Keybase 4.0
github.com
github.com
I've had an account for a while but don't really have any reason to use it.
Seems like they're pivoting towards being a Slack competitor. Maybe if they open sourced the server portion it could be a chat solution that OSS projects can feel okay about using.
I use it for personal communications too, so it is nice to use the same secure messaging platform for both work and personal and switch back and forth from computer to phone easily. I do wish the server portion and apps were opensource though.
I wonder now could it be used for corporate secret management. I wouldn't like to use cloud solution for that and on existing on premise solutions do not cover all scenarios I need (on-boarding one of them, or guests).
I get it that they want to get usage telemetry, but it's ridiculous for a security focused app to force itself like that.
https://github.com/keybase/keybase-issues/issues/2380
https://github.com/keybase/client/issues/8264
You need to know the password and be in possession of a device already trusted to confirm a new device, right?
You certainly need to be logged in to keybase on an existing trusted device, though.
Having 2FA with Keybase would be similar to having 2FA with a local password safe like Keepass. Yes, you could implement 2FA. However, you would have to rely on an external service, and if people have your password and can modify the software, they can simply comment out the 2FA check and they can decrypt your password safe.
The entire security model of Keybase is based on having all data encrypted at all times. Adding 2FA would add some false sense of security, which doesn't affect the encrypted data at all.
Why not use an M-of-N / 2-of-3 encryption scheme where the user can optionally have Keybase protect one of those keys via a 2nd factor. The user would keep the 3rd in the form of a yubikey or simply written down and physically secured.
This could improve both usability and security and Keybase itself still doesn't have access to your data.
That's not true. You can verify the time based codes or do u2f yourself. You don't need a third party for that.
This means I haven't wanted to even suggest trialling it at work, so I haven't used the teams feature at all and without that it's basically an encrypted cloud storage mechanism with an interesting Git integration.
T_T