5 ms·
After getting burned by Keybase, I didn't even look at Signal. I am curious to see how Signal works in the long term without a revenue model. I paid for Matrix
by markhalonen 6y ago
After getting burned by Keybase, I didn't even look at Signal. I am curious to see how Signal works in the long term without a revenue model.
I paid for Matrix and got my team on it, working great.
The nice thing about paying for something is you know what it costs.
- sjaak 6y agoBurned by Keybase how? It's still online and functional afaik. Do you mean the cryptocurrency shenanigans, the acquisition, ..?
- markhalonen 6y agothe acquisition https://news.ycombinator.com/item?id=23102430 https://news.ycombinator.com/item?id=23102430
- olah_1 6y agoHow did you get burned by Keybase? An outage or something else? I know in their own terms they basically say “we can delete your account, but we won’t”. I chuckled and never bothered.
- rvz 6y ago"Ultimately, Keybase's 'future' is in Zoom's hands." [0] That is what the parent comment is talking about. [0] https://keybase.io/blog/keybase-joins-zoom https://keybase.io/blog/keybase-joins-zoom
- lucb1e 6y agoI'd estimate that Signal is a fair bit better than Keybase since the latter wasn't end to end encrypted in the first place. But since you're on Matrix now, of course that's self hosted and as stable as you make it yourself. Decentralization for the win, kudos for going with an even better solution (even if I disagree about Signal not being a stable choice)!
- glerk 6y ago> since the latter wasn't end to end encrypted in the first place I’m pretty sure keybase is end-to-end encrypted, at least that’s what they are claiming. What makes you think it isn’t?
- lucb1e 6y agoThis makes me think it isn't: https://security.stackexchange.com/q/222055/10863 https://security.stackexchange.com/q/222055/10863 > after [installing the Keybase app] and starting a chat with your friend, you still need to verify that the server sent you the right encryption key. Since you can't host your own server, it has to be the Keybase, Inc's server that sends you the encryption key of your friend. > there is no way to display [the 'signature chain' of the person I'm chatting with], I have to trust the server to send me the right key. [Yet the client] displays a banner above the chat saying "end-to-end encrypted".
- pbronez 6y agoThe whole point of Keybase is that you could verify the keys that the server sent you by looking at signed statements posted on third-party websites. That verification happens client side.
- lucb1e 6y agoRead the post. I've had this discussion dozens of times now, everyone repeats the same arguments, all based on what Keybase puts out, never checking anything for themselves or even logically reasoning about how this could work (for those who bring up blockchain instead of third party proofs). There's a reason I link the information you're looking for, you don't even have to check it for yourself anymore. > It was mentioned on hacker news that the app should check third party proofs by itself. This is not exactly what end to end encryption means since it still relies on third parties, but nevertheless, having to [compromise] 2 or more companies' servers before being able to MitM someone's keys (which are additionally TOFU'd) should give quite some confidence. > However, when checking in Wireshark whether it actually does this (ask the Twitter API for the proof string and verify the signature with the the public key it received from Keybase), Keybase on my phone did not contact Twitter at all. (It did, however, proudly proclaim that the new chat was end to end encrypted.) > The packet capture started before the username was typed into the search field on the test device and ended only after Keybase completely established the chat and claimed it was end to end encrypted. > It is deemed implausible for the mobile Keybase client to simply have downloaded all signature chains from all users that exist on Keybase and to have checked all their proofs prior to starting the packet capture. This is the only way I can think of how the third party hosted proof could have been verified prior to the packet capture.
- zamadatix 6y agoPaying for something doesn't really tell you anything.
- olah_1 6y agoIt tells you that there’s a sustainable business model. Less ambiguity often translates to more comfort.
- zamadatix 6y agoNot really, ive paid plenty of subscriptions to services that later shuttered and not paid for plenty of things long kicking. And vice versa of course. Ambiguity goes away by understanding the total finance model not by knowing you paid 5 bucks. That being said I'd like to at least cover my cost to them to see it better grow. A payment isnt the same thing as that though it only tells you you at least paid a portion e.g. buying a smart tv doesnt mean you now know the tv cost less than that to make.
- mayneack 6y agoNon-profit 501c3 is a sustainable model. Plenty of non-profits span decades.
- tgsovlerkhgsel 6y agoCounterexample: Wikipedia.
- olah_1 6y agoTrue. However, every year they send a campaign that makes it sound like they absolutely will not survive.
- tgsovlerkhgsel 6y agoWhich is/was a lie - they always had more money than they could spend. (They reduced the aggressiveness of their wording over the past years in response to criticism.)
- stmw 6y agoKeybase is now owned by Zoom.