Zoom Acquires Keybase
keybase.io
keybase.io
Now they've lost their independence and they're owned by a communication company that has [edit: the majority of] its dev team in China.
I use Keybase to talk to my friend in China since it's one of the few services they don't block.
This is a pretty disappointing outcome.
citation needed
Also, what are you trying to imply by this assertion?
https://www.theguardian.com/uk-news/2020/apr/24/uk-governmen...
The implication is that China is hostile and leverages their power to censor/collect communication information from companies and their people without checks on this power.
They are aggressive in stealing IP from other companies and blocking software they can't control. They have history of wielding their power to pressure organizations to deny or ignore aspects of their history that they dislike (Taiwan, Cultural Revolution) and they pressure companies to hand over PII on people they find to be political threats without due process.
This is not a country you want to be a steward of an encryption identity standard.
I'm not disagreeing with you on the implications of having engineering teams in China, I think you would like to put that paragraph in your original post to give some context.
[0] Tech job postings in US: https://zoom.wd5.myworkdayjobs.com/Zoom/0/refreshFacet/318c8...
[1] H1b filing on engineering positions: https://h1bdata.info/index.php?em=Zoom+Video+Communications+...
edit: better formatting and grammar
Honestly I feel that if you're arguing in one direction or another and haven't checked the facts, maybe it's better not to argue about it?
They do have support people in the US and a handful of non-support engineering which is why I said thanks and immediately updated the comment to say "majority" instead of "entire" since it's more correct.
That technicality is less relevant to the main point of the argument.
As of January 2020, they had 2,532 full-time employees. Of those, 1,396 were in the US and 1,136 were in international locations. Within the 1,136 is "more than 700" employees in R&D in China.[1]
A LinkedIn search for "engineer" working for "Zoom Video Communications" in location "United States" shows up 558 results.[2]
Their entire management team is in the US, and of their 17 data centres, only 1 is in China.[3][4]
[1] https://www.sec.gov/ix?doc=/Archives/edgar/data/1585521/0001... [2] https://www.linkedin.com/search/results/people/?facetCurrent... [3] https://zoom.us/team [4] https://blog.zoom.us/wordpress/2020/05/04/navigating-a-new-c...
I mean, from a certain point of view, why not? If you're thinking in terms of 1, they're wildly different. If you're thinking in terms of 1,000,000,000,000, they might as well both equal 0.
Source: have lived in both countries
Edit: Someone disagrees? Consider Guantanamo Bay, third-party renditions, and drone strikes. If China did drone strikes, there'd be a huge outcry.
This sort of whataboutism does not surprise me but it's getting tiring when made repeatedly in disguise of intelligent discourse. It's dishonest because the difference is blatant.
For a company that does security that's concerning.
That is on top of the fact that Zoom encryption is weak af.
> We also operate research and development centers in China, employing more than 700 employees as of January 31, 2020.
You can find more stories from last year talking about that was how Zoom had such a large engineering staff, is that it was cheaper for them to pay for R&D in china than in the US[0].
[0] https://www.cnbc.com/2019/03/26/zoom-key-profit-driver-ahead...
Assuming GNOME shell is Linux users' default desktop environment is very wrong.
However, providing desktop GUI app in AppImage format is great.
Keybase solves a (to me) nontrivial problem: How to bring private keys into social media. Just a silly example: You don't use the same private-public key exchange in Whatsapp as you would use for your emails, or to sign your packages. It's a bit of the now infamous Dropbox situation: Most people can sign things with private keys and properly keep track of it, but they don't get around to doing it. It's only critical cases where the use is common (like signing packages). It took a long time even for HTTPS to become standard practise, though I guess the situation with your browser is a bit different.
My first reaction was: it can't be that keybase can it? Huh, well maybe I'd sell my principles for that much money too, oh well.
Maybe some keybase employee will end up being a whistleblower sometime soon though.
Zoom already has end to end encryption according to some of their other press releases and public statements (we know they don't), so why on earth would you believe this one?
Hear hear. It really is an absurd world we live in, and I had a good chuckle about that - just before I deleted my Keybase account.
In the post Covid world I was forced to compromise a bit and I will join a Zoom call in a browser (when it works) or install the app on my phone if I have to. I trust iOS to not get totally owned by a rogue app more than anything else I have available. Although recently that's not an entirely safe bet either.
Keybase was not critical to my daily life so it will not hurt to get rid of it. It's about risk management. There are no upsides to Zoom and almost no upsides to Keybase (for me). With the growing list of downsides it's an easy choice to make.
Why do I owe a commercial enterprise anything? They demonstrated repeatedly they cannot be trusted. In obvious and extreme fashion.
The fact that Keybase agreed to this tells me a lot more about Keybase than it does about Zoom.
I don't quite get the purpose though, why would I post something in public only for a group of people to be able to read it? Why not post it in a private chat then (encrypted, naturally)?
This is likely related to both nations having rules that allow only their own agencies to wiretap.
The VC funding model is terrible for most open source projects. With a few exceptions, you end up with an acquisition that ends or repurposes the project, or an Open Core project. And a VC-funded Open Core project will end up trying as hard as it can to have everyone need to buy the paid version, since that's clearly the way to optimize revenue and eventually the slippery slope will get you there. I don't blame folks for taking VC; it was easy to get, and there aren't a lot of alternative funding models that can pay the multiple fulltime staff that might be required to create what one wants to create.
I don't think VC funding as it currently exists is consistent with running an open source company according to my values, which is why we're not taking venture funding for Zulip. Obviously, being scrappy, applying for NSF grants, and spending my own money have very real downsides both personally and for our growth, especially when every competitor has VC funding, but it also means that I can ensure Zulip continues existing as a real open source project for the long run.
Don't founders often have the ability to overrule and make their own decisions?
Chris is already financially independent from the OKCupid sale, he could have open sourced the server code and/or reduced the overall burn to pivot to paid accounts.
Though the weird Stellar wallet addition implied some vision/product issues anyway.
Of course it's easy and probably unfair for me to say these things as an outsider with limited information and no real stake, it's definitely possible I'm wrong about important details that would change my mind. It'd be interesting to hear from Chris, but the sale probably restricts public communication?
This reminds me a little about the OKC sale actually, they had a blog post about why charging for dating sites made them worse that they took down after selling to match (they used to do cool analysis and publish them as blog posts, most of the details ended up in the book a different cofounder published called Dataclysm). That's more understandable to me though since I think it was their first exit.
Reading about Zulip - didn't you get bought by Dropbox before being open source? Is your current situation a lucky outcome - or was it a condition of the sale?
[Edit] - To clarify since there are downvotes, my questions aren’t rhetorical - they’re genuinely asking.
I think it's less about the power relationship, exactly, and more about the way VC-funded companies are setup to be run. As part of raising a round, you prepare a business plan that involves aggressively spending the money over a couple years. You're committed both internally and to your board to execute that plan, and it's cognitively difficult to do something different as there's social pressure to do so (and one of your VC's greatest sources of power over you is they're the reference for your next fundraising round).
The result is that your company has planned to run out of money with potentially a multi-million dollar annual burn rate in two years. If as those two years are approaching, the company and/or market situation don't support raising more capital and the company isn't close to profitable, the momentum of that burn rate applies a great deal of pressure for a sale, destructive layoff, or total change in goals to "anything that improves the bottom line".
Also, the search for a story to help raise your next round can have a big effect on companies -- my view is most of Dropbox's problems when I was there (2012-2014) resulted from the search for a totally new business bigger than Dropbox Business that could justify a bigger valuation than $10B starving more obvious investments (Carousel, the now-dead photo sharing app, at one point had ~10x the engineering resources of Dropbox Business).
> Reading about Zulip - didn't you get bought by Dropbox before being open source? Is your current situation a lucky outcome - or was it a condition of the sale?
It's an extremely lucky outcome. There's a combination of factor that made this possible:
* Dropbox leadership prioritized doing the right thing by their users, and so we were able to get permission from both leadership and legal. I'm sure my personal position as a leader at the company who had a personal relationship with the people who had approve it made a difference (Though Luke Faraone made a big difference by asking legal if we could and inviting me to the meeting!). But I think Dropbox deserves a lot of credit, because they spend significant time from expensive resources (legal, etc.) making this happen, and I don't know of many companies that would ever do that. * Our users were big fans, enough so that 10 of them flew to Dropbox HQ for a week to help us do the technical work required to do an open source release with all 10,000 commits of history intact and with a scripted installation process. This was essential to Zulip being usable after that release.
https://zulipchat.com/history/ has a bit more background on the early history (though it's a bit out of date).
I think I have a better understanding of how the incentives to cooperate would be hard to overcome even if you technically have the power as a founder (and even if you’re already financially independent).
The personal experience was also interesting - thanks!
But usually VC-funded companies have a board majority of said VC's, so they can overrule the founders anytime they want to.
Most commonly that's used to fire the founders and appoint a pet CEO (sorry, professional manager) who happened to go to school with one of the VC's.
So taking a story to them about "giving away our source code" would end up with the same result in most cases.
In a case like this, a founder can't just give away the source code. They'd have to believe that doing so was in the best interests of the company. And unless they wanted to risk a lawsuit, they'd have to persuade the shareholders of that too.
Fiduciary duty is extremely rare to be the subject of a suit against a, let's say, CEO. It's a complex area of law because it isn't actually a law, nor specified anywhere, and not a requirement for corporate existence. So, it's a set of court decisions that future cases are built upon, but in general a house of cards in that it could be invalidated by a) legislation; and b) adverse rulings at any level of a suit.
It's a myth that the only purpose of executives is to maximize profit for the shareholders. It's a canard. PBCs are a counterfactual here, full stop.
https://en.wikipedia.org/wiki/Public-benefit_corporation
[note the significant use of "goal" in describing traditional corporations]
I am curious because B-corps have been popularized in the recent years, but when I looked into what B-corps are, it seems to me those are just bogus certificates that aren't doing any good, except enriching the people who print certificates for these types of corporations.
I don't really know whether I am right or wrong here, but I weren't able to find anything that actually makes a B corp different than any other. Would love to hear your thoughts.
Going further, I believe this canard is promoted by greedy assholes as justification for their bullying of "nicer" people who might have a more holistic view of corporate behavior, something which bullies are psychologically incapable. These people would call PBCs theatrical, "hey bro, good for you!" on par with starting a nonprofit.
I don't know a lot about B-corps so I'm generally talking out of my ass, but it seems like a "hey we tried" get out of jail card if they decide to shed it, which they can always do. If they don't wind up shedding it, do they go for PBC? Overall, maybe it's good for setting expectations, but since there's no legal committment involved I don't see much more to think about it.
From my experience being a CEO and reporting to a board, trying to act in anything other than the shareholder's best interests would be... problematic, shall we say. I would need to be very convincing that what I was doing was in the best long-term interests of the organisation. Or have a board who agreed with the "not maximising shareholder value" goal.
It's only technically a myth that the only purpose of executives is to maximise profit for shareholders. That's definitely the most common instruction from the board, often implicit rather than explicit, and not doing that will get you into trouble in most situations. That trouble may not be a law suit, more probably just being summarily dismissed.
However, in practice if one has taken $10m from investors looking for a big payday, one can't just do any old thing. Doing something sufficiently contrary to the interests of minority shareholders could certainly result in a lawsuit. Could the shareholders win? Who knows! As you say, it's a murky area. But winning in that case isn't what matters. The lawsuit will tie the company up for years, forcing significant spending. And if they include the CEO in the lawsuit, it will mean personal expense and an enormous headache. So in practice, the Keybase execs couldn't just say, "Fuck it, we won't sell to Zoom, everything is open source now." Not without talking it through with the investors, anyhow.
I suppose, but does it? Ever? Not to be antagonistic but your entire paragraph is a hypothetical which is substituting for anything from the real world, which leads me to believe that it's either not a risk at all, or such a small risk as to be invisible and still effectively not a risk. I mean, I'm sure we would have heard some cautionary tales by now!
If you're specifically asking about VC-vs-founder lawsuits, I think we don't see many of those because everybody has strong incentives not to let it get to that stage. Founders really want to keep on good terms with VCs. VCs want to be seen as pro-founder. Their incentives are generally aligned right up until things start going south.
And once we get to the on-the-brink-of-failure stage, the VCs hold all the cards. Any continued investment requires the VCs to at least approve. If a founder ever might want to do something venture-backed again, they need to stay in their VC's good graces. If the investors don't have majority control, they at least have board seats and the ability to disrupt any deals or other actions the CEO might make against their interests, both internally and by threatening deal partners. The CEO also probably can't afford a lawsuit either with the company's funds or on their own.
So I don't think we see the cautionary tales because few who have been selected by investors and spent years dancing to their tune turn out contrary enough to set those relationships on fire when it doesn't really get them anything.
I wanna say we don't know. Has there ever been an instance of any company getting their tranche(s) and saying FU to the VC, and there being any repercussions? It's a two- or three-level hypothetical, but I think it's worth exploring to give you a complete answer.
Stellar integration was weird indeed, but it blended really nicely into the chat, and it would totally work for Keybase if there was an easier way to cash in / cash out. That said, any cryptocurrency would do the job, but if this particular one helps monetize the product, why not?
So what now? Maybe someone could clone the GitHub repos. And/or are GnuPG keyservers safe enough again?
For chat, Session looks most interesting. It's got the Signal messaging bits. Plus anonymity via the Loki onion network. And it's available for all platforms.
However, it's very new, and often buggy. And the Loki Foundation is Australian. So at some point they'll likely get pressured to backdoor stuff. And they probably won't be able to disclose that, unless someone leaks.
There's also Tox, where each user runs a Tor onion client. That's secure enough in Whonix. But the Whonix user base is miniscule, and I wouldn't trust an implementation in Windows. But then, maybe Session in Windows is too iffy as well.
Anyway, I'll be deleting my Keybase account, as soon as I've negotiated alternate comms with my contacts.
PGP keyservers have a fundamental issue that demands a solution like CT logs or Keybase-style merkle trees.
The only way to prevent getting Loki backdoor issues would seem to be a development so clearly in-the-open, that any secretive addition of significant code/suspicious PR behavior is obvious.
Tor does not use Tor by default. It works with Tor, but that's it.
My tinfoil hat tells me this information could be somewhat valuable to their Chinese overlords...
Well, now he has a thousandfold outcome compared to breadcrumbs that devs would throw at him. I.e. the system worked.
I think the vital question is why was keybase not blocked?
Maybe it was owned by someone high-up in China. That is why maybe Chris Coyne refused funding. It was free to just to onboard maximum number of users. Seems like "users" where the products that bought value to keybase.
In the Keybase case I think it was just obscure enough to avoid the censors.
This acquisition is a shame.
Attention people starting businesses: VC funding is fun and all, but please, have a business model. Your users and employees depend on it.
So perhaps better advice is, start a business even if you don’t have a plan and someone may buy it anyway.
A better world for your personal pocketbook maybe, but certainly a worse world for the rest of us. I wouldn't characterize that as "better" in any general sense.
The sad thing is that you need to remind people of it. I would never start a business without an idea of a viable business model for it. What do they expect? Growing until they are too large to fail and then ... Godot arrives and everything is fine?
I don't have much respect for zoom's security practices, while I do have much respect for the keybase team.
Perhaps this is Zoom's way of admitting that there is no way they can just solve the problem internally by keeping doing what they're doing and they need to get some fresh blood and build upon good practices designed outside their current culture.
Public perception of zoom/security is "beyond horrible", thus visibly spending lots of money on an acquisition of a very well respected name in security helps them polish that image at least a little.
And who knows, maybe they'll even work on actually improving security. Always the hopeless romantic/optimist, me. ¯\_(ツ)_/¯
I'd say you overestimate that. Perhaps 0.01% of the public knows that Keybase exists and has a bad opinion of Zoom security. Expert's opinion is important, but does not automatically become general perception.
(Anecdatum, I'm far from a security expert. I know that Keybase exists, even have an unused account; I use Zoom for work and don't blame them for not locking up tighter. Their blog post on the topic sounded reasonable to me.)
This is true, but perhaps a bit short-sighted. Expert opinion on Zoom is "avoid it like the plague". This does not automatically become general perception, true, but:
- Over time, expert opinions have a marked effect on adoption by non-experts in their vicinity. See the adoption of Firefox, or Google Chrome, for example.
- For a social networking platform, powerful well-connected never-adopters can pose a problem both to growth and to a budding monopoly. If CIOs and CISOs say, "Zoom over my dead body", that will tend to discourage adoption and encourage development of good alternatives.
Hiring consultants may be perceived like starting an investigation, not getting the fix now.
The question remains how soon and how true this will translate to the stated goal of true end to end encryption.
Nope. Once a pariah, always a pariah.
TLS is there to break sessions that would work under TCP. GPG is there to tell you to discard some mail.
But I do think that company values do change.
Zoom is getting the shining light of attention globally. Even human beings, in these situations, start to act more conscientiously, and then believe their own morality after the fact!
I believe the keybase acquisition demonstrates this a bit - because they will get zero public goodwill from this - nobody on Main St. knows are cares what Keybase is, this won't be on CNN so they are probably very much trying to make things better.
Owners of the company want money - now they are popular, they have to behave well to get that money. Wanting money usually transcends everything else including loyalty to state. A Chinese CEO with a popular Western product is going to realize that if his customers are way for CCP grabbing their data, it's a problem to his business. He doesn't want CCP snooping and one of the better ways to do that is to have better encryption as well.
Doing slightly suspicious things doesn't matter if nobody is watching and therefore nobody cares, now that people care ... it matters. Just as a matter of pragmatism.
They prioritized ease of use above all to get adoption before. This is appalling to me, but I believe they are seeing enough pressure to change course. It’s believable to me that they would intend to as they have already captured much of the consumer (non-B2B) market mind share and can afford to invest in this area.
Will I be using it now? Still a no. Maybe I’m time though.
Call my cynical, but "hiring" a bunch of infosec celebrities and critics as part-time consultants or contractors should be considered nothing but a (brilliant and silencing) PR move until the day that product updates and analyses reveal otherwise.
The product (and their poor installer practice) has been updated several times in the past few months alone, and each move has made Zoom a more secure product, with the vast majority of the hubbub having been addressed. So are you simply ignoring that, or are you setting your own personal goalposts?
Frankly, I don’t care if it does or not. I was just providing some visible signs of investment.
That's an intepretation you're choosing to make.
For evidence that they've changed their focus you can see their April 1 blog post[1] and the weekly video AMAs they do that are summarised in their "90-Day Security Plan Progress Report" blog posts.[2]
They're making a lot of progress.
The Keybase acquisition is about building out a strong security team that will help them implement end-to-end encryption in 1,000 person meetings, which currently isn't possible anywhere.[3]
[1] https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... [2] https://blog.zoom.us/wordpress/category/announcements/ [3] https://twitter.com/alexstamos/status/1258405729720918016
“Stove is hot, be careful before touching it.”
“Microsoft sexually discriminated in executive hires because ‘women will get pregnant and quit’, stifled completion in multiple categories, expected free overtime or you’d be stack-ranked out of a job. Be careful before trusting.”
Ultimately, an organization's policies are a reflection of the policies of its leaders. The bigger the organization, the more leaders have to change before the organization itself can truly change. It's much more likely that those who change just move on to another organization instead.
Besides, the end-to-end encryption incident wasn't a "mistake". Zoom's response was to say that their definition of end-to-end was just different from everyone else's. They clearly knew exactly what they were doing.
Zoom can change, but given their size and past I want more than a corporate apology and pinky swear before I trust them. They are making plenty of money and aren't going anywhere. There's plenty of time for them to earn my trust. However, they haven't yet earned enough of my trust to make me comfortable with this acquisition.
I've seen this turn out for the best literally one time, and that was Microsoft.
All the other times the bad company just continues its horrible slide into madness. It doesn't die either, just silently keeps churning out billions of dollars of shareholder value.
They are just very good at putting a dusting of Open Source sugar on things.
The book "The Power of Habit" has some good examples of large organizations changing course.
Leopards can't change their spots.
This phrasing is sophistry: there has never been an "era" where this was not true. Humans suck; humans have never not sucked.
If Zoom is acquiring Keybase because the C-suite is pivoting culture around security, then it'll probably work. Otherwise, not much will change. So until I see more evidence that Zoom's upper management had a change of heart (creating a CISO council is a good start), I'm going to be skeptical that this will actually move the needle.
I don't trust Zoom to be custodians of the Keybase company or software. This has been a real blow to my confidence in them and I'm not sure I'll continue to use Keybase :(
The disappointment comes from the loss of Keybase and what it could have been.
The main problem is Zoom having most of its development done via companies based in China. This means it is no longer possible for Keybase to achieve its original goal (and whatever encryption they add cannot fix this core problem).
It's one thing to accept the risk for video conferencing, but it's another to accept for an encryption ID standard.
I agreed with Chris Coyne's comments on HN a while back when he argued that the closed source server code didn't matter because of how they handled the encryption (when compared to Signal). While that's still true from a technical security standpoint, it looks like it does matter in a larger sense because this kind of sale shows that you can't really trust a company to act in its user's interests long-term.
Because no one ever buys or hires a conscience. If you thought a conscience was worth having one, that implies you would already have one and thus wouldn't need to outsource it in the first place.
Ethics always rolls downhill. If Al Capone goes out and hires Mr. Rogers, the power imbalance between them means Mr. Rogers is going to get dirtier than Capone will get clean.
If having a conscience means prioritizing security above all else, then Keybase is doomed.
But security isn’t the only thing that matters. Zoom seems to have focused on making a very user friendly product. Keybase focused on making security more user friendly. In many ways, the user focus of both apps is their Prime selling point.
Perhaps they weren’t buying a conscience, they were fixing a blind spot.
On April 1 the CEO basically said they messed up and would pause all feature development and focus exclusively on security & privacy for 90 days.[1] They've also done weekly video AMAs that are summarised on their blog under the 90-Day Security Plan posts.[2]
They've made a lot of progress.
The Keybase acquisition is absolutely about helping to build a security team that can help them implement end-to-end encryption across 1000 person meetings. You can see that from this Twitter post[3] from Alex Stamos and this interview[4] with him.
[1] https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... [2] https://blog.zoom.us/wordpress/category/announcements/ [3] https://twitter.com/alexstamos/status/1258405729720918016 [4] https://cheddar.com/media/zoom-acquires-keybase-beefs-up-sec...
Besides upvotes, HN should have a hall of fame for comments this good.
It reminds me of 1 Corinthians 15:33 quoting the Greek poet Menander:
Do not be misled: “Bad company corrupts good character.”Essentially, on some level we never stop the role-model based adaptation we did as children, when we modeled our behavior on what our parent(s) did.
> What the Keybase team will be doing
> Initially, our single top priority is helping to make Zoom even more secure. There are no specific plans for the Keybase app yet. Ultimately Keybase's future is in Zoom's hands, and we'll see where that takes us. Of course, if anything changes about Keybase’s availability, our users will get plenty of notice.
> So, our shortest-term directive is to significantly improve our security effectiveness, by working on a product that's that much bigger than Keybase. We can't be more specific than that, because we're just diving in.
They're not even making the usual "Zoom is committed to keeping Keybase alive" promise :(
If you have specific links to cases where this has been a problem, you'd be welcome to send them to hn@ycombinator.com so we can take a look. Or keep that in mind for the next time this comes up.
1. Integrates with an existing, open ecosystem
2. May have open-source clients, but server is closed source and does not federate
3. Pretty UI and good marketing
4. VC funded
VC Funded™
I actually think that this played a non-trivial part in Android getting early traction - similar dynamic to Gmail where tech people got excited about it eventually "my friend who's good with computers recommends this" becomes a factor.
Not the exact same formula as you formulate above, but I think there are parallels to draw.
Embrace, extend, and extinguish, and all that.
Fortunately, I've decided to go with Openmoko instead back then. I'm so glad I did.
Really sad because I personally recommended it too, and was hoping these things would work out somehow. Lesson learned: they don't. The next messenger I will promote with my friends would be one without the server at all.
https://en.m.wikipedia.org/wiki/Embrace,_extend,_and_extingu...
If the writing is placed on the wall (the marker cap is open right now) then replacing each of Keybase's features with existing technologies won't be difficult -- just time consuming, which is why they have market fit.
If Keybase completely shuts down, I have hopes the team will be able to convince Zoom to let them pack up and release parts of the server code not being shared with Zoom's products.
the trend exists because "pretty UIs" and usability are actually valuable features to users, and the existing open ecosystems tend to fail at that aspect.
Well, that definitely translates to uncertainty and ultimately the death of Keybase.
"We are excited to integrate Keybase’s team into the Zoom family to help us build end-to-end encryption that can reach current Zoom scalability."
not a word about what happens to the existing technology which doesn't sound very reassuring to existing keybase users.
Though what the main features were got very muddled anyways, especially with the odd Stellar cryptocurrency wallet implementation. I'm very interested to see what they do with the existing tech, or whether there will be open-source forks that are somehow compatible.
This will possibly change over time though.
I don't remember at all uploading one or where to find it if I did, can you explain the issue you have in mind a little more?
It's designed to lower the barrier to entry, but is obviously less secure than managing it yourself outside of Keybase (e.g. in GPG keyring, or a physical OpenPGP smartcard such as a Yubikey) - and some consequently wish the storage had never even been offered.
There is still (apparently under another command name) this ability to upload your private key.
It was badly implemented, badly introduced, and harmful for both users and adoption of the platform.
> Zoom has not and will not build a mechanism to decrypt live meetings for lawful intercept purposes.
> We also do not have a means to insert our employees or others into meetings without being reflected in the participant list. We will not build any cryptographic backdoors to allow for the secret monitoring of meetings.
One court + gag order and all of these promises are out the window.
warrant canaries must be written in the past tense. This is future tense. So they can monitor millions of calls, and give your information away at every second. This text only tells you about the next second (a promise they will break too, but then the text will be about the next second)
That seems to include past tense.
“...will not build a mechanism to decrypt live meetings...”
So, this means that they can record meetings, then retroactively decrypt and monitor meeting contents :)
IANAL, but I'm reasonably confident that it does not.
What do you expect them to do? Hire a PMC and fight a war with the police when they come around to raid the server room? Go into hiding so that the security agency can't steal the upgrade signing key from them?
We can't expect all of the internet to operate like Wikileaks and The Pirate Bay. If the justice system is broken, then the people aren't safe.
No, we want them to assume the same thing we are assuming. That if their service becomes successful, they will be coerced to compromise their users, regardless of how frequently they promise that they would never do so.
If they are even bothering to make public announcements like this, then that means they believe the security of their system can be founded on the honor of their employees. It's important to recognize that this isn't even true if you assume every member of their team is an uncorruptible seraphim.
Instead, where possible, the service should be zero knowledge, where not possible, it should be considered insecure.
Why not? That's just what it takes.
> If the justice system is broken, then the people aren't safe.
It is, and they are. After 50 years under the heel of the war on drugs, how is it not 100% obvious?
These kinds of statements are typically most usefully interpreted as a template for the kinds of things they plan to do, just maybe not exactly in that way.
> > > You guys should be taking my money
> > One way to pay, if you want to help ensure their success & longevity, is to evangelize for them, and get other people hooked on their product. Getting other people hooked on it like you are and seeing the potential and get over the adoption humps... that's valuable! They're not taking money because it raises the barrier to entry, and growth is most important. Pay them by helping them grow.
> It's valuable, but not in the capital sense. Each person you get hooked on their product increases their burn rate, and both makes them more attractive as an acquisition (which is scary for users) and more desperate for cash (which makes acquiescing to acquisition more tempting).
> Without a road to profitability (or at least a road to revenue) even attracting equity is difficult; investors who enter with that knowledge will be looking to exit through acquisition, since that's basically the only way to exit, other than just getting more capital.
Most people here seem to be making a self fulfilling prophecy of keybase's death.
But I like to think that Zoom intends to reuse large parts of keybase codebase:
> Logged-in users will generate public cryptographic identities that are stored in a repository on Zoom’s network and can be used to establish trust relationships between meeting attendees. An ephemeral per-meeting symmetric key will be generated by the meeting host. This key will be distributed between clients, enveloped with the asymmetric keypairs and rotated when there are significant changes to the list of attendees. The cryptographic secrets will be under the control of the host, and the host’s client software will decide what devices are allowed to receive meeting keys, and thereby join the meeting. We are also investigating mechanisms that would allow enterprise users to provide additional levels of authentication.
Will the founders be interested in releasing parts if not all of the server code to the public? I believe the founders' mission is still achievable and can be carried out, should they be willing to release the code in public.
Isn't this just all inevitable? Aren't all these startups just lining up all in the hopes just to get acquired?
I guess when we see VC Funded™ on any startup what it _really means_ is that:
"We are prioritising a return for our investors even if it means violating our mission statement".
What is more 'fun'? USD in bank account, USD as cash, DAO, or gold? I would think those are monotonically decreasing in 'fun'-ness. "Actual" money is not a good word for printable items of arbitrary scarcity. Not arguing for or against GP, just saying.
[1] https://en.wikipedia.org/wiki/Private_company_limited_by_gua...
I guess most founders are really just motivated by the pot of gold at the end of the rainbow :/
Even Mozilla Foundation [2] was spun off from Netscape, and heavily supported by AOL in its early years.
[1] https://www.effectivealtruism.org/articles/why-nonprofits-sh...
[2] https://en.wikipedia.org/wiki/Mozilla_Foundation#History
So either you're self-sustaining and are in it for the long haul, or you're looking to get acquired.
For example, if it was optional to connect to the Keybase network to begin with.
Imagine a keybase-type app that is built on web of trust rather than centralized servers.
An open source social identity attestation layer that people can operate and federate. Now that sounds cool!
Hard agree! Let me know what you think of this project Iris. I know it's still early, but the plan is sound imo https://github.com/irislib/iris
This outcome is almost certainly seen as a failure by the VCs. It looks like an acquihire. If so, it's quite possible that the VCs didn't even get their money back. Acquihires generally do not return money to VCs -- obviously, given that the employees are free to work anywhere, the acquirer's interest is in paying as much as possible to the employees and as little as possible to the now-worthless acquired company.
It's likely the employees are the ones benefiting most from this outcome, in that their pay has probably gone up considerably and they are no longer nervous about their job security, after many years of high stress and low pay.
It's possible the VCs were even offering some more cash to keep going, but at unfavorable terms, and the team said: "No, we'd rather take the big paychecks from Zoom."
Given Keybase has only had one funding round (according to crunchbase), the founders certainly still had a controlling stake in the company and the VCs couldn't force them to sell or not sell.
You can blame VCs for a lot of things but this kind of outcome is just not one of them (except insofar as that it allowed a company with little viable business strategy to exist in the first place).
(I am the founder of a failed startup. We had multiple "acquihire" offers, none of which offered any money back to investors.)
You really want to lock down some strategic IP that stands in the path of a behemoth and hope they'll want to aquire it under their growth goals or attempts to stomp out potential competitors (by throwing money at them and not through litigation or other paths). The big boys win because they buy out proven effective solutions/IP and models while failed startups eat the market high-risk exploratory costs.
But reading this, Zoom+Keybase will make sure of this themselves. This press release indicates that this is a 100% acquihire. There's only talk about what the Keybase people will be tasked to do, and there isn't any talk about Keybase's services in the first place. There's no real reason Zoom would be interested in keeping Keybase's services up and running anyway.
Let's hope they make it a swift death. Shame about Keybase, loved using it so far. It's somewhat encouraging to see a change in direction for Zoom, too. Hope the acquihire works out.
Perhaps the moment that Keybase took VC funding a while back, it was over to begin with and the principles of being a "Slack competitor" and respecting their users privacy went straight out of the window and into the bin.
I really had high hopes for Keybase as a Slack competitor, the cryptocurrency stuff I actively ignored, but this is a disaster.
Fission Mailed.
This feature saved my skin on one occasion.
Edit: This has a received a few downvotes. If I'm wrong here, I'd really like to know why! I thought this explanation was correct and clear.
It is different. Keybase could update the app to steal your key, but that’s a visible attack that can’t be done retroactively.
> If it was truly secure, then you'd be using a new private key to encrypt your real private key
There’s no reason to use asymmetric crypto for symmetric encryption.
> I believe the argument is that a private key encrypted with a password is not cryptographically different from a plaintext private key.
You have it backwards. On principle an encrypted anything (key in this case) is of zero value to anyone. It does’t matter if you tweet encrypted messages every 30 seconds to millions of followers or not: they're encrypted.
When you use a password to encrypt, and you (or your client/agent) selects an appropriately sophisticated suite, you end up seeding a KDF with your password and then using the resulting data as the actual “private key” (its just a symmetric key, no public/private). If your password has enough entropy, then the resulting key is perfectly secure.
In practice people are paranoid. “If the key is on Keybase’s servers, someone could get it and brute force decrypt it.” It’s almost pop culture fallacious, though, because if you believe someone can do that, then they can just as easily brute force the actual key. In practice people use shitty passwords, and crypto weakens as time moves forward, there are good and bad algorithms, and the whole point of a public key infrastructure is to keep private keys off the wire. So it’s generally seen as bad form to copy private keys around, even if they're encrypted. We’re still pretty far on the spectrum here because if your crypto breaks you have to rey key everything anyway. Not just re-encrypt unchanged private keys.
At the end of the day you're either copying a private key around or you aren't. And you should probably avoid situations where you need to do that because there are better ways to PKI. If your threat model can tolerate encrypted key backups and key sharing, then go for it. But that should be something you control.
If sharing a password-protected private key is perfectly safe, why bother having them? Why don't PGP users just password protect everything?
Above all else though, is there an authoritative source that can answer these questions? As a run-of-the-mill programmer, I don't really understand how crypto works well enough to trust my own common sense here. It's been drilled into my head that there are certain rules to follow set out by people who do know what they're doing. And when people say "it's all good, it's password protected", and I'm not sure what their credentials are, I get a little nervous. I did notice that Werner Koch uses Keybase, but if they could simply point to an "okay" from him or Zimmerman explaining the situation, it would be settled. To me anyway, it's not simply an abundance of caution ("paranoia"), it's that something seems fundamentally wrong with the approach and I just don't know the actual cost.
What’s “sharing” here? You “share” an encrypted private key with Keybase so you yourself can recover it back from anywhere using the password that you know. PGP, meanwhile, is used for communication with people who are not you.
> If people have bad passwords, that makes brute force recovery of the private key on a Keybase server plausible, right? At least a lot more so than the whole key from scratch.
Yes. If you want to upload an encrypted copy of your key to someone you wouldn’t trust with the key, you should use a strong password.
> I'd assume that a machine generated key has more entropy than any password that a human can memorize.
That’s not a correct assumption, but your password doesn’t have to be more complex than the key to be safe against brute force anyway, especially when work is added with scrypt (which is what Keybase uses).
The keybase model revolves around devices. Device keys are private keys that are tied to a particular device (your phone, pc, etc) and never leave that device (unless it gets compromised somehow). The only way you can decrypt your data on another device is by registering it using another authenticated device. These keys don't have passwords.
Its basically like encrypting a pgp key with another pgp key, and uploading it somewhere, like people upload all manner of secrets to github or s3 or whatever.
Keybase just provides an easier flow to register new devices and to import and decrypt your secrets (like via a QR code scanned by your phone, for example). Your private keys are as secure as any private, encrypted piece of data that you might send out over the wire, so long as your devices are secure, that is.
If one or more of your devices gets owned, all bets are off, AFAIK. Even if you set a passphrase on your pgp key, all it takes is a key-logger to get it. And since your device is already compromised...
This is where hardware keys win out (yubikey, etc), that require a physical touch to unlock.
DISCLAIMER: I really only have a layman's understanding of crypto.
Assuming what you're saying is correct, it seems much more sensible. It almost makes the PGP key seem superfluous, though I suppose it help with legacy this way.
It still seems not ideal, in that having one device compromised would give away your main private key and thus your whole identity. It would be nice to have it be some sort of subkey situation. I'd have to think about how that would work.
This is actually one of the best "features" of keybase. They've backed everything by some strong pgp crypto roots, but none of their stuff really "operates" using pgp. The fact that they have abstracted it, in my opinion, is part of why people have adopted it so easily.
At the end of the day, your keybase device key is, itself, simply encrypted with your keybase password. The point I've been trying to make clear is:
> Your private keys are as secure as any private, encrypted piece of data that you might send out over the wire, so long as your devices are secure, that is.
Except that long time ago, when device keys didn't even exist, there was a feature on Keybase website that allowed to upload a PGP private key encrypted only by your account password (which was never transmitted to Keybase in plaintext though – it was scrypted in browser when logging in, too – but this still means your private key was as secure as your password, which isn't a good practice in my opinion).
To be fair, you also have to trust native apps and browser extensions the same way. But with websites, the risk of a sudden and targeted (not noticed by the general public) update is much greater!
And the client is open source, which iirc includes being built by distribution's maintainers/build servers instead of Keybase.io.
scrape all those social media posts, reddit subs, etc. and you've probably got a solid idea of who that user is. all under the guise of public FLOSS stuff.
If anyone else is interested, please contact me directly (email in my profile).
While there are likely limits to the extend of my potential involvement in these efforts, I'd not want that to be in the way of further communications.
> What the Keybase team will be doing
> Initially, our single top priority is helping to make Zoom even more secure. There are no specific plans for the Keybase app yet. Ultimately Keybase's future is in Zoom's hands, and we'll see where that takes us. Of course, if anything changes about Keybase’s availability, our users will get plenty of notice.
> So, our shortest-term directive is to significantly improve our security effectiveness, by working on a product that's that much bigger than Keybase. We can't be more specific than that, because we're just diving in.
So, yup, keybase is dead.
A lot of people will stop developing integrations for Keybase because of this. It's sad.
The post is actually refreshingly honest that keybase is now abandoned and will probably die at some point.
The idea that companies were stupid enough to place their internal identity on some random 3rd party is so incredibly stupid that it’s hard to feel too bad for anyone.
Congrats Keybase!
I miss the days when businesses existed not just to serve investors but also their employees and the common good. It's like a 1%-er meta profit model where the actual business is in buying and selling the business and the core business is really just a temporary front that is designed to never make a profit, just create fancy looking charts and eventually bait and switch consumers when it is sold to the highest bidder and the employees all eventually lose their jobs.
One day, VC funding will either be illegal or required. considering the flow of money in this exchange, I'm betting on the second.
Uh when was this? For-profit businesses have always been created for the primary purpose of making money. Any side effect like employee well being happened to coincide with what maximized profits at the time or due to regulation.
I'm a big fan of business and entrepreneurship, but let's be clear here: there is a reason we invented government. There was never a time when we could 100% count on the beneficence of business leaders to advance social goals.
Edit to add: I'm not trying to demonize all business leaders here. There are some bad actors, but even business leaders who desire to do well have to succeed in the marketplace--even against bad actors. Unfortunately, doing bad things in business often confers the benefit of lowering costs, which is a competitive advantage. This is a known structural issue with a marketplace economy and why we need more than just business to have a good society.
So really, it's not that "there are some bad actors", but that "the system strongly encourages businesses to install these so-called bad actors as their leaders". I agree with you, that we need strong government labor regulations to counter this mentality, but this mentality is why these regulations have deteriorated over the past 50 years.
I'm sorry, but this is just not true. If it was legally mandated, then the Costco CEO would not have been able to resist such shareholder demands. Your example proves the opposite of what you think it does.
Nothing has changed in the legal structure of corporate governance since 1970. Do you think that investors never demanded greater returns from business leaders prior to 1970?
They can still demand all they want, but the law remains clear today that corporate directors and managers have the power to run the business as they see fit, and shareholders' sole remedy for their disappointment, in the absence of outright fraud or gross negligence, is to sell their stock.
In February 2014, Tim Cook was the CEO of one of the most valuable companies in the world. At Apple's shareholder meeting, he directly told his shareholders that he does not even consider ROI in some of his decisions. Legal consequences to Apple and Tim Cook for this statement? Zero. He's still CEO. Because there is no legal mandate to maximize corporate profits.
Honestly, by buying into this myth that the law changed in the 1970s, you're lending power to a fake idea that you seem to be opposed to. There is a group of people who wish such a mandate existed, and by acting like they're right, you're kind of helping them.
Business leaders might make anti-social decisions because they feel competitive pressure to succeed in a marketplace where customers are free to choose and are price-sensitive. That's not nearly the same thing as saying that corporate governance law forces them to make such decisions. It doesn't.
"All but" is handy phrasing if you're trying to create the impression that something you prefer is true. If you don't prefer it, I think that using that phrase is like shooting yourself in the foot rhetorically.
I think it's more constructive to point out that such a mandate does not exist (regardless of what some shareholders seem to believe), and there are good reasons it doesn't.
Here is a link that showed up in google for me when I tried to find support of this claim: https://www.washingtonpost.com/opinions/harold-meyerson-the-...
Literally they bought an army and took over India for money.
> cotton, silk, indigo dye, salt, spices, saltpetre, tea, and opium.
Surely access to those provides some benefit other than making money, which it also did for them.
Also worth noting that not every company is ... that one.
This is an utterly meaningless distinction. Money is fungible with all of those goods.
Anyway, if you want to go down that path you can easily conclude that literally any good or activity is just money, that you live a money-dominated life and we all exist for money all the time and while useful in some contexts I don't think it's particularly apt, but I hope you enjoy it.
In the grand context of life, no (despite the vast majority of large scale events that we learn about in history being usually a result of conflict over money/power) , but in the context of business, as this thread is, yes in a for-profit business literally every good and activity is about money.
Some businesses may choose to sacrifice money for things like employee well-being or community contribution, but that's a choice they make, or more likely are forced to make.
I think you need to read a little more history. People haven't changed their core nature in the past 40 years. Look at Carpetbaggers, the Triangle Shirtwaist company, and William Hearst for relatively recent examples. Further back you can look at The Dutch East India Company, the Knights Templar, and the various and sundry monopolies that have arisen throughout history.
People are driven to acquire capital initially to meet their own needs, then for power. There always have been people and groups of people who strive for the latter, not being satisfied with the former. Romanticizing long dead business owners may play well in movies and books, but it isn't reflective of human nature.
One day, revenue models will either be illegal or required. Considering the outflow of users in this exchange, I'm betting on the second.
Look up Joseph Rowntree[0]
[0] https://en.wikipedia.org/wiki/Joseph_Rowntree_(philanthropis...
"Yes, we sold our previous 2 businesses. But I want to point out that (1) neither of those sales ever hurt (and arguably both sales greatly helped) our users, (2) Keybase deserves special consideration which we are aware of, and (3) both Max and I are happy in a world where we never try to sell a company again, and only build things we like."
I feel silly for falling for it too. Even very wealthy people enjoy extra money.
I'd say, don't overestimate the tarnished reputation (= some news stories for a while, most didn't read or care about -- including corporate users).
And of course they wouldn't get into it in a press release/blog post for an unrelated to the issue acquisition! Doesn't make sense to sabotage themselves this way...
This seems like an extension of that. If anyone has thought a lot about multi-party encrypted communication it is the keybase folks.
I'm interested to know if you thought keybase doing the whole unsolicited Initial Coin Offering was a reputation tarnishing or polishing event for that company. (I'm circumspect about both of these outfits to be honest.)
Keybase seems like something that should be small, isolated, FOSS, supported by a foundation, etc. They could have built a business _around_ Keybase I'd imagine, but all they managed to do with this is invalidate Keybase and make people like myself, who feared their business motivations, feel vindicated for being paranoid.
I'll never blame anyone for wanting to make money, to make a business, etc. But if you make a product that walks talks and acts like a FOSS project, but keep it to center your business around... I'll always be longing for a real, true FOSS replacement.
In this case a good looking FOSS alternative came out a few months ago iirc. Though for the life of me I can't remember the name.
edit: https://keys.pub/ - though I will still miss KBFS
Arguably I think they agree with me, about the extensions at least. As seen by their seemingly random directions of feature extensions that Keybase was prone to. My issue is not that they chose random features to try to make profitable, but rather that the core premise, a public keystore, was tied so closely to a for profit company.
It would be like losing Git because Github went under. (Though, terrible example because Git works without a centralized repo, but it's just the first company <-> FOSS relationship that came to mind lol.)
Keybase was a centralized key storage with value-add services such as file storage and chat.
That was absolutely comparable to github, as you could've just gone back to manually syncing pubkeys and encrypting msgs. If github went away, you'd be without a lot of value-add services as well such as wiki, issues user management etc
Realistically speaking, nobody is going to do that... And tbh, it was already dead in the water when they added crypto currencies... Just took a while for their money to run out.
The actual difference is that there are enough competing products for github, not for keybase however, as that is just too niche
I don't see how Google's proprietary search engine or Facebook's proprietary interface to our social network rely on the broken window fallacy.
Would you mind elaborating?
Open source is famous for fostering a bunch of different approaches to the same problem, and slightly different forks of the same concept. That's the "bazaar" in the famous metaphor, as opposed to the "cathedral" of monolithic, hierarchical, linear proprietary development within a closed-source company.
"Everyone working on the same thing" only works well when there is broad agreement on what that thing should be, and strong governance to resolve disputes. National highway systems, militaries, and power grids are good examples.
I don't think search engines are a good example of where this would work; it's not clear in advance what will make a given search engine better. Thus we benefit from a variety of competing approaches, essentially to expand the space in which we're searching for the optimum.
Also, the broken window thing asserts that small amounts of criminal activity lead to larger amounts of criminal activity via signaling that being bad or neglectful is OK, which is both not proven and irrelevant to software writers being prone to reinvent the wheel for whatever reasons they have.
I think you would be right about the greater good being served by everyone being aligned on the same search engine ONLY IF we understood search engines so well that we knew there to be only one mathematically optimal way to build search engines.
Since we don't understand search engines that well, there is a LOT of value in the exploration over the space of search engines that these different companies represent.
The broken window fallacy argument is that those speaking of the benefits of the broken window are mistaking maintenance cost for generated value. That doesn't seem to be the case here. This is society implicitly investing in exploration over exploitation.
However they would still be able to borrow good bits from each other and gain insight on how things could be done differently, so arguably the end result would be a win. From a technical standpoint that is -I think where it gets messy is when we try to factor in the business implications.
> It is not seen that as our shopkeeper has spent six francs upon one thing, he cannot spend them upon another. It is not seen that if he had not had a window to replace, he would, perhaps, have replaced his old shoes, or added another book to his library. In short, he would have employed his six francs in some way, which this accident has prevented.[1]
Capitalism is about acquiring capital, i.e. money. There's no such evidence that people with money actually spend it in ways other than investment, and the sole purpose of that isn't to donate to companies that need it, it's to profit off it and essentially hoard more capital. Sure, poor people with either very little or no capital spend that capital on necessities, and thus drive the economy, but there's no evidence that people with large amounts of capital spend that on anything at all, there's more evidence that they hoard it and seek only to acquire more capital. The entire system is built to favour those people.
If you have to pay to replace a window that should have lasted, say, ten more years, that's money you now cannot spend on improving your factory somehow.
It is still economic activity (and the glazier doesn't mind the work) but it's remedial rather than generative. (The glazier that repairs the window could have been installing a new one in a new factory, eh?)
EDIT: It looks like it might, from the front page, I will try it out to make sure. If it does, that'll be great!
EDIT 2: It sort of does, but it's on a per-key basis, not an entire identity. You can publish proof on Twitter/Github/whatever, but it's only for one specific key, and it's one key per service, which means you can't only have one identity and multiple services.
And even if retention wasn't a problem at all, skilled people are not inherently skilled, they need to keep challenging themselves in their area of expertise to stay sharp. If the "home" product was failing to foster in-house expertise before then chances are high that it's a problem based on culture and priorities and experts injected from outside would quickly lose their edge. Keep them on the project they became experts on and they stay experts.
I wouldn’t quit my job (and I’m not looking anyway), but there’s plenty of hiring going on.
People went to work for this company based on the domain, the people, or the culture. With the acquihire they change the domain first, and the culture about a year in. Then the people start to leave, and it's just a job, and one you didn't even apply for.
On my worst days it felt like I was sold like cattle, and I would have seen more upside by hiring on someplace else.
I believe it's only enabled for a few distros though
I can't think of a single instance where acquisition of a smaller company like this resulted in an improved version of the original product. How many of us are running RHL? Skype is now close to Microsoft spyware that's impossible to remove from a Windows installation. Facebook purchasing Whatsapp, another service that formerly stressed encryption, resulted in things like plaintext backups of your texts on Facebook servers being aggressively promoted as soon as you loaded the app.
It's pretty much always cheaper to gut the original product, ignore the problems with your software, and enjoy the enhanced price of your shares while effectively spending no more money than you had for the original acquisition. As far as I can tell, Keybase has never had a business model or constant source of revenue.
Ia that the case? AFAIK WhatsApp gained proper end to end encryption after being bought by Facebook and pushes for backups to Google (and maybe iCloud?) servers.
Wikipedia writes:
> WhatsApp was initially criticized for its lack of encryption, sending information as plaintext. Encryption was first added in May 2012. In 2016, WhatsApp was widely praised for the addition of end-to-end encryption
Long term it ended up pretty good, with Koum and Acton taking their acquisition money bags and pouring them into FOSS projects like FreeBSD and the Signal Foundation. Maybe malgorithms will do the same.
https://en.wikipedia.org/wiki/Timeline_of_WhatsApp
> pushes for backups to Google (and maybe iCloud?) servers.
Yeah, I was incorrect. They backup to Google servers. Not sure if that's better or worse. :)
Since then, FB has offered willingness to cooperate with foreign governments to break encryption. I guess we will see what happens with the EARN IT Act.
https://www.bloomberg.com/news/articles/2019-09-28/facebook-...
RHL might be a bad example too, since Fedora is still pretty prominent, even if not often used compared to debian or debian-based distros these days.
If.
They're not the only ones though, this is what most companies call "on any device".
Screen sharing only works on Xorg, and screen scaling doesn't work (so it's super blurry on hidpi).
I've never seen that thumbnail window either -- though I don complain on that item, I prefer not having something like that.
And depends on iBus which breaks keyboard input for me.
> Zoom needs people who know how to make modern client software
It's the best video client available on Windows / Mac and works acceptably on Linux, what exactly needs to be more "modern" about it? Slack's video call thing is way less featureful, and Teams is still the abortion that is Lync / Skype for Business under the hood which is and always will be shit-tier.
> chat
I don't want my video app to be my chat app. There's any number of reasons why separation there is a good thing. I can start a Zoom call from Slack in 1 second, what more do I really need on that front?
Now, why Canonical decided to go off and write Mir instead of collaborating on Wayland development, I have no idea.
Plenty of people use this all the time. It's probably the single best thing about X.
Since these were also pretty much the only people who were putting effort into maintaining X, I think it's reasonable that they decided to replace it instead.
The history of X is a history of forks. But we've not seen another X fork appear to compete against Wayland. Instead we see the people who are writing Wayland continuing to retrofit the new technologies they're able to bring back, back to X.
Unless you begin to accept investors money who want an exponential growth at all cost. But if that’s what you want as an investor, no idea why you would invest in Keybase.
Well, shit.
Keybase had an amazing potential. I use it every day to ad-hoc securely share/store stuff. It will be sad to see it wither even more than it has. :(
Not exactly. The clients are open source, but the central server isn't. See https://github.com/keybase/client/issues/6374. It might be possible to reverse engineer the server, but it would be a lot more involved than just forking the project.
A shame, it seemed to work really well. Maybe Zoom will be willing to take my money to be a DropBox end-to-end encrypted cloud sync service instead, they seem to be fairly on the ball with responding to complaints and that they decided it was worth buying Keybase to improve their service maybe they'll come out alright.
Wishful thinking maybe =)
So imagine being able to add user@domainA.com, user@domainB.com, and name@nonprofitname.org to cool-dev-group and them being to instantly be able to access the relevant chat rooms, git repos, shared folders, etc. If password/secret management had been added, then access to that too could have been allowed. If SSO/Oauth had been added, then any service could be covered by this sort of role-based-access-control-for-anyone.
So no user has been created, they're using their existing identity to access new resources. With some extra coding, triggers and events could have been added to do things like auto-sign public keys.
Wow, this means that keybase stuff thinks that Zoom is secure already. Zoom should have hired people who don't think that way.
Their original purpose — tying identities to keys — could have been a nice small non-profit. But there aren't fortunes to be made from managing GPG keys, so they had to pivot into shark jumping.
https://pgp.mit.edu/pks/lookup?search=Satoshi+Nakamoto&op=in...
Not to mention it's notoriously slow and has been shown to be an insecure method of distributing keys (due to the fact that anybody can upload any key).
The whole point is that you don't just use it to upload a key. You link various verified identifies of yours across the web to your Keybase account so people know the PGP key there is the one of the verified person. It's a way to tie all your verified identifies together.
If someone would manage to compromise a bunch of identities of someone on the internet, and then create a Keybase account with them and then upload a compromised PGP key that would be a problem if you don't verify the key. But that's a bit of a stretch.
My real wish is that keybase supported ssh keys and would provide them as an agent.
I do agree on the ssh key feature being nice, and, here's a link: https://keybase.io/blog/keybase-ssh-ca You could also just use the keybase file system to keep ssh keys around.
PGP sucks.
PGP (GnuPG at least) is lightweight. I don't need an Electron dependency or a multi-megabyte chat room in the same application (address space too?) that supposedly keeps my private keys safe.
PGP is spoken by everyone, every programming language, having implementations on even ancient operating systems and architectures. Every email client worth its salt can use PGP. Emacs can decrypt and encrypt GnuPG-encrypted files seamlessly; other editors have plugins to do the same.
Even when they do use it, it’s easy to mess up.
The biggest flaw though is that in person key signing parties were never a viable or realistic thing for identity verification and web of trust based on that works poorly as a result. The use of multiple signed public social media accounts for identity instead as a way to fix this was Keybase’s main innovation.
For UX, even Snowden couldn’t get Greenwald to set up PGP and after multiple attempts Snowden eventually gave up and tried Laura Poitras with better results, the burden on the user is too high.
See https://keys.openpgp.org/about for why.
However, after playing with it, checking out their board of directors, and deconstructing their app design, their vision is not really "cloud storage", at least, not the way we typically think of it.
Their long-term mission is preserving a digital legacy, oriented around relationships, families, and organizations. You don't use permanent.org to store things in the cloud that people normally think as "cloud storage", not for the day-to-day stuff. The kind of things you want to store in there are the things you want the world and your descendents to have access to after you die. They won't have to (directly) pay upkeep to keep that legacy preserved. I think that is convincing enough for me to see it as a critical piece of free and open web, even if this doesn't seem obviously connected to the idea of preserving a legacy.
For example, an indie musician wouldn't have to rely on SoundCloud to keep their recorded music around. SoundCloud is not in the business of preserving the creative work; they are in the business of aggregating users and they use user content to do it. Placing those music files in permanent.org has a much better shot of preserving that creative legacy for future generations than leaving it on SoundCloud.
I've been juggling a lot of meetings between Zoom and my kid's school on different platforms, and the difference between Zoom and Google Meet is night and day. Schools are mostly switching to the latter because of the security concerns, but damn is it terrible. It's like Skype from 15 years ago.
It was “cool” to use Slack until it became widely used, and then it was “cool” to use Keybase instead. Zoom is currently seen as “uncool” (E2EE screwup + widely used), so when they purchase “cool” Keybase, now Keybase automatically becomes “uncool” as well and people will look for something “cool” to migrate to next.
This isn’t a complete explanation of all possible reasons, but it’s absolutely a contributing factor.
EDIT: I predict Riot/Matrix will be the replacement “cool” for Keybase.
Privacy considerations were secondary and only came to light (from their perspective) during the increased scrutiny brought during COVID-19.
In one way, good job Zoom for looking into security. In another way, I'm still looking at this awful UX that's buggy as hell and thinking it's gonna be a real slog for the keybase team to overcome that momentum.
Tech doesn't matter nearly so much as market. Marrying better tech chops to better market potential is a rather better investor storytime.
(Doesn't mean it'll work, doesn't mean Keybase tech will, or won't, survive. But the plave to be is Zoom's niche with Keybase's clue.)
Because Zoom is the buyer and they have the power. Sellers can make whatever promises they like (see: Whatsapp, Instagram) and it is reasonable to assume the buyer will have their way in the end.
Zoom will certainly use Keybase to improve their security overall. However, the rather obvious lack of commitment to existing users means there likely won't be any longterm.
My prediction: Zoom integrates well with keybase, there's a blog post that keybase is shutting down external services in a few months, the keybase founders leave and 1-2 years later, we hear of a new company they've founded.
What we are seeing is that Zoom is truly concerned about how their security posture is hurting their business. Remember they aren't the only game in town and there are plenty of competitors. Buying Keybase is an investment in their culture and longterm outlook.
It was just tarnished and unloved. Got notified this morning that I won't be able to access the public files of most of my 'security circle' on Keybase because they deleted their accounts.
I am disappointed by Keybase's impending doom.
If that comes across as negative, it's because it is.
Should it not be? I love Keybase, I've been using it for a long time and it's such an important part of my daily workflow that I would be more than happy to be a paid subscriber. Now it's most likely gonna shut down. I find it hard to find any positivity in this.
In other words, a fully open source (and open standardised) alternative continues to exist in the form of Matrix.
[disclaimer: project lead for Matrix]
(Congrats on the cross-signing release though, it's been a long time coming and it's been working really well!)
https://github.com/matrix-org/synapse/blob/master/docs/messa... has the details.
>Note that over every server in the room, only the ones with support for message retention policies will actually remove expired events. This support is currently not enabled by default in Synapse.
However I'm not aware of any client that opens conversations in different windows.
Let's say you're in a position that I think may here are: You would prefer to use IM in a secure way. Let me qualify "secure" for this purpose meaning: Encryption of communication in rest and transit; not relying on a single infra/network/service provider; being able to communicate with new peers easily without having to sign up with new providers; not requiring sign-ups leaking PIIs such as phone numbers; being able to sync message history across devices; all of this should hold for group conversations.
matrix.org seems to be on the right track towards that. Feature-wise there's some missing pieces in terms of federation but the roadmap looks like the ambition is right.
But in practice, it's realistically years until you can meet a random person in a bar and ask to join you on matrix to stay in touch, so many of us will still keep our accounts on the not-as-great platforms such as FB, Skype, WhatsApp, Signal.
Given that, wouldn't it be nice to facilitate using those platforms in a way that 1) absolves you from the behavioral tracking that comes with most of the first-party web- and smartphone apps and 2) integrates them in the same UI?
There are, of course, solutions to this end. Bitblbee (IRC gateway), libpurple (pidgin, finch), third-party clients like franz. I'm sure there are many here who have or are using libpurple or bitlbee for this.
But matrix also has bridges!
I'm thinking one potential way that matrix could really get traction and seed the network infrastructure would be just that. Given stable gateways for the IM networks people already use, it's suddenly a much easier sell to get enthusiasts and power-users to self-host matrix servers just to solve their own bridging needs and get a unified flow for disparate protocols.
As that grows, eventually there's a large spread-out flora of matrix servers that can become part of something larger.
I think if there's one thing that can make matrix succeed in it's mission, it's stable, feature-complete (or at least ticking the important boxes for the majority) bridges to mainstream services such as Facebook, Whatsapp, Signal, LINE, Skype, Google and Keybase.
I think this should be a focus for Matrix, and amazing it would be to have these be the fruit of voluntary contributors, some funding is likely required if it's to be sustainable as proprietary protocols and endpoints will inevitably break.
What's your take on that? I realize it's a long comment and I'm in a bit of a rush, but I'd be really curious to hear how you think about these things.
On the other hand, bridges are always an impedance mismatch - you have to keep up with new features on both side of the bridge, and the system you're bridging into doesn't always want to be bridged.
So, we think bridges are a key thing for Matrix (it's where the name comes from - matrixing together different comms platforms!) - but it'd be wrong to predicate the success of the protocol on bridges. They're useful, they have their place, but they're not the sole reason to use Matrix.
* delivering messages and file/image attachments work reliably in both directions
* stickers and other native attachments (location, audio clips, etc) can be received, not necessarily sent
, that's absolutely Good Enough for daily use for me and I imagine many others.Reactions and sending of stickers etc optional, but if that's there, that's basically full parity of what anyone in the target audience mentioned above could expect. Actual parsing of non-plaintext data is obviously up to clients and should be approachable for the average casual contributor.
> the system you're bridging into doesn't always want to be bridged.
This should be the crucial and challenging part to maintain.
More than that, some of the system explicitely _don't_ want to be bridged, because retaining users in their silos brings in more money than maintaining a window to the world outside the silo. It's tolerated at best today, but you can be sure that if a bridge ever get traction, the Whatsapps/Facebooks/Wechats will do what they can to block you.
Rather than betting on the bridges in the long term, I believe it's in your interest (as a Matrix user) to host a bridge to Whatsapp, and tell your Whatsapp friends that it kinda works but it's gonna fail at some point, so they better have a second account for the future. Install the account for them even, that removes some of the friction. But ultimately you have to realize that Whatsapp doesn't want to talk to Matrix (the situation is completely different for an open protocol of course, like IRC or XMPP)
Thanks to you and the team for all the hard work!
The only way I've found to join a room is the `/join` command. There's a GUI search, but it doesn't work.
Users have to pick their identity provider, their home server, etc. Lots of choices, scary messages, and generally annoying to set up. Services that depend on someone who is technically inclined setting things up never become widespread outside technical communities.
If users pick an unreliable server to connect to, or there's a network split, things break, just like IRC does.
There are several clients, all slightly different. It's up to the user to pick which one they want, when they've never used any of them and just want something to work.
It's better than IRC, but that bar is so low you'd have to bury it to get any lower.
It's true you have to pick a server to use, but we try to provide decent defaults (although it's true matrix.org has been overloaded recently).
We're trying to simplify onboarding via P2P Matrix - by default, you'd start off entirely P2P, and only pick a server if you want to 'anchor' your account somewhere.
I have a feeling you may be going off outdated impressions here; we've been desperately trying to improve UI/UX (as per https://blog.riot.im/e2e-encryption-by-default-cross-signing... and https://blog.riot.im/e2e-encryption-by-default-cross-signing...).
riot-web version: 1.6.0 olm version: 3.1.3
Search didn't find the room. /join did.
Also it just took me over a minute to find the version number, because the client settings are hidden in a dropdown menu under my user name, not in the gear icon (tooltip "settings") on the upper left or the hamburger menu that says explore, and even in the right dropdown it's under "settings->help & about" instead of just under "help" where the "about" box has lived in every single program since the '90s...
And noted, in terms of the version number being in the wrong place on Riot/Web.
never used that /join command, the GUI works fine for me
Riot is a Matrix client made by New Vector (https://vector.im), the company started by the team who originally created Matrix. The endgame there is to sell Matrix hosting (https://modular.im), support and other value-added services for Matrix. We are categorically not going to sell out our userbase - and we have no reason to; if we did, they’d just move to a different Matrix service provider.
It would be utterly sabotaging, and in the case of the Matrix Foundation, the Foundation is independently regulated by the UK Government as a Community Interest Company - and so anyone would be welcome to complain to the regulator (via https://www.gov.uk/government/organisations/office-of-the-re...) that the Foundation was breaking its charter, and the Directors would face fines and/or legal action.
This is why Matrix is in a fundamentally different situation to Keybase, or Zoom, or pretty much any other communication project out there, and why we spent so much time (and money) setting it up properly as a non-profit Foundation.
Matrix is 100% Free Software and you can run a server yourself.
Anyway, I run a matrix server for my family (and we all use the Riot client) and the number one issue is encryption and mysterious "Unable to Decrypt" messages. (Closely followed by how rough the Android client is.) This fixes all of that (well, once RiotX replaces the standard Android client) and I think it will remove a lot of friction.
Thanks for your work!
Is that true in Matrix? Several services advertise themselves as "end-to-end" encrypted, but then when you poke harder it turns out either there is some sort of TOFU (so an opportunity for the server to insert itself) or else there is no device continuity (which means in the case of e.g. Whatsapp that keys are reprovisioned almost promiscuously to avoid bad UX). Whatsapp is a particularly bad example because (a) I lose chat history when I move devices, and yet (b) the UX does not require an old device to authenticate the new one, so I can compromise conversations (at least moving forward) if I can compromise a server.
How end-to-end is Matrix really, and how similar is the new support to Keybase's key management flow?
All keys are stored clientside, with the exception of if you enable serverside key backup, when they are then encrypted and optionally stored serverside to allow you to recover your history if you lose all your devices.
Edit: Specifically, is key backup tied to the ability to recover account history on a new device, or can I still get that with key backup disabled as long as I have at least one other device active?
Edit 2: Can you address this paragraph:
> One point for super-paranoid users: currently the private key used to sign your own devices and the private key used to sign other users are encrypted by your recovery passphrase/key and stored on the server to allow recovery if you lose all your devices. We also allow signing keys to be shared (gossiped) between devices, but right now the implementation also stores them encrypted on the server too. This restriction will be fixed in future, but for now if you don’t trust your server with encrypted keys, you may want to hold off on using cross-signing.
If I understand correctly, sounds like security is based on the complexity of your recovery passphrase and an implicit assumption that the passphrase doesn't get transmitted to the server... is that correct?
> If I understand correctly, sounds like security is based on the complexity of your recovery passphrase and an implicit assumption that the passphrase doesn't get transmitted to the server... is that correct?
If you use cross-signing, then yes - your signing keys are stored protected by the recovery passphrase on the server. We also support gossiping them between devices (same as message keys), and there's no reason for them to have to persist on the server. We just need to hook up the UI to expose that as an option and we ran out of time to do that before shipping the initial release. It will follow shortly.
Edit: deleting my cookies and re-logging in did the trick, in case anybody else hits this issue. After re-logging in I now have one fewer cookie than before, so I must've picked up an extra cookie that was screwing with their auth handler or something.
Looking back on my usage of Keybase, I realize that encryption to me is a feature, not a tool or an app. I prefer my conversations encrypted, but I don't seek out an app that does it. I would like my files to not be tampered with, but I just kind of assume that's the default on Dropbox at el, even if it's not.
From this view point, it might be a good thing that Zoom acquired Keybase. I would have rather it be Slack or Google or Microsoft, but Zoom will have to do. If they don't murder the acquisition right away, there is a chance they turn Zoom and all their future tools into a more secure environment, in which case it's a win-win for all.
But after reading it, duh. It's an acqui-hire. Zoom definitely needs to improve it's security, because of recently publisized problems. These are the right people to work on that, the security problems are similar in keybase and zoom, and an outside team with an established track record will help Zoom regain credibility. And Zoom probably had lots of cash on hand to buy whatever they wanted.
So that all makes sense. I wouldn't expect the keybase product to stick around though.
Not because, as other commenters had said "Zoom doesn't care about security." Because they did an acqui-hire to get a team to help them with security, not because they wanted the product. I expect this will result in Zoom's own security improving, it's not some kind of smoke and mirrors trick. It's not that they don't care about security, I think they are presently prioritizing it. They just don't care about the keybase product. Obviously, why would they? It can't have revenue or profit anything close to what the zoom product has.
I’ve enjoyed keybase for many years, it made a lot of annoyances of encryption and key management easy. I particularly liked its encrypted git repo feature—now I’m struggling to think of an easy alternative.
From this article: [0]
> Within days, Stamos was on the phone with Keybase co-founder Max Krohn, and the teams started working toward a deal. Yuan said after he talked with Krohn and dug into Keybase’s software, he was convinced this was the right deal.
[0] https://www.cnbc.com/2020/05/07/zoom-buys-keybase-in-first-d...
Brian Krebs talked about this a bit in the wake of Equifax: https://krebsonsecurity.com/2018/12/a-chief-security-concern...
Assuming Zoom is really trying to fix the problem, it makes a lot of sense to bring in management (and/or teams) who have experience with bringing security into engineering culture, as opposed to individual security experts who may not even want to work for Zoom in the first place.
From the blog
Initially, our single top priority is helping to make Zoom even more secure. There are no specific plans for the Keybase app yet. Ultimately Keybase's future is in Zoom's hands, and we'll see where that takes us. Of course, if anything changes about Keybase’s availability, our users will get plenty of notice.
So, our shortest-term directive is to significantly improve our security effectiveness, by working on a product that's that much bigger than Keybase. We can't be more specific than that, because we're just diving in.
Absolutely. This was clearly an acquihire.
I copied all of my data out of my keybase folder today and I'd suggest you do the same.
Some people would regard this stock price as unsustainable compared to historic/similar earnings multiples, and that the stock will likely decrease in value in the "near" future. So from Zoom's perspective they may as well buy as much as they can while their Zoombucks are worth a lot since they'd be parting with fewer shares now than if they made the transaction later on.
I'm particularly disenchanted with the growth of these multipurpose tools, but I am not their target audience. (Nor, I suspect, are many HN participants, but this is a baseless guess.) I suppose I'm more of an adherent to so-called "UNIX philosophy"--the best, single-purpose tool for each task, preferably that can be combined with its like for a solution customizable to how a specific user gets work done.
Maybe they should work on the fact I can run Zoom in screen share and just about nothing else. Just entering a call for me takes ~75% of my CPU and I beach ball regularly when screen sharing lightweight text editors doing barely more than scrolling and typing.
I always liked the idea and the people behind it seemed like good people, but I'm sad to say I won't miss a worse version of Slack, Bitcoin and Dropbox.
https://ourincrediblejourney.tumblr.com/
Argh, yet another for the list. Certain cycles in the tech world are both extremely predictable and regrettable, yet for most of them the sting seems to fade a bit as the decades go by. But the acquisition-for-the-talent/IP-now-great-product-is-toast one somehow never, ever manages to lose its capability to be depressing. On the contrary new ones just make me think back on previous dearly departed that never got an equivalent replacement. It's part of what's made me particularly suspicious about new non-OSS "free" offerings, because that's generally just not sustainable. And the better it is the more I beg them to have some sort of decent paid tier. I guess some though just plain are aiming for a buyout from the start and that is in fact their planned profit/exit strategy, and fair enough but still ouch each time.
Zoom is presumably going for "look, we are bringing on-board this team of trusted people who understand privacy", but I think most are just going to assume it'll work the other way and Zoom's culture of poor security practice will bleed into Keybase over time.
- https://book.keybase.io/docs/crypto
are not available!Missing linked documents:
- https://book.keybase.io/docs/server_security
- https://book.keybase.io/docs/server_security/merkle_root_in_bitcoin_blockchain
- https://book.keybase.io/docs/sigchainLooking forward, none of that seems to matter due to this acquisition/acquihire - it seems clear that we'll not be able to count on Keybase in any meaningful way from now on.
This is the most disillusioning acquisition to date for me.
I've been using it on and off for years.. I'm still not sure what exactly it is or under what circumstances I should be using it.
For me personally, this is of course worrying news. I'll suspect that Keybase will die a rather quick death, as most of it's users are security minded that wouldn't ever trust Zoom.
Say, anyone got any Keybase alternatives that are focused only on identity management?
Discord is a nice solution if proprietary solutions aren't a problem. It's really sad.
It's a shame, really. The web of trust idea from PGP could've been really cool and useful to apply to modern social networking and communication services - one that I can imagine even some normal users using. But it seems that Keybase were one of the last willing to try...
Zoom definitely sees this as a chance to take on Slack given their new momentum.
https://www.heraldlive.co.za/news/politics/2020-05-07-parlia...
Relevant to the acquisition, perhaps: https://web.archive.org/web/20191122031523/https://github.co...
Selfishly hoping the cores service isn't shut down, though. I've been using it authoritatively for 5+ years. Treasuring the username I got too.
I'm sure the result of this will be lots of good and secure trustworthy software that I'll be eager to install on my computer. It's totally legitimate and accurate that people are reporting today that this acquisition will bring real end to end encryption to Zoom as if buying a company causes software to spontaneously manifest out of the ether with zero delay. Don't worry, everyone: Zoom is secure now because they wrote a check!
What is it with cryptographic charlatans these days?
[1]: https://sneak.berlin/20190929/keybase-backdoor/
[2]: https://news.ycombinator.com/item?id=21109530
[3]: https://www.zdnet.com/article/zoom-defends-use-of-local-web-...
[4]: https://blog.zoom.us/wordpress/2020/04/01/facts-around-zoom-...
[5]: https://www.forbes.com/sites/thomasbrewster/2020/04/03/warni...
I was playing around with a bunch of different crypto currencies when Keybase did the airdrop with Stellar. At every point in the process, it was opt in. Then I received ~$60 and that was it.
It seems your article was going for sensationalism and was highly disputed by all commenters on HN, not covered up by some capital driven conspiracy.
The text alludes to that being possible, but it doesn't tell you it's going to actually do that, or that it will then be impossible to remove the ad from your profile after you do.
The specific opt-in consent text matters. It says a thing, you click ok, but then it does that thing but also a second thing.
Ultimately this doesn't matter though, because keybase is toast now.
Your writing comes off quite accusatory but is also full of technical jargon that I can’t parse so I’ll naturally side with the majority. That’s not saying you’re wrong, but I’m sitting in a camp where I have 60 bucks and don’t feel slighted by their practice in the least.
It seems pretty clear from that description that the user consents to signing...
I think it’s annoying to see wallet and chat when all I really cared about was a discoverable public key, but it doesn’t appear to be a backdoor signing method.
Also, if you ratchet rhetoric up to this level of indignation, you detract from your own credibility, so it's not in your interest.
Please delete/kill the comment, it’s actually irrelevant because their old product is probably toast now (as is implied in TFA). My delete button timer has expired.
https://www.change.org/p/zoom-video-communications-inc-relea...
A lot of push recently has been into making it a "team chat" platform, which is great except that all of the participants are public, and tied to their name. It makes for hideously bad opsec if any company were to seriously use it.
The truth is that sharing money in the same way we share messages and images (i.e. chat) is a good idea, and in my opinion is absolutely inevitable.
Now we don't have to do that via cryptocurrency, but the reason we don't already have it in the west is because it's a coordination problem, and there are entrenched interests that won't care about giving the user a good experience until forced to by competition. Cryptocurrency lets you avoid that problem, and given that it is entirely around managing keys, it's a very natural fit for KeyBase.
I thought the integration into keybase chat was genius, and the user experience of transferring money in that way was much better than anything traditional banking has ever offered me.
They ended their Stellar airdrop early, but I guess it didn't help that bots were joining the platform, and affecting the other parts of the Keybase community, just to get a share of it.
$ keybase account deleteAs soon as they required me to use zoom, I told them I would not use zoom. I just go on their whatsapp thing, so of course I get less info, etc.
I really fail to understand how Zoom became so popular, and I was recently wondering the same thing about TikTok, which by the way, was just a clone of Vine.
Essentially, with apps like that, advertising and adoption is critical, the tech doesn't really matter that much. I would really be interested in understanding what are the strategies in place to make people use those things. Of course the virus played a huge role, but I'm certain there are specialists about how to gain users rapidly.
For Zoom though, I feel it's quite trivial to see how it became popular. Of all the various video chat/conferencing software that exists, Zoom is the easiest for the layperson to setup and use while also tending to be the best performing in terms of audio/video quality, latency, large numbers of users on a single call, etc. My girlfriend was able join a Zoom call with her parents a few days ago without even telling them how to do it; yesterday I overheard a 30 minute phone conversation while she tried to explain to her mother how to edit a facebook post (unsuccessfully, despite valiant efforts).
Outside of this niche community, basically nobody knows or cares about Zoom's various security gaffes. They just want something that works and gets out of the way. And I say all this as somebody who has watched others use Zoom a few times and read about it, but never used it myself nor felt the inclination to.
I'm sure you're right about specialists and strategies to try to spark mass adoption being things that happen, but the technology matters as well.
> CEO: But that would cost millions over the course of years!
> Engineer: Or we could just buy an already secure video app and put our features inside of that instead?
> CEO: Genius!
And that's how Keybase became Zoom.
Together with W3C's draft Decentralized Identifiers (DID: https://www.w3.org/TR/did-core/), it could provide a decentralized alternative.
Not sure what is the best way to verify Twitter/Github account though. This has to be managed by users themselves. E.g. one user posts a proof in the Twitter account, the other user verifies the proof by checking the proof against the public key posted in the database.
Edit: updated description.
Keybase has been one of the very few performant and usable "new-style" applications that I've used -and the only one of its kind.
Sadly I am forced to suffer electron-based vomit every day -between Skype, Teams, Whatsapp, Hangouts, Facebook messenger and whatever else I might be fortunate enough to be forgetting. It sucks that I might have to be on the lookout for a decent encrypted chat application that I don't actually hate, again.
Not sure why the use-case of chat communications has been afflicted by so much crappiness -as if it's a curse.
I didn't say that all electron apps have to suffer, at the same time it seems to me that there is a strong correlation.
Once Skype was rewritten as an Electron app, I noticed the same performance issues. MS Teams at work, same.
This on very decent computers.
I really feel there has to be something that Keybase does differently on the front-end.
With the shitshow that Zoom has turned out to be (there’s a long article on tidbits.com about the various issues), I don’t have any confidence that any part of Keybase as it exists now will survive. My belief is that it’ll shut down its services sometime this year or the next. I used it very rarely to verify certain identities, but am going to just delete my account and be done now.
Startpage by an ad company.
PIA by an anti privacy malware company.
Keybase being a slack competitor merging with zoom makes much more sense in retrospect. Zoom is insecure while keybase is seen as secure.
Companies are purchasing competitors or revenue stealers.
What a solid and useful product Keybase was! I'm ashamed that I didn't see this coming. Now I have to find a replacement that isn't compromised.
Hopefully Zoom avoids gutting Keybase. I found it really useful for bootstrapping credentials when onboarding remote team members and contractors. Way easier to manage than GPG: it was fairly painless even for non-technical people.
Fingers crossed. I wonder what the infrastructure overhead cost is?
So regardless of what happens to it with Zoom, the community can fork it and continue developing it, no?
So if people don't want it to be dead... it's not dead. That seems like great news, right? (And great foresight?)
Time and time again I forget about it and when I check the website it seems to be doing something different - but it all sounded very centralized, first the gpg keys, then the file-sharing and chat - it doesn't seem to be federated.
So unless some entity steps up as the de-facto api-compatible replacement, I don't see how having the code alone would help, unless you want a chat solution for a handful of users?
There's Tahoe-lafs, which ahs been around for years but, although secure was originally pretty notorious for being hard to use. Maybe it's improves since...
Please please please can someone fork and RE the backend code?
(Keybase's crypto stuff is nifty, but we all know there is no money in that. They tried to make money by integrating cryptocurrency, and people did NOT seem to like that. So here we are.)
[2] https://github.com/peergos/peergos
[disclaimer: Peergos founder]
Realistically this is probably the best outcome for the Keybase team as they presumably have jobs for the foreseeable future.
PR-wise it does not seem to bode well for those who relied on it for both file, chat and social graph storage...
Zoom seems so off mission for them. Very disappointing.
They'll either deliver that or they won't.
[1] https://twitter.com/alexstamos/status/1258405729720918016
# keybase uninstall
And then delete the app from Applications (recommend using AppCleaner to delete the app, as it leaves behind almost a GB of stuff).I wonder if Zoom will change that or not...
Matrix isn't the answer. That's like saying just use SMTP for email.
The slackification of Keybase did not lead to a viable business model, unfortunately. In fact, it's such a no brainer, I can't wait for someone to build Keybase 2.0. It might not be a VC enterprise, but could be a great lifestyle business for a small team.
Now I don’t even know if I can trust Keybase, and am trying to figure out if I should delete my account. Does anyone have any persuasive arguments for/against?
Best case scenario: the Keybase app gets spun out and gets an appropriate home.
I'm curious about the encrypted filesystem, secure messaging that works on computers (non-phone), and public key trust.
I don't want to delete it if it is just a soft delete.
I hope it doesn't die.
later today or tomorrow when I have free time, I will be deleting my keybase account.
So it will be harder for us to get at your stuff than is is presently, but we will still be able to if we bother to do the work.
>We are also investigating mechanisms that would allow enterprise users to provide additional levels of authentication.
So they will offer completely secure communications if you are at the paid level.
What’s that open source alternative that someone recently posted here?
So is this real end-to-end encryption, or Zoom-brand "end"-to-our-server-to-"end" encryption?
Yup, it sounds like the perfect plan to me.
What likely happens is this. The current codebase is too ugly to improve. But since they have a lot of users, it has value. So, the engineers from Keybase started from scratch, try to implement all of the functions in the existing codebase, plus secure. The plan is, after it has been developed, replace the existing codebase. But unfortunately, they miss the planed deadline by years and when it's finally working, they couldn't implement all of the existing codebase because nobody knows how to implement it. No documents and original implementers were left the company long ago. But they spent so much effort on the new project and all the new features are implemented just on the new one. Resulting the chimera of old and new code base both running at the same time. Oh and by that time, the user is rapidly decreasing for they failed to improve the service for years while the competitors offer the better service now.
The same story repeated countless times.
- Acquihired employees end up having zero passion or motivation to work on tech from their new masters and end up doing a crappy job and implementation before their retention period ends and they bail out.
- Mish-mash of additional crap code increases tech debt to a point that alienates top engineers causing them to leave for greener pastures. The second-tier engineers end up taking up the reigns hack band-aid further destroying the codebase. Cycle of crap code and good engineers leaving continues until the company is left with lowest-tier engineers who couldn't get a job elsewhere or desperate H1-B visa holders who hold up the fort until a competitor comes to eat their lunch with a better, more performant product.
And stupidly try to restart the same shit in the same niche.
you mean... to help you sort out your false advertising.
I just pulled a random page from Dec 25 of 2019 from internet archive where the site says this:
Meet securely End-to-end encryption for all meetings, role-based user security, password protection, waiting rooms, and place attendee on hold.
https://web.archive.org/web/20191225055029/https://zoom.us/m...
Fake it til you make it?