Full Disclosure mailing list archives
Re: keybase.io
From: Tony Arcieri <bascule () gmail com>
Date: Sat, 21 Jun 2014 14:15:59 -0700
On Fri, Jun 20, 2014 at 1:22 PM, Rikairchy <blakcshadow () gmail com> wrote:
Why would a website focused on providing security allow users to upload their private keys?
They are willfully creating a less secure system in hopes of making it popular. Supporting private key upload completely changes the threat model, from the end-to-end system they are allegedly trying to supplement, to one that's no different from just using TLS and a central service. I hope it's clear to any security enthusiasts where their priorities lie. Security takes a backseat to popularity. That's the wrong set of priorities for secure software. -- Tony Arcieri _______________________________________________ Sent through the Full Disclosure mailing list http://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Current thread:
- keybase.io Rikairchy (Jun 21)
- Re: keybase.io Dennis E. Hamilton (Jun 22)
- Re: keybase.io Attilla de Groot (Jun 22)
- Re: keybase.io Tony Arcieri (Jun 22)
- Re: keybase.io Robert Dannhauer (Jun 22)
- Re: keybase.io Tony Arcieri (Jun 23)
- Re: keybase.io Jonathan Care (Jun 23)
- Re: keybase.io Tony Arcieri (Jun 25)
- Re: keybase.io Tony Arcieri (Jun 23)
- Re: keybase.io Sam Stewart (Jun 25)
- Re: keybase.io Nick Boyce (Jun 23)