Someone recommending the closure of #Keybase accounts and rotating keys, passwords, and anything else that KB has touched.

I probably have not been as vocal about it, but ever since I personally discovered (very early on in KB's existence) that following their default instructions uploaded your #privkey to their server, I have recommended avoiding them, cancelling any keys used with them, closing any existing KB accounts. I still feel that way ... and tying up with #Zoom is unlikely to improve my opinion of them.
#Zoom buys #Keybase as part of its plan to fix its security flaws. [www cnbc com]

Not sure that buying Keybase, a company that originally uploaded people's #GPG #privkey by default, is going to add any understanding of security at all. I've avoided them since I discovered they were uploading private keys by default (though I've heard they later changed that) because that indicated they did not know what they were doing.

I am glad that Zoom seems serious about fixing their issues. I just don't think this is advancing toward that goal. Now, instead of one business with severe security issues, they have two businesses which might have such issues.

I've made a ton of #keybase friends since joining up withe mastodon, not that I use keybase very much

#Keybase just came out as a crypto-currency marketing scheme. Moreover, they're trying to spin the fact that they actively hid that their funding was coming from a crypto "non-profit" as a positive, _somehow._

I know they're popular on the fediverse as an identity verification service. If you're using it for that purpose, I urge you to reconsider in light of this.

So, I tried a while back because I like the idea of being able to verify identities.

Now, it’s trying to get me to start using Stellar’s crypto currency by “giving” away Lumens ( Anyone have an opinion on this? Seems like they are abusing people’s trust in an identity service to lock them into a crypto currency racket.

Tien donc, #Keybase qui donne des Lumens ($XLM) à ses membres!
Ils m'ont donné ~356 $XLM, équivalent à ~21 $USD.

#Keybase app on iOS is having a hard time loading anything. I wonder if their infrastructure will hold up to 300k people checking to see if 21$ worth of #Lumens showed up.

@WPalant Any thoughts on #keybase as a protocol along with gpg-esque bits?

Here was an audit posted from them too for additional context:

For all TootWorkers who want to verify their Mastodon account on their Keybase profile. It's a little finicky with our setup here since Okta does not forward links properly.

But all you have to do is use the #keybase command-line utility and do:

$ keybase prove <your-username>

Then copy the given URL and paste it into a window where this instance is already open and visible. That worked for me.

What is the final verdict on #keybase? Actually private and encrypted or is it more in the style of zuck’s newest plans of “privacy” where meta data and networks reign profitable but this time with verified id

With the recent #WhatsApp security issue, many people recommend #Keybase as alternative. Personally however, I certainly prefer products that own their security issues: And I'm not the only one who made such experience with the Keybase team. #infosec

Thinking of resurrecting my #keybase profile 🤔️ I think I should give it one more chance 😄️


@succfemboi please point me to evidence of this integration with #Keybase requiring non-free code to be shipped with #Mastodon. Otherwise Gargron has "merged proprietary integrations" many times, such as the feature that allows YT videos to embed when YT links are posted. So?

So whats the whole purpose of keybase. Can somebody explain it?


J'ai une bonne vingtaine d'invitations sur #keybase si cela vous intéresse, faites-moi signe !

