I’m pretty sure keybase is end-to-end encrypted, at least that’s what they are claiming. What makes you think it isn’t?
> after [installing the Keybase app] and starting a chat with your friend, you still need to verify that the server sent you the right encryption key. Since you can't host your own server, it has to be the Keybase, Inc's server that sends you the encryption key of your friend.
> there is no way to display [the 'signature chain' of the person I'm chatting with], I have to trust the server to send me the right key. [Yet the client] displays a banner above the chat saying "end-to-end encrypted".
> It was mentioned on hacker news that the app should check third party proofs by itself. This is not exactly what end to end encryption means since it still relies on third parties, but nevertheless, having to [compromise] 2 or more companies' servers before being able to MitM someone's keys (which are additionally TOFU'd) should give quite some confidence.
> However, when checking in Wireshark whether it actually does this (ask the Twitter API for the proof string and verify the signature with the the public key it received from Keybase), Keybase on my phone did not contact Twitter at all. (It did, however, proudly proclaim that the new chat was end to end encrypted.)
> The packet capture started before the username was typed into the search field on the test device and ended only after Keybase completely established the chat and claimed it was end to end encrypted.
> It is deemed implausible for the mobile Keybase client to simply have downloaded all signature chains from all users that exist on Keybase and to have checked all their proofs prior to starting the packet capture. This is the only way I can think of how the third party hosted proof could have been verified prior to the packet capture.
- Wire
- Signal
- Jami
- Matrix/Element with central servers
- Threema
- Briar
- WhatsApp if you turn on key change notifications
- even Telegram secret 1:1 chats on a client that supports these kinds of chats
- anything you add OTR or PGP to... and the list goes on
You just need to do key verification, since key distribution is an unsolved problem in cryptography.
If I had an IT department and a secure server center I would for sure self-host. In the mean time I will get used to the tech and support the cause
> after [installing the Keybase app] and starting a chat with your friend, you still need to verify that the server sent you the right encryption key. Since you can't host your own server, it has to be the Keybase, Inc's server that sends you the encryption key of your friend. [...] How does this work with Keybase?
> there is no way to display [the 'signature chain' of the person I'm chatting with], I have to trust the server to send me the right key. [Yet the client] displays a banner above the chat saying "end-to-end encrypted".
It's all marketing department with a sprinkling of blockchain magic.