[HN Gopher] Keybase.pub Shutting Down on March 1 2023
___________________________________________________________________
Keybase.pub Shutting Down on March 1 2023
Author : Wingy
Score : 143 points
Date : 2023-02-08 15:49 UTC (7 hours ago)
(HTM) web link (keybase.pub)
(TXT) w3m dump (keybase.pub)
| crepererum wrote:
| https://keyoxide.org/ might grow into an alternative. It's still
| missing some convenience features, but the foundation looks sane.
| ocdtrekkie wrote:
| Keyoxide's developer has gotten some grants to really beef it
| up. One of the things Keybase really shines at is
| documentation, it makes a lot of GPG things pretty stress-free
| to deal with, and Keyoxide has room to improve on the user
| experience, polish, and documentation side.
|
| But since Keyoxide doesn't depend on a central authority to
| manage proofs, it is definitively going to be the future in
| this space. Nobody can really kill it.
| voidfunc wrote:
| KBFS was awesome for a small startup I worked at where we just
| needed some quick and dirty shared filesystems for development
| document sharing, quick scripts etc. Our onboarding for new folks
| used to be as simple as install your favorite distro, install
| keybase, run the onboarding script at $kbfsMountPoint and go get
| some coffee.
| benatkin wrote:
| Incredibly short notice. That feels like a sign of panic.
| rvz wrote:
| Exactly as suspected. [0]
|
| [0] https://news.ycombinator.com/item?id=34696606
| energybar wrote:
| are there any alternatives ?
| kodah wrote:
| I think I'd be happier if Keybase and Zoom would publicly commit
| to a direction for Keybase. I don't know what the acquisition
| details were for the OKCupid alumni but this dance of slow and no
| updates makes Keybase a risk when it comes to it's prospective
| usefulness in the future.
|
| I am glad it's just keybase.pub that's affected atm.
| client4 wrote:
| I still use Keybase and KBFS daily. It sounds like those services
| are around to stay -- but I hope if Zoom ever decides they don't
| want to keep running them anymore they spin it off to a non-
| profit to keep it running.
| qbasic_forever wrote:
| I would make plans to migrate to an alternative service sooner
| rather than later. Zoom is shedding employees and clearly in a
| cost cutting mode. It's only a matter of time before someone
| does the math and realizes shutting down a few of these
| services will save some more money.
| drcongo wrote:
| What alternative would you suggest? I really like Keybase and
| can't seem to find anything that covers the same
| functionality - been keeping an eye out since Zoom bought
| them.
| mperham wrote:
| I use the free Resilio Sync tier to keep a shared fold in
| sync between several servers. It's worked incredibly well
| for the last decade, no issues at all.
|
| You configure a secret token and all servers which know the
| token automatically sync via BitTorrent. You don't need to
| manage lists of server IDs like with syncthing, it's
| completely peer-to-peer.
| mwest wrote:
| The only one I've seen that comes close is
| https://keys.pub/ but it still misses a lot of what keybase
| gives (sigchains, etc.)
|
| Previous HN thread:
| https://news.ycombinator.com/item?id=22995792
|
| Are there any others to consider? It's been quite sad to
| see Keybase so stifled after being acquired. :-(
| qbasic_forever wrote:
| Yeah it sucks there isn't anything 100% like it. For just
| simple file syncing with end to end encryption I like
| syncthing. For encrypted data in a git repo there are more
| DIY options like using sops or similar tools.
| drexlspivey wrote:
| The coolest use of KBFS I found is a zero code real time chat
| app. One person types
|
| echo Hello >> /keybase/private/Alice,Bob/chat.txt
|
| while the recipient types
|
| tail -f /keybase/private/Alice,Bob/chat.txt
|
| and it just works!
|
| edit: end-to-end encrypted too!
| kseistrup wrote:
| Before keybase chat proper, I used tmux + bash to emulate a
| chat app that used kbfs as storage and transport medium:
| https://codeberg.org/kas/kbmsgr
|
| It only ever was a proof-of-concept and I haven't touched it
| for years. It may not be working anymore.
| rodolphoarruda wrote:
| Me too. File synchronization is a key feature for my work.
| onlyrealcuzzo wrote:
| Keybase is too good to be true.
|
| They probably need to charge close to $10/m just to break even
| for what you get for free.
| kej wrote:
| I'd happily pay twice that if they would let me.
| jimt1234 wrote:
| Keybase (the chat app) was hot for a while. However, everyone I
| know switched to Signal the day after Zoom acquired it. It's
| basically a ghost town now. ;(
| sleepybrett wrote:
| If all you want is chat, it's a fine alternative. If you want
| the other features, key managment, web of trust... less great.
| andrewstuart wrote:
| What a waste. There's a real need for identified users on the
| Internet - a service that other companies can subscribe to verify
| all sorts of users actions.
|
| I thought this would be it but they never seemed to see
| themselves as fulfilling that role, despite from the outside it
| looked like that was their big opportunity.
| t3e wrote:
| Check out https://www.hello.coop/ - super early, but they're
| building this, with an unusual governance structure designed to
| keep control in the hands of users.
|
| (I'm not affiliated with them.)
| epalm wrote:
| Keybase was really nice, until it started talking about wallets
| and coins and Stellar Lumens and no thank you. I jumped ship a
| while ago.
| ocdtrekkie wrote:
| This is the only time a startup company meaningfully gave me
| anything that was worth something long term. (Money.) I still
| appreciate it. I sold the crypto when it was worth like $700 or
| so.
|
| If I could pay to subscribe to Keybase, I could probably
| subscribe to it for several years before it cost me more than I
| made from using it. :D
| carrja99 wrote:
| Hey I didn't mind. During the latest bull run I looked into my
| wallet and realized I had $800 of stellar lumens on it.
| Transferred it out and got some additional money from it.
| anaganisk wrote:
| Me too, i was actually thrilled to get some random free money
| by doin nothing.
| LoganDark wrote:
| I am, honestly, really upset at this. I understand there was no
| guarantee that it would be up for any length of time, but it was
| a really convenient solution to a problem we had. I guess we have
| to find a different place for our passwords database that can be
| accessed over unauthenticated HTTP, but still very easily
| updated/accessed from any of our computers (without requiring
| manual uploads/transfers like with FTP).
|
| -Emily
| eropple wrote:
| Keybase is still running. The web hosting is being shut down.
| LoganDark wrote:
| Yes, and the web hosting is why we used them. It's not just
| the file sync. It's the file sync _and_ being able to access
| the file from any browser on any computer just by typing in a
| short, memorable URL.
|
| -Emily
| jacooper wrote:
| Use CF pages?
| LoganDark wrote:
| No, because what we need isn't just a static file host.
|
| If we wanted one, we'd use logandark.net. We use that server
| to host many static files. It's just not easy to upload them;
| it requires logging into a control panel, navigating to the
| directory, and manually uploading the file. And we're not
| particularly interested in provisioning a set of shell
| scripts or cron jobs or whatever to make it easier, because
| that's not an easily reproducible setup.
|
| -Emily
| JonChesterfield wrote:
| > I guess we have to find a different place for our passwords
| database that can be accessed over unauthenticated HTTP
|
| That's a strange sentence. Passwords shouldn't go over plain
| text (e.g. HTTP) and shouldn't be world-readable without
| authentication. If the database itself is encrypted then you
| could put it on any web server, even ye olde ftp, as a
| replacement for this service.
| dewey wrote:
| Unauthenticated http != plain text
|
| Looks like it's encrypted, so it shouldn't really matter:
| https://keybase.pub/logandark/passwords.kdbx
| LoganDark wrote:
| Indeed, that is it~ we use argon2id with some decent
| parameters. We may even up the parameters significantly
| when we switch to our desktop with an overclocked 12400F as
| a daily driver.
|
| -Emily
| LoganDark wrote:
| The purpose is to be able to download the encrypted database
| onto things like mobile devices that can't do anything like
| connect to FTP servers. Having a virtual filesystem is
| convenient because we don't need to do constant shuffling and
| transferring when updating our database from a computer.
|
| "just put it on a normal web server" ignores the rest of the
| convenience that keybase.pub provided. It provided a virtual
| file system that can be accessed over plain HTTP. Sure, SSHFS
| exists but it's terrible and not fault-tolerant at all.
| Keybase did it way better.
|
| -Emily
| JonChesterfield wrote:
| Ah yes, that I sympathise with. Thank you for clarifying
| JimDabell wrote:
| > It provided a virtual file system that can be accessed
| over plain HTTP.
