Hacker News new | past | comments | ask | show | jobs | submit login

To clarify: Keybase.io, like Signal, Whatsapp and Telegram above, is encrypted but not P2P - all of them rely on centralized servers.



and thats where the vulnerability is, in the centralized servers


The only vulnerability introduced by the servers at keybase is denial of service. I believe the protocol and clients are open source and there is no need to trust their servers for the key distribution part either (keys are cryptographically verified from a variety of sources like DNS, Twitter, Reddit, HN for each recipient)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: