5 ms·
Blog author here. In the interest of keeping the post more of a summary, we left the cryptographic details to our docs. Here's a link to that: https://keybase.i
by malgorithms 9y ago
Blog author here. In the interest of keeping the post more of a summary, we left the cryptographic details to our docs. Here's a link to that: https://keybase.io/docs/teams/index https://keybase.io/docs/teams/index . We're happy to answer questions here.
This really is an exciting product for us. Once you can define a team, cryptographically, without server trust, a lot of other things follow. We'll be launching some of those things in the coming weeks.
Also left out from the blog post: teams (and chats) can be controlled through a local API, so pretty much everything in Keybase can run in the form of a bot, also without trusting Keybase servers. Cheers to crypto!
- LeoPanthera 9y agoIf you delete a team, can a new one be created with the same name? Edit: Additionally, are team names private? Can they be discovered without guessing them? If you guess one, can you prove it exists?
- malgorithms 9y agonope! We feel pretty strongly this is the right answer.
- malgorithms 9y agoAnswer to your edit: team names are not private, as their hashes can be found in our merkle tree, which anyone is free to mirror or lookup. So if you name your team `foobar` someone would be able to hash foobar and look it up, and yes, prove it exists. This is a feature, not a bug :-) But if you picked a team name with very high entropy, then I guess that would be semi-private in that it would be undiscoverable by brute force.
- tehno 9y agoSame goes for sub-team name? I.e. don't put private project names, future release date related things etc in there?
- xnxn 9y ago"The very existence of subteams are hidden from all who aren't members of the subteam. Thus, if you wanted to create the team `lets_fire_bob.just_kidding_fire_bruce`, then Bruce would have no way of knowing his number is up." (from https://keybase.io/docs/teams/design https://keybase.io/docs/teams/design)
- thecoffman 9y agoDoes the presence of files in the teams feature mean that kbfs will be rolling out to the iOS app? Its been "coming soon" for awhile now and has always been the more compelling feature to me than chat :) Either way, congrats on the release, this looks really awesome!
- malgorithms 9y agoIt'll come after some improvements to team management and chat. But it isn't that much work, technically. KBFS is already running on your phone and understanding the filesystem... (your phone helps rekey data when needed.) It's just about building an interface around it. Which is no small task. It needs to be good. Hopefully soon.
- gr2020 9y agoI'm sure you're thinking of this - but integration with the iOS 11 Files app would be awesome!
- CodeMichael 9y ago+1 -- I would really like files to be working at all, but integration with iOS11 files feature would be amazing (also would love to see iPad working)
- amatix 9y agoOT, but any update on exploding messages in Keybase chat? (or did I miss it?)
- malgorithms 9y agowe pushed it behind teams, but we'll do it soon. 2 things we want to work on shortly: (1) switching to short-term exploding message mode (what you would expect from OTR), so your messages can be read and then disappear. And devices don't cache them. This has inconveniences, especially for team chat, but it's what you might want in certain sensitive situations or certain DM's. (2) a message auto-deletion policy for the team. This is different, and it's been requested by some testers.
- amatix 9y ago> it's what you might want in certain sensitive situations or certain DM's +1 – use case for us is sending creds between team members/with clients/etc that we don't want to share permanently via 1PW/other vaults.
- ineptech 9y agoCan the team creator give up admin rights on the team without resetting her user? I want to create a team for my employer so we can try it out, but I'm not the person they would want to be the admin if/when they adopt keybase.
- malgorithms 9y agoYes, you can be the initial owner and then add other people as owners (or admins). From there you could downgrade yourself to a regular user - or if they're owners, they could downgrade you. They could also kick you out. I've done this a few times today. We reserved a number of team names for known tech companies, and when they've asked, I've created the team myself, added a couple of their managers as `owner`s, and then they've booted me. You can think of the team's sigchain as just a string of signed announcements. You can sign someone else in as owner.
- zokier 9y ago> We reserved a number of team names for known tech companies I think this demonstrates the problem of creating completely new namespace from scratch. One way to solve that would be to couple the team namespace to DNS namespace; to claim a team name you'd need to demonstrate the control of corresponding DNS name, same way as you do for DV certificates. Of course I can understand that you'd want to support teams for organizations/groups that might not have their own domains, but you could support such cases by creating a "pseudo-TLD" (or just straight up buy your own TLD), for example .keybase.
- phinnaeus 9y agoBut control over DNS can change, right? If you sold or forfeited your domain name, how with this separate authority know to revoke your access to the team name as well? Should they even do that?
- azag0 9y agoDNS could always be used only for the initial name registration. After that, ownership would be managed within Keybase.
- amingilani 9y ago@malgorithms is there any support to change usernames? Before teams, I had a company PGP key under the company name, but with this launch I can't create a team with the defacto company name since it's already in use.
- V99 9y agoI have the same problem.. The only obvious possible option is deleting the whole account, but even that says "If you delete your account, you can't get it back, and you can't create another account with the same name." so you might not be able to use it as a team after deleting.
- insomniacity 9y agoWhen will you add file support to the mobile clients? We're absolutely dying for it over here!
- artursapek 9y agoAre you worried someone will dictionary-attack this feature and just claim all of the good names?
- coenhyde 9y agoIs it possible to encrypt with teams? eg `keybase encrypt -m "my message" {{insert team name here}}`
- oconnor663 9y agoIt's not yet, but this is on our short list!
- StavrosK 9y agoCan you post some information about this local API? I'd love an interface for building end-to-end encrypted bots, but I haven't found anything that allows that yet.
- malgorithms 9y ago`keybase chat api --help` gives a bunch of examples. There's more possible than what that suggests, but it should be a good start. We'll expand the docs soon. We have already written a number of internal bots at Keybase. We have one that posts all our github commits into a channel, for example.
- StavrosK 9y agoFantastic, thanks!
- AFNobody 9y agoPlease work on building some kind of safeguard against typosquatting and other similar angles. The one thing that worries me with this sort of thing is the "oops, I typo'd" something factor.
- C4K3 9y agoOT, but I'm curious what are the scenarios in which somebody (except keybase.io) can lock me out of my account? If I understand keybase correctly, if somebody were to say deploy some malware on my computer, thereby getting both my password and one device key, they would be able to completely take over my account, revoking each other key, and I'd have no way of getting my account back. Obviously if somebody gets a device key, they would get access to all data, but is there any way to prevent the above from happening? So I could revoke the compromised key(s) and setup anew. Aside from manually having somebody at keybase do so.