Keybase cancels Stellar token airdrop
keybase.io
keybase.io
Keeping cryptocurrency keys secure has always been a challenge. Keep them too well, lose your money; keep them not well enough, someone can steal your money. It's a thin line to walk.
Keybase wants to make encryption user-friendly, and keeping cryptocurrency keys secure fits very well to that purpose. This is probably the least painful way I've kept crypto private keys.
Besides, the wallet is pretty functional, and is integrated to an app that's already sync'd to my phone and computer. It's without fuss and just works. Compare that to yet another app which I don't know, need to evaluate, don't trust to keep my secrets, or won't share them across my devices. Here, it's painless.
I personally knew Stellar already, but as a technical user (which I feel is a natural demographic for any crypto to start to get early adopters), this brought back Stellar in my mind and renewed my interest (or would've interested me if I hadn't known it).
Besides, I quite like Stellar as a cryptocurrency for payments: fees are low, and confirmations are near instant. And I'm not even naming the fact that it natively allows you to keep fiat money as a Stellar asset instead of exposing yourself to the risk of losing value to fluctuation. (Though there are caveats, but the infrastructure is there natively to build very useful things.)
I don't think this was quite bad a move as some make it out to be.
Did you just get really excited by their enthusiasm?
I love the idea of keybase but in practice I never had contact from strangers suddenly using GPG, so it felt more aspirational than useful. But with zero interest in cryptocurrencies any tiein/integration was just wasted on me.
Of course, absolutely ZERO crossover between that kind of utility and this Stellar thing. I'd like them to find more life-improving nuggets of utility like that instead. Find more places in your life where you want something encrypted ad-hoc but don't want to memorise your GPG key ID. Any time someone would normally whisper to tell you something could be a candidate.
module "iam-user_foobar" { source = "terraform-aws-modules/iam/aws//modules/iam-user" version = "2.3.0" name = "foobar" pgp_key = "keybase:foobar" force_destroy = true create_iam_user_login_profile = true create_iam_access_key = false password_length = "${var.password_length}" }
This sets the users password then PGP encrypts the password with their keys from keybase. You can then use the module output to get the pgp encrypted password and pass it to the user (manually, email etc...).
Otherwise it will put the password in plaintext in the state, not a massive issue as you can set it to require changing next login. But eliminates the even slight chance of leakage.
I use git-crypt for storing secrets in git repositories.
In the future, I'll probably switch to this, though: https://github.com/bitnami-labs/sealed-secrets
Nah, not really.
Unsophisticated users tend to keep their crypto on the bigger exchanges, which means someone else manages their keys.
Sophisticated users tend to use (cheap) hardware wallets or at least understand paper backups of keys and passphrases.
How-tos and warnings are exchanged ad nauseam on crypto Twitter and crypto blogs.
I imagine Keybase would have moved this forward about as far as they've moved forward GPG / PKI for the general user. (Not much)
This is mostly Stellar trying to gain some marketshare since they haven't made much progress elsewhere.
I could imagine transferring some lumens to a friend for my share of dinner, but only if my friend is actually going to want lumens. Even if they're a keybase user, they're hardly going to be excited if I transfer them tokens that they are then, themselves, going to find difficult to exchange for goods or services.
If Keybase had to cancel this because all of the people signing up were after the lumens to speculate, maybe they should work on making the currency actually usable and liquid. I'm not interested in speculating; if I could use this to buy something down the supermarket, I'd be very interested.
I went from about 25 followers to over 50 in approximately a month, after being there more or less from the launch. Those first 25 were largely people I've personally met in real life. The rest are entirely fakey.
This has just forced them into coming up with a solution now rather than waiting a few more years when the network's larger.
So yes, it's had an effect here as well.
They should have just given coins to existing active keybase users. They would have had healthy increase in users based on regret and fear of missing out again.
The cryptocurrency wallet feature is not useful for me, but it hasn't really impact me in any negative way, so I don't mind it.
Is it "not particularly strong" against nation state adversaries? Or can any script kiddie with a toolbox break it?
These are why I’d never use Keybase to chat even though it’s better than Signal from a usability perspective.
1. For _other_ Keybase messages without PFS it's open season. Say Alice sends you a normal Keybase message right now about murdering her husband Bob. Keybase will ensure Alice provides keys to decrypt that message for your iPad, iPhone, the MBP and your old Thinkpad. This way you can read the message from any of your devices. Convenient.
Spooks can record Alice's encrypted message and get it back if they at /any/ subsequent point obtain the Keybase device key for your iPad, iPhone, MBP or Thinkpad, for example as a result of seizing it for some other reason. Maybe it's next week, or next month, or next year, or in ten years time. The device may never have received these messages, maybe it was switched off, or they've since been removed. Doesn't matter until the key is replaced.
In contrast a PFS system would discard the keys as soon as they'd been used to decrypt stuff, and agree new keys for subsequent messages. Signal's double ratchet does this for every single message back and forth. "I killed Bob" (new key) "You did what?" (new key) "I was so angry I just stabbed him" (new key) "Shit. Now what?" (new key) and so on.
2. Actually though "exploding" messages are another Keybase compromise. Visually it seems like they blow up instantly when the time limit expires right? Gone. But cryptographically it takes up to a month or so for the bomb to "explode". Suddenly it's more like you wrote the message in chalk on an outside wall rather than it instantly "exploding". This was easier for their multi-device large group stuff. That's right, your 1 hour exploding message about the lawsuit was optimised for cases where you'd need to share it with a 500 person group who all have multiple devices. That makes sense right?
Always with "exploding" messages the actual expiry is implemented by some software explicitly deciding to throw ephemeral data away. Signal's ratchet makes doing so constantly the unavoidably the correct software engineering choice, otherwise your code leaks endless old keys because of the ratchet. But Keybase only throws away "ephemeral" keys after at least a week, chances are if you're a multi-device user there are some fortnight old "ephemeral" keys in one of your systems right now. A Keybase exploding message you got on the 1st of December with a one hour "fuse" on it is still actually readable now using keys from that device. Huh. The Keybase UI doesn't make that apparent at all.
Compared to WhatsApp and Signal that's bad, they both use a well-thought out security model.
As for Telegram, well, Telegram is Telegram.
It's up to the reader to decide what "theoretically unlimited time" means in this case with regards the adversary.
I guess being a free keyserver and identity verification service (they frequently check all your signed messages across all linked web properties) just isn’t a viable business model.
I agree, although I'll freely admit I haven't tried to use the other features all that much.
However, I do find myself a little uneasy with the key management aspects too. The official keybase CLI package being ~500mb when installed, the background server, etc concerns me. The alternative of using curl with a heap of largely inscrutable commands seems unworkable¹.
I wonder if anyone has worked on an alternative, and easy to inspect, client to interact with keybase for just the key management aspects?
1. I largely used the curl method, but suspect very few others would.
I think we're in agreement that a huge binary client is worse, but I'm suggesting there may be a middle ground with a small/simple open source client just for the key management aspect. That said, it does of course rely on people actually looking at the source of such a client ;)
A small client is still going to send the same payload.
"can you just email me a copy of your passport photo and these 5 other things i need to completely verify your identity to banks and so on"
errrr .... no ?
Individuals are arguably not fussed. But surely business can get behind some better levels of encryption / verification ?
A hard problem with email is that there is a boundary inside the address itself. How can anyone know this is steve@example.com? Maybe an outside authority can verify it's really @example.com but if I thought this was Steve and it's actually Tammy then I'm unhappy anyway.
For your purpose you probably don't think you care. You don't know whether custserv@example.com or customer@example.com or jenny.smith@example.com is the right email address to be telling you that your complaint is being confidentially processed anyway. But what about steve-the-plumber@gmail.com ? Does it matter if this is really from Steve or the mail actually came from tialaramex@gmail.com ?
