The cryptocurrency wallet feature is not useful for me, but it hasn't really impact me in any negative way, so I don't mind it.
Is it "not particularly strong" against nation state adversaries? Or can any script kiddie with a toolbox break it?
These are why I’d never use Keybase to chat even though it’s better than Signal from a usability perspective.
1. For _other_ Keybase messages without PFS it's open season. Say Alice sends you a normal Keybase message right now about murdering her husband Bob. Keybase will ensure Alice provides keys to decrypt that message for your iPad, iPhone, the MBP and your old Thinkpad. This way you can read the message from any of your devices. Convenient.
Spooks can record Alice's encrypted message and get it back if they at /any/ subsequent point obtain the Keybase device key for your iPad, iPhone, MBP or Thinkpad, for example as a result of seizing it for some other reason. Maybe it's next week, or next month, or next year, or in ten years time. The device may never have received these messages, maybe it was switched off, or they've since been removed. Doesn't matter until the key is replaced.
In contrast a PFS system would discard the keys as soon as they'd been used to decrypt stuff, and agree new keys for subsequent messages. Signal's double ratchet does this for every single message back and forth. "I killed Bob" (new key) "You did what?" (new key) "I was so angry I just stabbed him" (new key) "Shit. Now what?" (new key) and so on.
2. Actually though "exploding" messages are another Keybase compromise. Visually it seems like they blow up instantly when the time limit expires right? Gone. But cryptographically it takes up to a month or so for the bomb to "explode". Suddenly it's more like you wrote the message in chalk on an outside wall rather than it instantly "exploding". This was easier for their multi-device large group stuff. That's right, your 1 hour exploding message about the lawsuit was optimised for cases where you'd need to share it with a 500 person group who all have multiple devices. That makes sense right?
Always with "exploding" messages the actual expiry is implemented by some software explicitly deciding to throw ephemeral data away. Signal's ratchet makes doing so constantly the unavoidably the correct software engineering choice, otherwise your code leaks endless old keys because of the ratchet. But Keybase only throws away "ephemeral" keys after at least a week, chances are if you're a multi-device user there are some fortnight old "ephemeral" keys in one of your systems right now. A Keybase exploding message you got on the 1st of December with a one hour "fuse" on it is still actually readable now using keys from that device. Huh. The Keybase UI doesn't make that apparent at all.
Compared to WhatsApp and Signal that's bad, they both use a well-thought out security model.
As for Telegram, well, Telegram is Telegram.
It's up to the reader to decide what "theoretically unlimited time" means in this case with regards the adversary.
I agree, although I'll freely admit I haven't tried to use the other features all that much.
However, I do find myself a little uneasy with the key management aspects too. The official keybase CLI package being ~500mb when installed, the background server, etc concerns me. The alternative of using curl with a heap of largely inscrutable commands seems unworkable¹.
I wonder if anyone has worked on an alternative, and easy to inspect, client to interact with keybase for just the key management aspects?
1. I largely used the curl method, but suspect very few others would.
I think we're in agreement that a huge binary client is worse, but I'm suggesting there may be a middle ground with a small/simple open source client just for the key management aspect. That said, it does of course rely on people actually looking at the source of such a client ;)
A small client is still going to send the same payload.
Because growth. Either by VCs insistence, or founders ambitions.
Or that they hired X people to build the identity bit and needed to build more to keep all funding and staff.
If they had separated it more under a suite of products then it would have been ok, instead of bundling it all in one client and service.
All I need is the web page for identity and the CLI for encryption and verification.
I don't need a heavy electron UI always running on my devices.
I guess being a free keyserver and identity verification service (they frequently check all your signed messages across all linked web properties) just isn’t a viable business model.
"can you just email me a copy of your passport photo and these 5 other things i need to completely verify your identity to banks and so on"
errrr .... no ?
Individuals are arguably not fussed. But surely business can get behind some better levels of encryption / verification ?
A hard problem with email is that there is a boundary inside the address itself. How can anyone know this is steve@example.com? Maybe an outside authority can verify it's really @example.com but if I thought this was Steve and it's actually Tammy then I'm unhappy anyway.
For your purpose you probably don't think you care. You don't know whether custserv@example.com or customer@example.com or jenny.smith@example.com is the right email address to be telling you that your complaint is being confidentially processed anyway. But what about steve-the-plumber@gmail.com ? Does it matter if this is really from Steve or the mail actually came from tialaramex@gmail.com ?
Because the web doesn't have this authority boundary the Web PKI can actually assure you of a meaningful fact to a worthwhile degree. This is really https://example.com/. Is example.com really your local plumber Steve? Are they legally authorised to repair your gas appliance? Are they crooks? We can't answer those things. But we can tell you this is definitely example.com