3 ms·
I agree with the OP about uploading private keys being bad, but you don't have to do that – everything works without doing that as long as you are comfortable i
by masnick 13y ago
I agree with the OP about uploading private keys being bad, but you don't have to do that – everything works without doing that as long as you are comfortable in the command line. Whether or not uploading private keys should be an option is a good question (I think they probably should not be uploaded ever), but the site is still early beta so they should be given time to work this out without getting thrown under the bus quite yet.
I disagree that the existing public key repositories are what people should be using and that the twitter/github integration is pointless. In today's world, we often want to communicate with people we have never met in person. An old tweet or a gist that hasn't changes in a long time seems like a pretty safe way of verifying someone's identity. Apart from the NSA[^1], it's hard to imagine a situation where both keybase was compromised with a bad public key, and twitter/github was compromised by invisibly changing an old tweet (not possible to edit without a big hack) or a gist (not possible to edit without creating a change history within a big hack). So this makes a lot of sense to me as a way to easily verify identity.
[^1]: At this point I'm not sure I would trust any encrypted online communication if the NSA wanted to read it.