Because the web doesn't have this authority boundary the Web PKI can actually assure you of a meaningful fact to a worthwhile degree. This is really https://example.com/. Is example.com really your local plumber Steve? Are they legally authorised to repair your gas appliance? Are they crooks? We can't answer those things. But we can tell you this is definitely example.com
Because growth. Either by VCs insistence, or founders ambitions.
Or that they hired X people to build the identity bit and needed to build more to keep all funding and staff.
If they had separated it more under a suite of products then it would have been ok, instead of bundling it all in one client and service.
All I need is the web page for identity and the CLI for encryption and verification.
I don't need a heavy electron UI always running on my devices.
Keybase had a certain quiet dignity to it. Everyone listed there was easily identifiable to me so there was never any confusion over who I was talking to, and it was easy to turn the notifications right down. We even used it for team chat. Keybase had some appeal as "crypto means cryptography." Introducing a cryptocurrency shattered that quiet careful image.
I wouldn't say cryptocurrency integration and the surrounding song and dance is the reason we switched to Slack for team chat, but it is the reason I stopped advocating for staying on Keybase.
I hope this move is part of shoring up the "quiet reliable tool" image I had of Keybase. Among the 1e6 chat programs I have to use to talk to everyone, Keybase was the closest to feeling quiet and reliable, and I hope it does again soon.
It seemed kinda novel and fun, but I've never really been interested in cryptocurrency, and I have no idea what Stellar is good for, or even if I care more than my ability to cash it out as USD.
Overall Stellar feels like a distraction from Keybase building out their core platform and improving the user experience to the point where I'd even think of trying to get my non-technical friends to use it. And if they want to attract the masses (maybe they don't), they need to integrate traditional payments, in local currencies. (Yes, I know Stellar can act as an exchange medium, but people will want single-click ability to transfer fiat currency in/out of their bank account.)
It's not super widely known, but Extinction Rebellion NYC relies highly on the whole keybase suite of tools, and I've heard they mostly like it (and they're def not predominantly technical). NYC is also likely inspiring other XR global chapters, but hard for me to speak to that.
November airdrop required providing phone number.
Does anyone know how successful this was at getting people on to the platform? I had the same number of friends on Keybase before the airdrop was announced as I do now.
I was on Stellar already and received both airdrops so far. About 55$ in total at the current rate. It peaked out at ~65$ a few weeks ago. It's a nice gesture; much appreciated. I already earned (as in I worked for it) some XLM through other means so I have a nice stash that I'm HODLing.
Keybase is actually a nice product. It lacks a few of the niceties of Slack but it has made nice progress over the last year. Setting up a team is quite easy and right now they are not really charging for it. I would consider it for a small team.
I guess it doesn't really affect me that the userbase is 50% crypto speculators. I don't have to interact with them.
They supply the tokens, and presumably are paying Keybase for access to their userbase (and non-removable ads for their coin on almost every single keybase profile page).
I also don't see how this works as a pump-and-dump to turn their ICO into actual United States Dollars. With the vast majority of people wanting hard currency instead of a cryptocoin... I feel like that can only drive the price down. Looking at some charts (https://finance.yahoo.com/quote/XLM-USD/), XLM has been trending downward for a year. There is a small spike right around the time of the first airdrop. Maybe that was all they needed to make some money?
I don't really know but it all seems shady to me. I have decided not to hold this against Keybase; it's an experimental app for "stuff" that I don't have to pay for. I am still suspicious of cryptocurrency in general, and especially ones I haven't heard of like Stellar.
I truly think they are simply okay with a $200-500+ CAC because it's all found money anyway (that dumping on an exchange would ultimately disclose and hurt future potential profits).
If they can make it actually get adopted, they stand to make a lot more—but it's a huge if.
https://www.gov.uk/guidance/check-if-you-need-to-pay-tax-whe...
