As the post says, this isn't a vulnerability in Keybase; it's a vulnerability in anyone who assumes that people use the same username on different sites.
Totally a lame vulnerability? Yes. Pretty effective? Also yes. If you go back in the github issue[1], it was even good enough to fool Chris, who founded the site, for 10 seconds.