Hacker News new | past | comments | ask | show | jobs | submit login

...with the added security benefit of not uploading your private key on Keybase!



You can use Keybase with GPG without letting it handle your private key. (I do.)


You can but last time I used it the first option you were presented with was giving keybase your key. I don't know if that's changed years later because I closed the app at that point, I wasn't interested in using or encouraging others to use such a thing. The guy pointing this out was downvoted and I frequently see the fact that its possible to not give them your key presented as somehow making it acceptable that they ask for it.


Same for me.


How is publicly sharing your public key a security flaw?


Keybase would prefer to handle your private key too. You can work with your key offline too, but you have to be aware that this is what you want when setting up- and it's very much not the happy path, so the site will not fully work as you might expect.

Not faulting them, they provide the steps needed, but it might be annoying enough for some people to start uploading private keys.


I've signed up a long time ago (yay early adopters I guess), so I can't comment on the sign up process or setup with your own GPG key nowdays.

But their website works 100% and provides all the functionality if you don't let them host the private key (they give you an easy-to-inspect snippet to paste into your terminal that downloads/signs/uploads things for them. Note, it does do anything when you paste - you need to manually hit enter)

Not disagreeing with you - Just adding my 2c.


It works fine; you just have to know up front to not just click "yes" for everything during the sign-up process. Not a big deal for people who already know how GPG works, but the whole point of Keybase is to make it easier to use for people new to crypto, and that audience can't be expected to understand that the default settings are a terrible idea.


I'm talking about uploading your private key. Obviously, it's required if you want keybase to sign on your behalf.


Which I have opted not to do as a over a decade user of GnuPG. But for complete newbs, JavaScript managed keys is preferable to no key at all.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: