This also makes none or very little sense - if this is actually just to cooperate with law enforcement, why would encrypting corporate (or paying) calls be any better, the bad people that are referred to in the statement could just get a paid plan?
This also makes none or very little sense - if this is actually just to cooperate with law enforcement, why would encrypting corporate (or paying) calls be any better, the bad people that are referred to in the statement could just get a paid plan?
https://www.reddit.com/r/Keybase/comments/77c241/keybase_why...
Of course servers are untrusted. If you think you need to see the server source then any trust you have is mistaken.
Same as with HTTPS. If you think you need to trust the MITM, you've already lost
But, if the server manages sensitive information, yes. It is preferable to audit the server code to understand how they handle the lifecycle of the information.
"If you think you need to see the server source then any trust you have is mistaken."
Sorry but I don't agree. I trust in systems I can verify. Trust without verifying is not trust, it is faith.
I was looking into their terms (https://keybase.io/docs/terms) and they should notify before it. And seems my account is up over there.