|
| It sounds like you want WebDAV? It's an extension to HTTP
| and you can mount it as a folder in most desktop
| environments without any additional software.
| LoganDark wrote:
| Oh, interesting, Windows supports it natively and we
| actually have a server (logandark.net) with WebDAV
| support. We may look into this actually, thank you!
|
| -Emily
| Wingy wrote:
| Maybe point a web server at your kbfs mount to make a
| similar service to keybase.pub but only for your own shared
| files.
| mxuribe wrote:
| I don't know your audience of expected users (e.g. just
| family, friends or customers, etc.)...But have you
| considered something like nextcloud? As @JimDabell noted,
| you get WebDav "for free" by using nextcloud....But of
| course there are other options to sync files.
| LoganDark wrote:
| The reason we liked keybase.pub is because we could just
| type in https://logandark.keybase.pub/passwords.kdbx to
| download the database to any of our devices that don't
| have the fully fledged virtual filesystem. I can't tell
| if Nextcloud offers any memorable URL like that.
|
| -Emily
| mxuribe wrote:
| I would say that nextcloud offers what you seek...Since
| nextcloud would live under a domain name (or subdomain
| name) that you control, hence ideally such a domain name
| would be memorable to you, i would say the scenario you
| noted is possible.
|
| Here's the brochure/"marketing-y" link to the nextcloud
| info around sharing, such as via links:
| https://nextcloud.com/sharing/
|
| And, here's the more in depth info that goes a little
| deeper: https://docs.nextcloud.com/server/latest/user_man
| ual/en/file...
|
| Note: Instead of sharing the file via memorable links, if
| possible, having each user download the nextcloud client
| and sync the file that way is more
| ideal/better/faster...of course, that approach may not
| align with your use-case. I hope the above helps! Good
| luck!
| chrisweekly wrote:
| FTA:
|
| It's just the keybase.pub web hosting service per se that's
| shutting down.
|
| > "No Keybase Filesystem (KBFS) data will be removed from any
| user public folders. All data will remain safe and viewable by
| others running Keybase. Other features of Keybase including Chat,
| KBFS, Teams, Git, Wallet and others will continue to run normally
| as well."
| sleepybrett wrote:
| for now. With zoom cutting 15% ...
| StreamBright wrote:
| Keybase is the only chat client I would pay for without
| hesitation.
| bchase wrote:
| I didn't know this exists. If I know this earlier, I have used
| it. Anyways, there's Github or IPFS.
| capableweb wrote:
| Clearly, you don't understand what Keybase is if you're
| suggesting that GitHub or IPFS is good alternatives :)
|
| As far as I know, there isn't anything that covers the same
| amount of features with the same security as Keybase,
| particularly the whole webring/authenticated accounts/chain
| that it's based on.
| xn wrote:
| I'm a daily keybase user, and I didn't even know keybase.pub
| existed.
| pydry wrote:
| I'm glad encrypted git is still running although its days are
| probably also numbered :(
| WXLCKNO wrote:
| I really like Keybase. I don't even use it much but if I had the
| choice of paying a few dollars per month or having it be shut
| down, I'd pay for sure.
|
| Maybe it's because development slowed down to a crawl but it has
| such an "old internet" feel to it. Like I'm using Kazaa or
| something.
|
| Edit: To clarify, I understand that Keybase is not shutting down.
| I'm just saying hypothetically if it shuts down, which isn't
| unlikely in the next few years.
| oefrha wrote:
| For commenters who can't be bothered to RTFA, and is somewhat
| confused because the Keybase name is used for a couple of not
| terribly related (on the surface) products: keybase.io the
| popular identity hosting service isn't going anywhere, what is
| being shut down is an unpopular file hosting service:
|
| > Although the service was a great showcase for the kinds of
| cool things that could be built with Keybase, the usage of this
| product never took off.
| capableweb wrote:
| > what is being shut down is an unpopular file hosting
| service
|
| Maybe unclear wording here, but to clarify: KBFS (Keybase
| FileSystem) is not being shut down, only Keybase.pub is,
| which is a service which exposes selected files from KBFS on
| the web.
|
| The file hosting (KBFSF) will still be a part of Keybase and
| remain working as-is.
| sleepybrett wrote:
| I'm just worried that it just gets chipped away to nothing.
