5 ms·
Since Keybase inevitably comes up in these PGP conversations, 2 things in advance: 1. I've really been very slow in letting people into Keybase. The wait time
by malgorithms 12y ago
Since Keybase inevitably comes up in these PGP conversations, 2 things in advance:
1. I've really been very slow in letting people into Keybase. The wait time is still 6 months (last night I was letting in people who asked back in August.) But now that we've added HackerNews key proofs, I'll let people in today who notice this post who have more than 1 karma and write "I'm HN: {theirusername}" in the request form.
2. We're not just about PGP keys. It looks that way now, and our first goal was to help solve the very on-the-record type things developers do. Which mostly requires PGP - and PGP is very good at. Signing code and commits, releasing software, etc. But sometime soon each of your Keybase devices will have a device-specific Nacl key, for example. And the process for provisioning devices is something we're taking very seriously - we'll soon have a big blog post about how public sibling key announcements will work. Here's the foreshadowing: with a Keybase account, very soon you'll be able to start with something as simple as a Twitter or HN username, and do some very cool, secure things with files and messages.
[EDIT] We are hiring. There's no specific job page because we've mostly been reaching out to people quietly, but we want help building: the Keybase client (Go), iOS and OSX GUIS (Obj-C), and the site (front end development and back end (Node)). Please reach out to me (chris@keybase) if you like the idea of working on usable security software. We are currently distributed in NYC, SF, and CHI, and ideally you'd work with us in one of these offices.
- peatmoss 12y agoHmm... I never knew about you guys. I think I may need to do this. I've been meaning to get rolling again with GPG, in part because I want to move to `pass` for password management. Might need to spend some time today getting my ducks in a row.
- malgorithms 12y agoCool, just keep in mind Keybase isn't an email client. So if your goal is encrypted email communications, you'll still need to pick a client for that. Whiteout/Thunderbird w Enigmail/Mail.app w/GPG Tools are all apps to look at for your desktop. Keybase right now is basically just a directory. It's a different model for making sure you get the right key for the right person. As diafygi pointed out, the traditional PGP keyserver model is busted. There's no canonical ordering of key announcements and revocations, and the gossip protocol is messy. Solving this based on social accounts is our top priority. Every proof or revocation you do on Keybase is put into a chain for you, and in turn that chain is attached to our merkle tree and written to the bitcoin block chain. We want to prove everyone in the world is getting the same answer from Keybase, everything is ordered, and that we're not omitting anything. What you then do with those keys is up to you.
- urda 12y agoHey man I love Keybase so far, I'm really glad I finally got in a few weeks back. Keep up the good work!
- tomjen3 12y agoI hadn't really heard about keybase yet, but does it solve the only problem worth solving in encryption? Does it allow me to take any email address and give me back a private key that only the recipient can use? If I wanted to know which public key to use I would just look at the recipients public website or ask that person through a phone. The problem is that people don't create keys because nobody ever send them anything encrypted and people don't send anything encrypted because nobody ever sends anything encrypted. But if keybase is just another storage for keys, what is the point? Especially if it is going to add a pointless waiting list that is just going to make the problem of not having a key even worse.
- mayniac 12y agoEasier PGP programs would increase the use of encryption, especially post-Snowden. I've walked people through using GPG4WIN/Kleopatra and it took a good half hour of explaining how everything works. People care about privacy, but unfortunately not enough to go through the hassle of manually encrypting everything.
- vog 12y agoNot sure I understand what you mean. For some family members I set up Thunderbird+Enigmail, which was very quick including keypair generation. Now they communicate with me always encrypted, automatically. They don't have to know any details about encryption, except that they occationally have to type in their password.
- kgo 12y agoKeybase lets you do some key stuff, but the bigger feature is that it provides a bunch of ways to authenticate the source of a key above and beyond the WoT and getting into the strong set. Authentication is an inherently hard problem. With keybase you can, for example, see that the key that you want to use to send an encrypted email to x@example.com's website is owned by someone who also controls x@example.com's twitter, reddit, github accounts, web-site, etc, making it less likely that there's a MiTM going on.
- zobzu 12y ago
- sergiosgc 12y agoThanks for the opportunity to try out Keybase. Great work. The only question, but really important is: What is Keybase's business model? How will you make your living? It's a great service, I'd love to build upon it (my company does email as a service), but that step requires knowing you'll still be here a few years from now.
- malgorithms 12y agoEarly, while working on Keybase, I answered it here: https://github.com/keybase/keybase-issues/issues/788 https://github.com/keybase/keybase-issues/issues/788 Technically, not a lot has changed. We're still just putting our own money into it. However, we just added 3 people full-time and 1 person part-time, and so our costs have gone up. I'll admit, we only did this when we got an idea that we thought could turn Keybase into a business. In a few months we'll be launching a tangential idea - more than just a PGP key directory. This product will let you do some neat things with data backup and signed (possibly encrypted) file hosting and message spooling. It has nothing to do with email, but it requires a real PKI. I'll save the specifics for a big announcement, but the pricing model will reflect our costs with room to make money. More per gig than Dropbox and far less than Tarsnap. Should the "business" fail, we'll be back to where we were when I wrote the above answer.
- feld 12y agoMy keybase.io account is useless because of an error I cannot comprehend. I've never had a problem with my key, and it was working just fine when I signed up! Your public key appears corrupted (no valid primary key self-signature) edit: my self signature is fine, as far as i can tell https://pgp.mit.edu/pks/lookup?op=vindex&search=0x983B64501F13E252 https://pgp.mit.edu/pks/lookup?op=vindex&search=0x983B64501F...
- maxtaco 12y agoI moved this to an issue on Github [1]. The key you uploaded to our server has a UID that expired on 2014-11-09. The key you linked to on the MIT key server has updated self-signatures (and subkeys), so doesn't have this problem. [1] https://github.com/keybase/keybase-issues/issues/1410 https://github.com/keybase/keybase-issues/issues/1410
- peckrob 12y agoJust wanted to say thanks for the chance to try it out. Looks pretty awesome!
- jmccree 12y agoI was initially skeptical of Keybase, but I was happy to see the comments on HN of letting people use keybase without installing the CLI client were listened to. Seeing how many of my friends are on keybase now, that never had gpg setup before, I can't help but think it's filling a need that's otherwise unserved.
- malgorithms 12y agoA lot of people are doing it this way: a GPG user can join Keybase via the website, without installing any Keybase client. When it comes time to prove something with their private key (say, their twitter account), the site shows them what to do, using bash/GPG/cURL. It's pretty straightforward if you already have a key pair / GPG installed. There's no Keybase software to run, and the site basically acts like a todo list / tutorial.
- ApolloRising 12y agoLooking forward to trying out Keybase, thank you for opening it up to HN members.
- iamcreasy 12y agoThank you for the opportunity. I've sent request.
- halostatue 12y agoHow hard would it be to add support for RubyGems certs being added to keybase? I’d love to publish the public cert somewhere without putting it in each repo.