9 ms·
Keyoxide: A privacy-friendly platform to establish your decentralized identity
- Seferi 5y agoAnd now there is an Android app for it: https://blog.keyoxide.org/now-on-android/ https://blog.keyoxide.org/now-on-android/
- 1MachineElf 5y agoSounds like what I hoped would become of Keybase.
- kkjjkgjjgg 5y agoWhat has become of Keybase instead?
- 1MachineElf 5y agoIn addition to what all the other comments have said about the history of keybase, the present-day state of it is a sorry one. There was a drastic cut to development activity, suggesting it has gone into "maintenance mode" ever since the Zoom acquisition.
- infinitezest 5y agoAssume that OP is referring to the fact that they were purchased by Zoom recently.
- lutoma 5y agoI'm not OP, but feel similarly about Keybase. When it originally launched, it marketed itself as directory where you could link your social accounts using cryptographic proofs, so that anyone who was wondering if "@lutoma" on twitter and "lutoma" on Hacker News are the same person could easily check. I.e. pretty much what Keyoxide now seems to aim to do. Simple enough and reasonably useful. But then at some point they tacked on some sort of Dropbox-y encrypted file system that also kind of but not really includes web hosting if you set your files to public. And if you visit their website now all their landing page talks about is their Slack clone with end to end encryption without mentioning any of the other stuff. And I just checked out their docs and there's a section on wallets for the Stellar crypto currency so apparently they also baked that in recently. idk it just seems like a company with absolutely zero direction that just builds whatever the product managers find interesting at any given time and I gave up trying to understand what it is they do. But since they sold to Zoom, it seems to have been financially successful so fair play to them.
- woah 5y agoSeems like the problem is that their core service simply did not make any money
- Jtsummers 5y agoThey never charged. People were willing to pay, but they never offered a for fee service.
- djbusby 5y agoI don't want a little money every month, I want a lot of money all at once! -- Russ Hannaman (from Silicon Valley)
- KennyBlanken 5y agoThat's because the service was to capture users to then monetize them and the people visiting the site to verify their ID. Ads, other services, etc. Every tech startup does the same thing. Capture users with something useful for free, get them hooked, go public, and then bilk them just enough that, well, just enough of them stick around...while monetizing the data they give you, even if it's just their IP address at any given moment.
- duskwuff 5y agoThey built a chat service for some reason, then they pivoted into cryptocurrency nonsense, and then they got bought out by Zoom.
- karmanyaahm 5y agoAn example user page is my page here: https://keyoxide.org/4af679d0aba0ed4b07bf7b6932ca3267c8d187d7 https://keyoxide.org/4af679d0aba0ed4b07bf7b6932ca3267c8d187d... Keyoxide is a really nice, but difficult to set up, tool
- pgrepds 5y agoHow have you accomplished the profile picture? My profile is setup and everything works except the picture.
- karmanyaahm 5y agoIt depends on your PGP client.
- kingcharles 5y agoWhy do some of your "profiles" have Xs?
- karmanyaahm 5y agoI haven't set it up correctly. Just laziness (DNS) on my part. Tho technically it means that the site doesn't belong to me (except it does since the root domain is verified).
- na85 5y agoIt'd be cool to see this without PGP. Signatures via signify/minisign are superior in every way.
- georgyo 5y ago> are superior in every way. Besides the fact that a signify/minisign are a raw key instead of being padded with identity information, in what way are they actually better? Similarly, minisign makes no claims at identity at all. You get a random string, and the user is responsible for knowing which key is for what user. The minisign public key contains nothing but the key. To me, that is a horrible user experience. A PGP public key contains many bits of information besides just the key, and that is how this is even possible. PGP tools are install nearly everywhere (except windows) by default, while minisign is an extra install. PGP's web-key-directory is making knowing the right for a user trivial and tamper resistant. IE: https://keyoxide.org/wkd/george%40shamm.as https://keyoxide.org/wkd/george%40shamm.as It's hard for me to see any benefits of minisign really besides key size. Calling it "superior in every way." is straight troll bait.
- robinhoodsghost 5y agoNah troll baiting is saying "PGP tools are installed nearly everywhere (except windows) by default" when windows still has almost 80% market share on PCs. Most of the rest are on macos. If you want something to be useful that relies on network effects then they, and mobile users are who you need to accommodate. Linux on the desktop users are a rounding error.
