3 ms·
if you are going to encrypt a message, it must at some point be input without encryption. Just like you wouldn't type a sensitive message with someone looking o
by dilatedmind 8y ago
if you are going to encrypt a message, it must at some point be input without encryption. Just like you wouldn't type a sensitive message with someone looking over your shoulder, you can use common sense and limit use of this extension.
Keybase is fantastic.
i've been using keybase for 2 years now and have had no issue accessing my files through kbfs.
with keybase teams you can store secrets at rest and make them easy to access across your team.
the client loads 10x faster then slack and has nice ux.
- phyzome 8y ago> if you are going to encrypt a message, it must at some point be input without encryption. How do you feel about someone else composing the message that "you" (your encryption software) are going to encrypt? Because that's what the article is talking about.
- dilatedmind 8y agoI feel like it would be best to avoid using their extension, but I am more concerned with the features and security of their core products. And I would think it is analogous to running kbfs on a machine with a virus or keylogger. And one nice thing is your root key is still protected by a paper key which you can physically secure, and use to de auth any compromised device keys. For the casual user who is just getting into keybase, social integration like this may be worth the risk in order to help onboarding new users. Once they start seeing the real benefits of using keybase, they can delete the extension and still make use of the good stuff. Finally, keybase is open source right? They are a small team and might not have the resources to improve the extension, but just getting the first iteration out there might be enough to attract contributors who see its value and can improve its security.