Keybase, the company that asks you to upload your private keys to their servers, has just been acquired by Zoom, an essentially Chinese company notorious for having terrible concepts on how encryption should be implemented.

Even if you gave Keybase the benefit of the doubt beforehand, this is corporate suicide at it's most graphic. Delete your Keybase keys. Close your account. Rotate everything that Keybase touched, be that password or cryptomaterial.

blog.zoom.us/wordpress/2020/05

@kline They only have access to my public keys. They give an option for you to retain your own private key. In this configuration it is perfectly safe and provides a useful service to retain it.

Not happy with zoom aquiring them but until it poses a security risk or until an alternative comes online its usefulness will cause me to continue to keep my account.

@freemo there's no way for other users to identify if they have anything more than your public key.

I can't communicate with anyone who uses Keybase with a given public as I can't verify ahead of time if they uploaded the private key or not.

It might be safe from your point of view looking out, but not for others looking in.

@kline
Show me the portion where #Keybase uploads a private PGP key unencrypted to their server.
@freemo

@erAck

They dont do it "unencrypted" but i can attest that giving them your private key so they can encrypt things for you server side is an option. Though you also have the choice to not upload the private key which means you can still do all the same operations but the commands are a bit more complicated, so people are sometimes compelled to give them your private key instead.

You will see the option if you try to setup a new account or new key.

@kline

@freemo
Yes, I _could_ upload a secret key, but it's not needed for anything functionality wise.
@kline

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.