4 ms·
As Zoom now owns Keybase, I am really worried about the future of Keybase, especially after statements like these. This also makes none or very little sense -
by simzor 6y ago
As Zoom now owns Keybase, I am really worried about the future of Keybase, especially after statements like these.
This also makes none or very little sense - if this is actually just to cooperate with law enforcement, why would encrypting corporate (or paying) calls be any better, the bad people that are referred to in the statement could just get a paid plan?
- StavrosK 6y agoPaying leaves a verified trace though.
- bborud 6y agoIt sounds like bullshit. I don't think the reason to avoid keybase is necessarily because it draws their security from authorities into question, but it does call into question if a company that would say something that looks like impulsive nonsense is someone you want to trust.
- fareesh 6y agoIs keybase fully open source? Or is the server closed source?
- eddieoz 6y agoThe server stills closed but seems there're people saying the server-side is not needed(!) to trust the platform. https://www.reddit.com/r/Keybase/comments/77c241/keybase_why_are_you_hiding_your_server_source/ https://www.reddit.com/r/Keybase/comments/77c241/keybase_why...
- sukilot 6y agoWhy (!)? Of course servers are untrusted. If you think you need to see the server source then any trust you have is mistaken. Same as with HTTPS. If you think you need to trust the MITM, you've already lost
- eddieoz 6y agoI think you don't need to trust the server just if you can audit the frontend and assure it does not share any sensitive information with the server-side. If they apply the concept of data minimisation, decentralisation and distribution properly, there are fewer risks involved. But, if the server manages sensitive information, yes. It is preferable to audit the server code to understand how they handle the lifecycle of the information. "If you think you need to see the server source then any trust you have is mistaken." Sorry but I don't agree. I trust in systems I can verify. Trust without verifying is not trust, it is faith.
- jrochkind1 6y agoOK, but that doesn't help you when they shut down the server, which I think is what this thread was about? That zoom purchased it as an aquihire to have staff work on zoom, and isn't committed to the platform.
- deleted 6y ago[deleted]
- eddieoz 6y agoAgreed, but a server turned off has lower risks to leak information. And I think also they bought the expertise of the team to improve zoom, more than getting the solution per se. It will take some months to have this question answered (about what will really happen to keybase)
- jrochkind1 6y ago
- stickac 6y agoKeybase is dead. In the PR they were explicit they were hired to work on Zoom and not continue working on Keybase. Luckily there is keys.pub