Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Keybase seems to rely on existing systems for trust anchoring (Twitter, Github...) as well as using existing cryptosystems for doing the heaving lifting (OpenPGP). If Github didn't reinvent the wheel because it's all Git, how did keybase.io reinvent the wheel by being all OpenPGP?


Its not all OpenPGP: it reinvents the web of trust part of OpenPGP instead of integrating with it. A more 'OpenPGP way' would've been to add a new uid to your OpenPGP key for each service (github/twitter/etc.), and have the 'service' (i.e. github/twitter/etc.) sign that uid on your key.

See also: https://news.ycombinator.com/item?id=7465564




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: