HNHacker News
TopNewBestAskShowJobs

malgorithms

3,974 karma · joined July 18, 2011

Chris Coyne | Keybase, OkCupid, SparkNotes, and many littler projects. Author of CFDG (a language for generating art) and some random video games. You can send me encrypted DM's on Keybase. I'm `chris` there. [ my public key: https://keybase.io/chris; my proof: https://keybase.io/chris/sigs/ZGN4xm-xstBYNd1npKXi6JXQMIiUDApwewlnQvqRsYk ]
submissionscomments
malgorithms··on Could keybase.io do for crypto what GitHub did for Git?
The client verifies the key by checking that the signed tweet, gists, etc., all exist and were signed by the private key that matches that public key. So to get the server to successfully lie, one would need to coordinate lies from twitter, github, etc., all at the same time.
malgorithms··on Tell HN: Meeting Satoshi
Please don't disclose the transaction. It's a serious decision, at least.
malgorithms··on Keybase.io
Hi riquito - this is a very legitimate concern, and it has to be reviewed individually for each type of proof keybase supports, in the client. With twitter, keybase, and github, you can't have a username containing any character other than an alphanumeric, dash, or underscore. Which means this kind of attack is impossible.

But for future identity proofs (domains, for example, which we've yet to implement), this kind of attack is real. Our approach here will be that anything outside of normal ascii will be highlighted and addressed to the user, as a serious warning.

malgorithms··on Keybase.io
To clarify the difference, it seems encrypt.to is a service which does PGP crypto in the browser, based on keys pulled from keyservers. In contrast, Keybase is an identity-proving service, which proves key X belongs to person with twitter account Y, github account Z, etc. As a convenience, it also does encryption and other crypto actions for its users.
malgorithms··on Keybase.io
confirmed, yes! Caroline is doing both the artwork and the site design. She's a wonderful artist and we're lucky to work with her. Note the site isn't done yet, so anything that looks funny or imbalanced is not her fault but mine.
malgorithms··on Keybase.io
boss, I'm glad you answered this question. Because it explains the impetus for Keybase.

I think what Keybase is addressing in the status quo is twofold: (1) sadly, almost no one does what you describe; in person meeting key exchanges and webs of trust may sadly be as unpopular in 20 years as they are now, and as they were 20 years ago. People who go to them are often confused, even programmers. I wish it were different.

And (2) more important, in 2014, often the person you're dealing with is someone whose digital public identity is what matters, not their face in real life or phone number. If you know me online as github/malgorithms and twitter/malgorithms, to get my key, meeting someone in person or talking on the phone to someone who claims to be me is actually less compelling than a signed statement by malgorithms in all those places you know me.

And if you do know me in real life, then I can tell you my keybase username and fingerprint, exactly as you're used to. So it's still as powerful for meeting in person. With the added benefit you can confirm my other identities, which you likely know to.

In answer to your scenario about verifying: you only need to review the "maria" the server provides once, and then your private key signs a full summary of maria -- her key and proofs. Cases 2 through 1000 of performing a crypto action on maria involve you only trusting your own signature of what "maria" is. The client can query the server for changes to her identity, and this will be configurable; if maria adds a new proof, you might wish to know.

malgorithms··on Keybase.io
yes, it does do this; once you're satisfied with maria's identity, that she's the person you want, you sign a statement to that effect, which you can store just locally or post back to the server. (or of course you can just sign her key in GPG!) The latter - posting back to the server - is for portability reasons. A keybase user will likely use keybase on multiple machines.
malgorithms··on Keybase.io
There were multiple questions/comments below about this, so I felt I should clarify one detail about the keybase client's trust of the server. When the keybase client requests maria's key from the keybase server, it does not simply trust the public key because it trusts the server (or uses https - huh?).

Rather, the server replies with links to tweets, gists, etc. -- maria's public identity proofs. The keybase client does not trust that these are honest, so it scrapes them directly and makes sure they were signed by the same public key that the server provided. In other words, the server could reply with a different maria, and simply lie, but not with the real maria's github or twitter account.

The server could also lie by omission, leaving out an identity. But it cannot invent ones that do not exist, without the client knowing.

Again, the premise here is that maria is the sum of her online identities.

The website itself is of course a different story. When you look up maria on keybase's website, you are trusting that keybase.io did not lie about her github account. Fortunately you can confirm by following the link to her gist, where she announced her keybase username and posted her key fingerprint.

malgorithms··on Keybase.io
Hi addisonj - sorry about this. The site is clearer about this limitation. If you request access via the site now (just click join on there) and remind me this happened to you in the comment field, I'll move you forward in the queue. Sound good?
malgorithms··on Keybase.io
Good question! There will be no such thing as a general check, because -- for any identity -- the client software has to perform a check that a human would agree means something. For example, what does it mean that you own a certain blog? How would a person confirm it? Well, at first glance it might mean that you have the power to post a message there. But someone else could do that it in a comment, and so that wouldn't work with Keybase. So any given identity check has to match some human definition of what it means to have that identity. And it has to be publicly auditable.

With twitter, it's the ability to post a tweet under a certain username. With owning a tumblr account, it might be something similar. With your known StackExchange profile it might mean posting a statement in a specific part of your profile. And so on.

The common thread in each case is (1) that you post in a place where only your identity can, and (2) what you post is a signed statement claiming a connection among three things: (a) your keybase username, (b) your public key, and (3) the identity on that third party service. (The third one is necessary so it can't be moved elsewhere.) Note how twitter and github's are totally different, but achieving these three things.

We will build out this list of identity checks, hopefully making all kinds of them easy to do. Everything from proving you own a domain to having a tumblr or reddit accoun. The definition of those checks will all be publicly reviewable, both in the spec and in the client, which is what checks them for you.

malgorithms··on Keybase.io
Hi everyone, Chris here, I've been working with Max on Keybase. I can't help but feel this ended up scooped a bit early. (Crap!) Not a surprise, because HN is quick.

The alpha site's changing every day, and we're working on the documentation now. I don't use the term "alpha" loosely. There will be extensive security details published, explaining every aspect of the identity proof system, client sessions, etc. They will be on the site before we open general access or turn beta. Right now only a few friends are on there. All that said, Max and I can answer questions here.

My profile on the site is https://keybase.io/chris if anyone wants to look. My profile demonstrates early examples of how identity proofs will work, including both twitter and github. We'll of course be adding other public identities in the future.

The site design is also very iffy at the moment; I was about to move into firefox bugs tomorrow.

malgorithms··on Secret – Share anonymously with your friends. Speak freely
Quick tip: I really wanted to try this app, but I didn't trust it to "find my friends", i.e., read my contacts. At first it seems you can't skip that step, but I force quit the app when it showed me the "find my friends" screen, and when I started it back up, it didn't show me the screen again.

Does anyone know if it spams your address book?

malgorithms··on Ask HN: How do I make my dating app popular?
Nope, it was a totally new site, new userbase. We learned while building SparkMatch that we wanted to do dating. But when we started OkCupid, we had all left the TheSpark/SparkNotes a bunch earlier, and there was nothing from SparkMatch on OkCupid. The only connection was a paid advertisement. We actually paid TheSpark to post an announcement of our new site, which got a bunch of the old SparkMatch users to try it. But, interestingly, it was LiveJournal (memories!) that drove most of our early growth, not TheSpark.

Also worth noting: OkCupid launched day 1 with the dating system as it is now -- answer arbitrarily many questions in 3 parts to build your own custom matching "algorithm". But we made it easier at the beginning for users to introduce their own questions.

malgorithms··on Ask HN: How do I make my dating app popular?
I once answered the question of our launch strategy for OkCupid on Quora (here: http://www.quora.com/OkCupid/What-was-OkCupids-launch-strate...). A few things I can add:

1. You're right in thinking that bootstrapping users will be much harder than coding the site. A dating site requires not just a critical mass of users, but also a critical mass using it in a certain location with enough people that there are internal compatibilities.

2. We loosely categorized our users into 3 groups. (a) those explicitly interesting in dating. (b) those who would consider it, but who weren't ready to make the decision, and (c) those who would never sign up for our dating features. Our early strategy was to (try to) nail all 3 groups, arguing that there was mobility between b and a, and that group c could still be used to spread around dating-related toys without realizing that's what they were doing. All this led us to personality tests and a bunch of other goofy things that attempted to be viral but could also enhance a profile if converted. On average, 10% of our early users became online daters on our site, and the other 90% were spreading the word in one way or another, but we never heard from them again. As we got bigger, we slowly shifted our message towards the dating side of things, as those "growth hacks" diluted our message.

Of course this is not the only strategy. Consider (1) Tinder, a very simple dating app, which has become a phenomenon. I would say it's hard just to invent this phenonmen, though... And (2) pay dating services, which can collect membership fees and then use the money to market. It's an expensive game which requires a lot of cash and marketing knowledge.

