3 ms·
As Chris said, we would like to publish everything, just haven't found the time yet. We have bits and pieces in wikis in our various github repositories (almos
by maxtaco 13y ago
As Chris said, we would like to publish everything, just haven't found the time yet. We have bits and pieces in wikis in our various github repositories (almost all of which are open source and public).
The high bits are: all crypto is with GPG/RSA as per RFC4880. There are of course problems here, but we wanted backwards-compatibility and well-tested, well-used clients.
We encrypt server-stored GPG private keys (if you choose to use that option) with TripleSec (see https://keybase.io/triplesec https://keybase.io/triplesec).
Users use GPG to sign a series of JSON objects, of the form "I'm maxtaco on twitter", or "I checked Chris's proofs as of 2014/2/14 and they look good to me." All JSON objects that a user signs are chained together with SHA-2 hashes. So a user can sign the whole group of JSON statements by just signing the most recent one.
Here's an example (click on "Show the Proof")
https://keybase.io/max/sigs/ZnBizHMA8RKSB598TaDtjlPlLKSEu1WuaT59 https://keybase.io/max/sigs/ZnBizHMA8RKSB598TaDtjlPlLKSEu1Wu...
There's a fair amount of engineering that went into the software distribution system. We rely first on npm to get the initial client out there, but after that, exclusively GPG for code-signing. That's documented here:
https://github.com/keybase/node-installer/wiki/Update-Architecture https://github.com/keybase/node-installer/wiki/Update-Archit...
We hope to have better documentation soon, and we value feedback, we just haven't had the time to put it together yet.
- theboss 13y agoOkay I'll dig into the details when I have time. I noticed you an malgorithms took the time to write big posts to me. Thanks, Ill make sure I repay you with some of my time too.