I rarely use those either. Maybe when adoption increases, but until then I'm loving my free 250 GB cloud drive and unlimited Git repos up to 100 GB.
Encrypted communication (and files): yes, we use it for Solo, and we also have a public team https://keybase.io/team/solokeys.public
I'd probably pay a few bucks a year (thinking 20) for the base identity service, if we're being frank. Even if the only separation between a free tier and a paid tier is e.g. more service integrations and an uptime SLA... sure, why not?
I also evangelized it pretty heavily and managed to get about 10 other people to use it.
Unfortunately, I ran into some pretty major issues with the desktop clients. They seemed to be coded pretty poorly, eating up massive amounts of CPU and/or RAM, and sometimes even causing my computer to freeze.
In practice, there also didn't seem to be much point to encrypting conversations if there was no password required to actually see them (if someone got a hold of my computer). And (at the time) there was no way to delete a message.
Due to these issues, I ended up installing it.
I'm curious if things have gotten any better since then?
Not sure if the desktop clients have improved, but I haven't had any issues in the last year or so.
It's easier for people to grasp/verify than the alternative ("pure PGP"). They go to /verify, paste in my message, and make sure it confirms as me. Keybase being compromised is outside the scope of the threat model - the threat model is mostly "impostors pretending to be me trying to get you to download potentially harmful files". People have no reason to know who I am but they do have a need to verify I am who I say I am.
Secondly to that, we heavily considered and trialed it a work to unseal Hashicorp Vault. You can add a single identity that is able to unseal, and having that person verify in the keybase-esque method is a great idea.
I do like keybase but practically in my day-to-day life GPG ends up filling all my needs.
We're also trying Keybase out as a family chat channel. I really like the CLI interface and the integration with kbfs, and of course the e2e encryption. We're probably going to stick with Slack for now, though, mainly because it runs on Chromebooks.
Then I started to go to keysignings etc and started using the keyserver infrastructure etc.
And then it took a while and I realized that I never used keybase and removed my account.
Neither Dropbox nor Google encrypts and keeps the keys client side, so not trusting them is probably the right thing to do (also Dropbox has been misleading in the past about their security, so that's another reason one should be careful).
Add me if you care to make a pen pal. https://keybase.io/dfischer
I have a copy of some important docs (taxes, etc.) in my private KBFS.
"At the time of this document, there are very few people using this system. We're just getting started testing. Note that we could, hypothetically, lose your data at any time. Or push a bug that makes you throw away your private keys. Ugh, burn."
And considering that kbfs is one of the more mature parts of Keybase, it has never inspired confidence in me that any of it is really ready for serious use.
Also, I'm curious where machine names were being exposed in Keybase?
That said, it would probably be good if they added a note saying that the device name you choose is public, which is not really clear in the current UI.
i used the filestorage/filesharing earlier and was happy about the git repository support though.
there were however very few of us, and we all dropped it when they jumped on the crypto currency wagon.
I keep asking my friends to join up. Let's try the team feature!
So far, no luck.