4 ms·
Internally (I work at Keybase) we use it even more for the opposite. We do use it for secrets, but very often we put public info into KBFS we want to verify. A
by malgorithms 10y ago
Internally (I work at Keybase) we use it even more for the opposite. We do use it for secrets, but very often we put public info into KBFS we want to verify.
As an example, a number of us use it to address pain points around SSH. I keep this: /keybase/public/chris/keys/ssh.txt (you can see them on keybase.pub/chris/keys/ssh.txt ), and I keep all my known hosts as a reference in another file (that one in my private directory)...so when I'm SSH'ing to a machine from a new one I never have to say yes to connecting to a fingerprint I haven't actually verified. If I don't recognize a fingerprint then in turn I contact the appropriate party using Keybase, get a confirmation, and then add it to my file.
I'm bringing up SSH because we're thinking of making SSH public keys an important part of Keybase and curious if others share the same pain point. You mentioned a bunch of team uses and wondering if this was part of your use too.
- james_pm 10y agoInteresting use case. I suppose you could put photos of yourself, or any other bits of information that you want to be able to say is provable as having been provided by you.
- tristor 10y agoThis is a great idea. Right now my team has an onboarding script we maintain in a Git repo and we prepopulate a separate known_hosts file with our validated keys, but from that point forward each person maintains it themselves. It'd be nice to see some automation around SSH key validation. For instance, if from Keybase we could publish our SSH public key and additionally have some sort of facility to integrate with OpenSSH locally so we can use the NACL functions to maintain a signed/verified copy of a known_hosts file locally. The known_hosts file is kind of a weak point for SSH security when using public key auth, and I'd love to see something external that can improve upon this.
- twitchax 10y agoHaha, hello from https://keybase.io/twitchax https://keybase.io/twitchax! This is interesting, and I am super glad that you are here, haha. I am about to (in 2 hours) give a presentation on keybase.io for a MS-level cryptography course. I like all of the features, but I was curious what the primary goal was. I see a lot of people mentioning the encryption tools (which are awesome and easy-to-use); however, I cannot help but think that keybase.io is really about identity proofs and signing. Would you say that this is the case? If so, are there any plans to, say, add driver's licenses, passports, or other documents to a user's signature chain? There are some countries which actually give citizens public/private keys for cryptographic purposes like voting, etc.? I ask about this specifically because my professor is Josh Benaloh (author of the Benaloh cryptosystem [https://en.wikipedia.org/wiki/Benaloh_cryptosystem] https://en.wikipedia.org/wiki/Benaloh_cryptosystem]), and one of his major passions is voting and identity proofs for internet users. Thanks for joining in, by the way! Bonus question if you have time: any thoughts about forward secrecy as part of the encrpytion stack in keybase.io?