3 ms·
As you just said, users must trust the JS coming from Keybase. It might be compromised at any time. Next, people usually mumble about auditing it, downloading
by sweis 13y ago
As you just said, users must trust the JS coming from Keybase. It might be compromised at any time.
Next, people usually mumble about auditing it, downloading a copy, signing it, etc. At the end of the day, you arrive to code installed on the client - which you already have.
The web version just weakens your story.
- aragot 13y agoBut it's a good idea: Sign the js. Even md5 would be enough, it's just so that when the FBINSA subpoenas you, we'll know it.