Disclaimer: I left OkCupid a year ago.

malgorithms··on Someone just made a $147,239,214 Bitcoin transfer
It couldn't be them - this was an odd number of bitcoins.
malgorithms··on StatHat iPhone App Released
2 hours ago I used a StatHat graph to convince a Time Warner Technician they'd messed up my network, and I showed them exactly when it happened. Love it.
malgorithms··on Hack this for 20 BTC
This is a good question: I posted the correct link 2 hours ago. It would be nice if everyone moved over there... https://news.ycombinator.com/item?id=6764619
malgorithms··on Hack this for 20 BTC
Yes, of course. But structuring it this way encourages users who wouldn't have otherwise done it to do so. We were prompted to build this feature because of how much money has gone through brainwallet with poor passphrases.
malgorithms··on Hack this for 20 BTC
fixed, thanks for the reminder!
malgorithms··on Hack this for 20 BTC
Hi everyone - just a quick update. (1) the URL is broken because the poster put it wrong (there shouldn't be a slash), not because the site is down. And (2) the github repository linked to is now public, not private. Enjoy the challenge. The first should fall fast.
malgorithms··on Chomsky, Valiant and the algorithmic mirror
some quick info: Petar Maymounkov, the author, is the same guy who invented kademlia, the distributed hash table that many p2p networks use (http://en.wikipedia.org/wiki/Kademlia).
malgorithms··on Gen. Michael Hayden: I'd also thought of nominating Mr. Snowden [for a hit list]
Is there a clear distinction between an "assassination" and a "targeted killing of enemy combatants"?
malgorithms··on Rainyday.js
I disagree. If it's an artistic project, I think it's pretty cool, and who cares if it works on all browsers? It's still worth seeing. Further, if it's just a UI flourish which doesn't otherwise affect the functionality of a site, then it's fine, too. Anyway, it looks cute to me. I'm thankful to whoever posted it and whoever made it.
malgorithms··on US Supreme Court: Cops can take a routine DNA swab at time of arrest
Did anyone else here get fingerprinted in elementary school, when the cops stopped by to say hi and talk about safety? We all were. This was in the mid 80's in Maine. I thought it was cool at the time, but I feel violated now. And I'm pretty sure my parents weren't asked.

More to the point: how would this generation feel about the police coming to school and taking DNA samples?

malgorithms··on Poll: Do you use your real identity on HN?
"Be true! Be true! Be true! Show freely to the world, if not your worst, yet some trait whereby the worst may be inferred!" -Hawthorne
malgorithms··on Department of Homeland Security Bans Dwolla Transfers To or From Mt. Gox
Who here feels their homeland is more secure now?
malgorithms··on NH-based entrepreneurs to launch Bitcoin ATM this week
I wonder if it accepts counterfeit dollars. [edit:] to clarify, I don't mean this as a joke. It seems that they're not paying out cash (only taking in) because they don't trust the depositor and have to wait anywhere from 10 mins to a couple hours for a transaction. But how can they trust the incoming cash? It seems like a perfect venue for a counterfeiter.
malgorithms··on CSS Zen Garden is 10 Years Old Today
A dream never realized...(sadly)...that one day websites would be redesigned by only changing the CSS. I'd love to hear everyone's opinion on why this doesn't seem to happen, in practice.
malgorithms··on My former employer Opera Software has filed a lawsuit against me
Unfortunately, justice is a one-sided story when large companies sue individuals or tiny companies at large corporate magnitudes. A defense alone can be financially devastating. Second, sadly, it's for "trade secrets" in the the world of software. Come on!

I (and again, this is personal, lest someone drag my former companies into this) stand by my statements, as long as this lawsuit exists.

If the basic facts themselves are wrong, then of course I will back off my statement. If Opera is not suing an individual for ~$3.4MM USD for divulging trade secrets, then great.

malgorithms··on My former employer Opera Software has filed a lawsuit against me
Thanks! Actually, I'm happy to address this comment now that it got your positive rephrasing. But first I should add I no longer work at OkCupid, and even if I did, the company is far bigger than one person's opinion. What I'm stating on HN is my personal opinion, not OkC's.

Ok, I personally find this kind of lawsuit deplorable for 2 reasons:

(1) The world is better when people share ideas and don't try to claim ownership over them. If, while I worked at OkCupid, someone left my company and used "secrets" we held to start or improve a competitor, I would believe it was their right. And that I had failed to nurture their creativity or compensate them well enough.

(2) This is an individual being assaulted at a corporate magnitude.

← PreviousPage 5 of 6Next →