> I'm not super keen on your chosen example of helping terrorists
It's a motivating example. You don't want to help Jenny and neither do I, but if the technology actually works that shouldn't matter, we have no discretion. If we have discretion in protecting Jenny, you can be assured that the governments sending these open letters will lean on that discretion for everybody, not just Jenny.
> No, private messages are private like you expect.
That's very confident considering the later caveats you introduce.
> Even if you consider a message service based on Tor, an attacker who controls the entire network can often figure things out by looking at sender and receiver timing.
Do you think humans (this is a service for humans) need sub-second delivery accuracy? No? So, why would you ensure this when as you realise this just helps an adversary? By throwing away everything better than second precision you make essentially no difference to the user experience but you mix everything up into 3600 events per hour that all have lots of indistinguishable participants.
> No, but you can see the length. Again this is true of all all end-to-end encrypted chat apps.
Again this is a service for humans. You can _choose_ to send exactly 1326 bytes over the wire out of some desire for brevity, but for humans padding everything to the nearest whole packet (~1500 bytes) greatly improves their privacy at essentially zero cost.
> If I never turn on that old laptop for months at a time, do we keep encrypting every message for its current key?
Well do you? My understanding is that in the Keybase design the answer is "Yes" and so most likely your confident "No" earlier will be wrong. Somewhere I can probably find keys that let me read Jenny's message and I am motivated to search for them.
> Exploding messages are a better solution for this problem, but they're also not a great default for most users.
Keybase's exploding messages are greatly fictionalized for the user experience. It reminds me of Mission Impossible. What the user sees is the message vanish instantly after a short timer, like a tape seemingly consumed in flame before their eyes on the TV show
https://www.youtube.com/watch?v=8VQfhyDP6vw
The reality is more like making Mission Impossible, the visual effect is achieved in a separate shot and pasted on, you could actually trivially recover the message for some time after it "explodes" across a variety of devices which each have their own keys. A month or two later the message is gone largely because nobody cares any more, not because it really "exploded" as depicted after just a few minutes.
> Keybase solves the key distribution problem in a totally different way from other end-to-end apps, by having you use social media to prove you own your key.
So, given my involvement with the Ten Blessed Methods (the means by which a Certificate Authority decides that ycombinator.com is really ycombinator.com in the Web PKI) you might expect me to be very sympathetic to this approach. But I'm not.
It ends up as a very woolly "Web-of-trust" type system and we know humans don't reason about those well. The technical argument may be "You can be confident that this Keybase account is controlled by someone who also controls the oconnor663 account on Hacker News or by someone who controls Hacker News itself or by someone at Keybase" but the human understanding is invariably just "This is Jack O'Connor" which is... misleading if I'm generous.
Forcing humans to do in person verification if they care, and allowing them to just not care is, in my not at all humble opinion, a better choice. I am very confident that messages from Al are really from Al having verified that our Signal numbers match, and not in the least bit confident that messages saying they're from Carol are really from Carol, and all the clever work at Keybase can't make a dent in that anyway because Carol leaves her phone unlocked on her desk.
> Forgive the wall of text
I'm the very last person who should criticise anybody on that front.