Hell, even with a cash allowance, if it exceeds a certain value during the year, you owe gift tax (though it's obviously difficult for the IRS to figure out about your allowance, especially if you never put it in a bank account).
Looked it up now and this explains why I had a lonely U2 album in my iMusic when I finally got another Apple product after 7 years.
The original design of the airdrop seemed designed to reward mostly/only existing users, but with the in for existing HN/GitHub users who might join. Basically it was narrowly intended to be for developers. The redesign to "avoid" abuse involved phone numbers, and allowing anyone with one in, which was the real floodgates.
It’s about user growth and attracting more people to the platform. Yeah git repos seem a little random, but you can’t have huge user growth from just offering identity verification.
That said sharing files from the command line is super-convenient. I just never remember it's a possibility!
Still no way to get it off of there, save for a total account reset that wipes all data and connections. No warning or notice when you are offered to generate stellar keys for a wallet that it’s going to separately use your keybase key to also make a signature and post this permanent, non-removable ad to your profile page.
https://github.com/keybase/client/issues/20022
Almost two months ago the Keybase guy said they were going to allow people to remove it; no progress as yet. I wonder how much they got paid by Stellar to make their client app abuse a user’s trust like this. I hope it was a lot, I used to really like the idea behind keybase.
Really the only thing missing is a way make semi-anonymous payments (sort of like cash).
Disclaimer: I sold the XLM I got years ago for XRP. I didn't participate in the recent giveaways.
Assumptions regarding the original purpose of the air drops:
1. Stellar's goal was to spur use and circulation of XLM.
2. Keybase's goal was to increase their user base.
I think they both took the easy way out: Give-away and pray.
If Stellar wanted to increase circulation, they should have rewarded transfers and payments. Keybase could have supported that effort via their infrastructure and possibly convinced their existing user base to become more active on their platform. I suspect that they'd have gotten much farther by demonstrating value to existing customers than trying to attract (buy, in the basest sense of the term) new ones.
Opportunity lost, it would seem.
It doesn't matter what they would have rewarded, it was going to be gamed. This is a fact of life on the internet.
I use keybase with two profiles. One which is linked to my IRL identity. And one which is linked to my internet identity.
The Stellar offering seemed really odd to me - because it seemed so outside of its core functionality. Almost scammy.
Then I read an article on Ars Technica about a flood of scammers and that sort of connected the two dots. The Stellar offering seems to have flooded them with more “people” than they can handle.
If I find someone on Twitter or elsewhere posting artwork I like and I want to hire them, then Keybase makes the rest quite simple: easy to confirm identity, discuss details over chat, share files, and finally make payments.
Seems like a platform with great potential that's horribly misunderstood.
I hadn’t considered Keybase as a platform for freelance work. If Stellar is supposed to tie in with their Teams, Files and Git offerings - that makes much more sense.
But the airdrops just felt off to me. Last time I checked the github issues page - I saw half dozen issues raised just asking for airdrop info.
And what are Lumens good for, anyway? Are there any ~anonymous exchanges with Bitcoin, etc?
Stellar looked promising a few years ago, but doesn't seem to have gone anywhere.
I never had much interest in trading or investing in Bitcoin.
But I do earn a little Bitcoin, now and then. And I like to play with VPS, and the occasional server. So I probably spend maybe $100-$200 in Bitcoin each month.
And given that I do all that ~anonymously, it'd be far more hassle without cryptocurrencies.
This can even happen years after you've deleted the wallet key and moved on to a new wallet.
So sure, all that Mirimir spends is linked. But nothing is linked to my other personas, or to me in meatspace.
Edit: Bitcoin Fog was used to mix thousands of Bitcoin from at least two thefts. In 2013 from Sheep Marketplace, and in 2015 from Bter. And as far as I know, none of that was ever traced.