- forgotmypw17 5y agoThey might not be installed, but they are available for easy installation, with GUI and without. There are also APIs and libraries for every major language.
- djbusby 5y agoIs 2% a rounding error? https://gs.statcounter.com/os-market-share/desktop/worldwide https://gs.statcounter.com/os-market-share/desktop/worldwide
- greenail 5y agoI really like the general idea of decentralized identity. Personally I'd prefer to keep my identities on different apps/platforms mostly (99%) separate. It seems to me that giving an adversary a map (especially usernames and email identities) of your online presence is a bad idea especially if they get access to one account and get some private details they may be able to use to socially engineer their way into other accounts.
- dane-pgp 5y agoI'm not sure what the best implementation of decentralized identity is (although proof-of-personhood systems like BrightID seem interesting[0]), but ideally the different platforms would cryptographically sign statements for you like "This user has a positive reputation on our platform" which you can disclose to other platforms without them being able to learn your username on the original platform. [0] https://www.brightid.org/ https://www.brightid.org/
- RileyJames 5y agoA tool like TLS Notary could be used to generate proofs of this nature. And do not require the participation of the host / subject of proof. https://github.com/tlsnotary https://github.com/tlsnotary Has some issues, but I find the approach very interesting.
- dane-pgp 5y agoI think it's not really viable to expect people to install a browser extension that interferes with their login sessions to sensitive websites, but if this technology was built into browsers it could be very interesting. The UX might be a little awkward, but you could have a "Notarised documents" location under "Save Page As" which stores the current page with an accompanying file containing the notary details. Then you'd be able to upload these documents via a web interface to a smart contract. There would have to be some way to cryptographically blind the connection between the distributed ID and these documents, though, as the documents would be plaintext and contain actual usernames.
- 5y ago
- gnufx 5y agoThere's also https://keys.pub/ https://keys.pub/ (from someone ex-Keybase, if I remember correctly). I haven't looked at either closely. Can anyone compare and contrast?
- doomrobo 5y agofwiw keys.pub has not had a commit to any of their GitHub repos since July 9 of this year
- deleted 5y ago[deleted]
- gnufx 5y agoNo, within the last month. One thing is that I don't see anything about auditing for Keyoxide, but Keys is up-front with a warning.
- karmanyaahm 5y agoKeyoxide doesn't use any cryptography, everything is handled by identities in PGP. I doubt it needs any auditing. The only reasonable attack vector I can see is hijacking the website (or proxy server) to return different keys or show something is verified when it's actually not.
- gnufx 5y agoI haven't checked quite what Keyoxide is doing, but I'm not sure cryptography is the only thing worth auditing for security.
- crosser 5y agoWould the following be functionally equivalent?: - on each platform, include your pgp key id in the "bio"/"about" of your profile - in your pgp key, include your profile URLs on each platform as an identity. (In DNS, CERT RR exists for this purpose already.)
- karmanyaahm 5y agoThis is exactly what Keyoxide does. See my HN profile description for step 1. See my pgp key at https://keyoxide.org/4af679d0aba0ed4b07bf7b6932ca3267c8d187d7 https://keyoxide.org/4af679d0aba0ed4b07bf7b6932ca3267c8d187d... for step 2.
- egberts1 5y agoIt is only a matter of time before such a website would offer an NFC-credit card to direct you to your account on their website.
- aborsy 5y agoPGP is a battle tested tool, widely available and straightforward to use vis Linux command line. It’s also well supported, eg, by Yubikeys etc.
- mountainriver 5y agoDecentralized identity is a pie in the sky to me. It sounds great but when you really start to think about what identity is, it’s formed by your relationships and connections. Tools like this may be useful in some instances but auth will always tend towards centralization
- Zababa 5y ago> Of course, one could opt for full anonymity! In which case, keep these properties as separated as possible. I really like the fact that they don't dismiss people that want to do things differently and don't need/want what they offer.
- kangaroopouch 5y agoOn the one hand, I like this idea. On the other hand, I prefer to avoid linking identities, especially in a publicly visible way. I see how it's useful for those that do!