Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
malgorithms
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
malgorithms
7y ago
Fair enough - I don't want to dilute my point by coming across as too hostile, even though my point is that it seems like a well-crafted diversion. Let me edit it down and your quote of the original can stand.
32.
▲
by
malgorithms
7y ago
It _seems_ you (someone from the Signal project?) are actively diverting from the point, with what is ultimately a security theater request. Keybase's app - which IS open source - doesn't trust the server at all. We could be runn
33.
▲
by
malgorithms
7y ago
Oh interesting. I don't think we've talked about this decision publicly, so I can write about it for a second. Not letting people re-use a device name is an inconvenience, I admit, but arguably it's not like other cryptograph
34.
▲
Keybase is not softer than TOFU
(keybase.io)
614 points
by
malgorithms
7y ago
|
293 comments
35.
▲
by
malgorithms
8y ago
I'd be curious if people on HN would want a zero knowledge survey and voting system inside Keybase, and if so, what would it look like? The background: we talk about it sometimes as a solution to a real problem: in certain teams and wo
36.
▲
by
malgorithms
8y ago
Yes! Each horizontal row in the rectangles represents a participating device. The purple/blue rectangle that comes in first represents all the bytes of the commitments coming in. Since we constrain the size of the rectangle it makes (I
37.
▲
by
malgorithms
8y ago
Perhaps an even simpler analogy is a light switch. Each person decides randomly either to flip the light switch or leave it where it is. This is basically what random XOR'ing is. If you're one of 10 people doing this to the light
38.
▲
by
malgorithms
8y ago
Author here, thank you for the comment. "flip again" was added at the last minute, after a night at a bar...where some beta testers were making real-world decisions using the app. I didn't cover some details I find fascinatin
39.
▲
Announcing StellarX
(medium.com)
11 points
by
malgorithms
8y ago
|
1 comments
40.
▲
by
malgorithms
8y ago
Author here. I'm seeing the same comment in 4 different places on here, worded with various amounts of hostility. I now wish I had addressed this in the FAQ on the post. There's the suggestion that an exploding feature is worthles
41.
▲
by
malgorithms
9y ago
Blog author from Keybase here. Always game for a Hacker News discussion! There's a subtle point I cut from my post for simplicity reasons, but which feels perfect for HN. I've been convinced by Mazières and the Stellar team that t
42.
▲
by
malgorithms
9y ago
Actually, heck, to illustrate all this, I just made a team called `hners`, for "anyone who loves Hacker News." It's an open team. You can join straight from my profile in the Keybase app, or by running `keybase team join hner
43.
▲
by
malgorithms
9y ago
Oh cool - wasn't really expecting to see this one on HN! The changes here are all a result of "iterating" on our product. Since we work in cryptography, it's not usually the case we can move fast. But this mini-blog post
44.
▲
by
malgorithms
9y ago
The outpouring of positive energy (on HN!) is really inspiring. Everyone on the Keybase team is feeling good about our work right now, so thanks!
45.
▲
by
malgorithms
9y ago
We believe the right long-term answer for Keybase is finding a way to charge large corporations and offer pretty much everything else for free. Obviously there would have to be some paid tier if you really wanted 10TB of storage or somethin
46.
▲
by
malgorithms
9y ago
Keybase team member here. Interesting fact: git doesn't check the validity of sha-1 hashes in your commit history. Meaning if someone compromises your hosted origin, they can quietly compromise your history. So even the fears about da
47.
▲
by
malgorithms
9y ago
I'm on the Keybase team and as you can see we jumped to sponsor a small block. We participated in this for two reasons: (1) shazow (co-author) was also the author of the official Keybase Chrome and Firefox extensions, and he did an ama
48.
▲
by
malgorithms
9y ago
There is an analogy here to the slippery-slope of attention-getting ads on the Internet. Once upon a time an ad was just a static (not even animated) banner of a certain size and shape. 468x60 was one of the earliest, IIRC. Advertisers inv
49.
▲
by
malgorithms
9y ago
When we started Keybase, it was a hobby project to address shortcomings of PGP. Max and I both had just downloaded software packages and wanted to verify them, and it took us hours. At least one of them was bitcoin; I recall staring in awe
50.
▲
by
malgorithms
9y ago
`keybase chat api --help` gives a bunch of examples. There's more possible than what that suggests, but it should be a good start. We'll expand the docs soon. We have already written a number of internal bots at Keybase. We have o
51.
▲
by
malgorithms
9y ago
Yes, you can be the initial owner and then add other people as owners (or admins). From there you could downgrade yourself to a regular user - or if they're owners, they could downgrade you. They could also kick you out. I've done
52.
▲
by
malgorithms
9y ago
Answer to your edit: team names are not private, as their hashes can be found in our merkle tree, which anyone is free to mirror or lookup. So if you name your team `foobar` someone would be able to hash foobar and look it up, and yes, prov
53.
▲
by
malgorithms
9y ago
It'll come after some improvements to team management and chat. But it isn't that much work, technically. KBFS is already running on your phone and understanding the filesystem... (your phone helps rekey data when needed.) It&#x
54.
▲
by
malgorithms
9y ago
we pushed it behind teams, but we'll do it soon. 2 things we want to work on shortly: (1) switching to short-term exploding message mode (what you would expect from OTR), so your messages can be read and then disappear. And devices don
55.
▲
by
malgorithms
9y ago
nope! We feel pretty strongly this is the right answer.
56.
▲
by
malgorithms
9y ago
There are so many conveniences around a global team name. Any time we played through the mental exercise of ambiguous names, it led us back to the deep pains of reading out loud security codes or fingerprints, or relying on some kind of har
57.
▲
by
malgorithms
9y ago
Blog author here. In the interest of keeping the post more of a summary, we left the cryptographic details to our docs. Here's a link to that: https://keybase.io/docs/teams/index . We're happy to answer
58.
▲
by
malgorithms
9y ago
Keybase is! | NYC | SF | CHI | On-site. We're building crypto for everyone, and we're making our tools/apps for cryptography and secure teamwork on all platforms: iOS, Android, macOS, Windows, and Linux. Our software is open
59.
▲
by
malgorithms
9y ago
TL;DR: Remove old paired devices! I just went through this this week with a 2013 Wrangler. Here's what fixed it for me: deleting the other bluetooth devices from the radio. It had my old iPhone and my brother's iPhone. Neither wa
60.
▲
by
malgorithms
9y ago
I almost forgot another interesting use of this second feature: package managers and binary distribution. Knowing that version 1.2.3 of some app was published a month ago is nice. Also nice is knowing that for the last month it's the
More ›