That's just one of the mixers that I used. So I'm not at all worried.
> We can recommend Monerujo on Android and Cake Wallet on iOS. These wallets integrate natively with XMR.to.
I don't use either Android or iOS.
Do you recommend a suitable Linux wallet?
Keybase was a nice protocol/command-line tool to prove identity, but it was over as soon as they flipped it to being some wannabe Dropbox with Adobe-quality autoupdate, then wannabe Slack, then some shitcoin-powered Twitter DM spam.
Also, interesting that the same user acquisition strategy works so often. Paypal gave away money to acquire (it's also in Zero to One but you'll remember it when it came out), Coinbase did, Jet did, etc. I'm quite happy with this strategy to be honest.
If I'm getting all my Stellar at once next week, I can complete my collection of Avengers Lego sets.
OK, so it's not WAAAAAAGGHHHH! But it's the same small pieces of crack cocaine. Although the WH40K lore is so much more wonderful than even the Avengers movies :)
(are you cunning and brutal, or brutal and cunning?)
Keybase still doesn't see the hordes of real people and their Eternal September effect on the platform as a problem. I'm not saying they have to see it as a problem - if they want to tell investors "We increased our userbase N-fold by attracting a bunch of people who are just here for the free money," that's their right. But for those of us who were previously on the platform for all the things Keybase used to advertise, it seems we're no longer the target market.
Who would have imagined giving free money would cause that?
When they then announced KBFS I was excited. It was just as useful as chat, and makes a ton of sense as a next step for the product. My second thought was hoping that I'd be able to pay for a "pro" tier and they'd then become profitable and sustainable.
Teams I also think was a very natural progression and definetely felt like the next thing for them. Especially with sub-teams, it opened a lot of doors when combined with KBFS and chat. To me it seemed to be gearing towards an eventual free personal tier with paid-for teams funding the platform. This would be similar to the model we've seen work with GitHub and such.
What came next was months of hoping that Keybase would become more stable and easier to use. The apps were buggy, but I could deal with it. The UI/UX wasn't very intuitive but with some effort I, as a technical person, could figure it out. I could even explain the concepts to non-technical friends and get them excited for it. But the quality just never picked up. The pain my friends experienced came from a crappy user experience, an incredibly flakey app (mobile and desktop). They all stopped using it, and so my usage became limited as well.
Then after months of waiting and hoping for improvements, they announced Stellar integrat. I was confused, it didn't really seem to have a straight forward commercial aspect. In my mind, you can sell keybase with file storage and teams, it seems like an attractive offering! Especially with hard line gaurentees of identity, that's a huge problem which is suddenly solved. But cryptocurrency, while fitting with the cryptography theme, didn't feel like it fit with the product they'd built. What's more, the apps still hadn't become more usable or stable.
I think my frustration with Keybase is that I thought they were using cryptography to solve problems with communication and collaboration. Instead it seems to be an excuse to for some crytopgrahy enthusiasts to build more things with cryptography. There doesn't seem to be a commercial approach, nor a true desire to make the power of cryptography accessible to the masses.
I really wish they'd invest in making teams, kbfs, chat, and identity easier to use and more stable. If they did, I'd find it really easy to convince my employer to give them money for the product suite. But instead they seem to want to throw in any feature related to cryptography, rather than building a product suite and applying cryptography to solve common issues.
I hope someone will one day take what Keybase has started, and will focus on the product rather than the tech. I'm not a cryto expert, most of what I learned was from being inspired by the Keybase articles. But at the end of the day I want to leverage this tech to it's maximum, not just use it because it's "fun".
https://web.archive.org/web/20191204211334/https://keybase.i...
2 Billion Lumens (XLM) were going to be shared over 20 months.
100 Million Lumens will be distributed on December 15th.
So, Keybase profits by keeping the remaining 1.9 Billion Lumens (19000000000*0.053261 current USD rate)
The whole office will be relieved when we switch.