Keybase: Public, Signed Files
keybase.pub
keybase.pub
That is to say, the website is https, so I trust that the server I'm asking for the file is the same one that gives it to me. And since I can verify signatures locally, any time I choose, it would be hard for that server to get away with modifying file contents only when served through the site, sooner or later someone would catch them out at it.
But yes, if it's important, definitely get the files from a native client, CLI or GUI shouldn't matter.
That's only true if they lie to large numbers of people. If they just lie to a handful of people, who will ever know? (And you're probably not connecting through Tor, so there's a good chance they could know exactly who you are.)
> the website is https, so I trust that the server I'm asking for the file is the same one that gives it to me.
Do you know if they use a CDN?
Considerably different than an anonymous attacker.
But in practice it doesn't seem very different from any other hosting site? I'm wondering if they use a CDN, how long they will be able to offer free hosting, and what happens when people start publishing controversial content through them?
Note that keybase.pub was part of the Keybase filesystem since almost the very beginning. I'm not sure why OP posted it now.
What they did add was SSH server, banning, git hosting, and now bots to the chat.
As for what it is, their primary claim to fame is to solve the identity problem in the internet and secondary they solve the private key on multiple devices problem by having a smart way to have private key per device.
Once you have those 2 things you can build all kinds of stuff around that, and that's what they do. A well encrypted Slack is basically what they are.
I use it mostly to move files between machines or to host files I want to send to others. I also use the private git for backups for important folders.
The main thing that they are really missing in my opinion is being a IdP for OpenID connect.
Not saying it’s good or bad, but if you look at why people need trusted ID it might make more sense.
I transfer them into Bitcoin and sell them on Coinbase and receive the money through Paypal. I've received over 80$ for basically nothing as far as I'm aware. I'm happy with it.
Cool!
Accessing the folder, creating a file, and even simple unix commands like `ls` feels significantly slower than other folders.
The default instructions did not work for me, my file path is actually:
/Volumes/Keybase/public/username
It is different from the one provided in the blog:
/keybase/public/your_username/
When reading the blog, it wasn't obvious how I can find the path to the correct folder. I had to open the Keybase app and find a notification.
Keybase has an amazing, user friendly e2ee story.
Because other people can trust that the files are from you. Lets say you have some C project on github, you want to release a binary. Put it on Keybase and people can trust it is from you.
Might start using keybase again.
Keybase is a good idea and they got lucky with getting popular but they haven't really implemented features that would make them essential. Most people just sign up and forget about it.
EDIT: Seriously why the downvotes without clarifying? Has Keybase adopted astroturfing on HN like Brave and DuckDuckGo?
The only way I see us migrating away from our current gpg use cases is if all the integrations we use somehow went unsupported. There's simply no reason to assume the risk of inserting Keybase (or anyone else's) dependencies.
I'm willing to believe nobody in your corner of the world does. That's not the only corner of the world.
Obviously they want to lock users inside their tool for business reasons.