yes, the premise here is that the Keybase server can be caught lying. If you want twitter user X's public key, Keybase can tell you the key and which tweet to look at to verify it. Then you can check it yourself. OAuth doesn't allow this.
No comments yet.