|
| It's already in a state where a new platform, major os
| change, architecture change could kill the apps usability
| for me. It's just coasting now.
| anigbrowl wrote:
| I like it too, but I stopped using it because of the user
| interface. I should check it again, but the text was so tiny
| and the dark mode _so_ dark that more than one group I was in
| gave up and moved back to doing everything in Signal groups
| despite Keybase 's technical superiority for many purposes.
| It's a great tool that was just tiring to use, an issue which
| has been PGP's Achilles heel since the outset.
| vel0city wrote:
| From what I understand, Keybase will continue to exist and KBFS
| will even still keep the files. They just won't be publicly
| hosting those files as websites anymore.
| soulofmischief wrote:
| To further clarify, Keybase Sites based hosting should still
| work as far as I understand. I don't use keybase.pub and I'm
| a hardcore Keybase user, so I imagine most don't. You can
| still get hosting through Keybase Sites.
|
| EDIT: No, I'm probably wrong.
|
| https://book.keybase.io/sites
| bluehatbrit wrote:
| Are you sure about that? It's under the keybase.pub domain
| name according to the docs you linked. I would have thought
| that means it's going as well.
| soulofmischief wrote:
| I'm not sure, and under further investigation you might
| be right.
| soulofmischief wrote:
| All of these complaints in the comments... Not realizing the
| diplomacy probably involved in keybase.pub being the only real
| hit Keybase takes in this round of layoffs. I would take this as
| a glimmer of hope that the folk at Zoom still appreciate Keybase
| for the same reason they bought it.
| Rebelgecko wrote:
| Isn't Keybase pretty much a dead man walking now? Their android
| app hasn't been updated in 8 months (shortly after the
| acquisition) even though it had some showstopping bugs like
| crashes/hangs when typing indicators are enabled
| blitzar wrote:
| > Zoom still appreciate Keybase for the same reason they bought
| it
|
| Didnt they buy it to ick it up with some dirty form of
| surveillance capitalism?
| morley wrote:
| No. Zoom bought the company during the pandemic -- after a
| period of being criticized for their security practices -- to
| beef up their security engineering team. (I worked with
| several Keybase members when they worked at OkCupid, and
| later worked on projects with Keybase.)
| lprd wrote:
| I'm honestly surprised that keybase is still around. It's really
| cool what they've built, but how exactly are they keeping the
| lights on?
| mynameisvlad wrote:
| Simple, they were bought by Zoom in 2020.
| dcchambers wrote:
| It seems like it was actually the acquisition by Zoom that
| seems to have sent Keybase down this slow death march. It was
| obvious that the acquisition was in order to acquire the team
| to improve Zoom's own security posture, and they had no
| interest in the Keybase product itself.
|
| Since then, activity on the open source keybase repos has
| been minimal and they have not made any major product
| changes.^1,2 Basically just keeping the lights on. I give big
| props to the few folks at Zoom that are still pushing
| commits. Keybase is/was awesome.
|
| [^1]: https://github.com/keybase/client/graphs/contributors
| [^2]: https://github.com/orgs/keybase/repositories
| avree wrote:
| well they had raised $10 million and burned through almost
| all of it so I'm not sure you can describe the acquisition
| that effectively saved their company as "sending them down
| a death march"
|
| however, it's clear you're right - Zoom doesn't prioritize
| the product.
| dcchambers wrote:
| Oh yeah no arguments from me there, they were definitely
| burning through cash without a clear vision about where
| they were going to start making money. But had they not
| been acquired I am 100% positive they could have raised
| boatloads of more money in that crazy market from late
| 2020-early 2022.
| mynameisvlad wrote:
| I mean, they basically said as much when they bought it.
| They didn't buy it for the product, they bought it for all
| the folks who bring a wealth of cryptography knowledge.
| This was also around the time that Zoom had a LOT of bad PR
| around privacy and spying on users, IIRC.
|
| That said, Zoom is the reason the lights are still on, even
| if not a lot of work is being done on the product. Keybase
| never really had a solid marketable product to begin with,
| so I honestly don't see it going down another way. They
| seemed to be entirely set up to get acquired at some point,
| regardless who or what their plans were.
| coldpie wrote:
| Keybase's life cycle basically turned me completely cynical
| for how tech startups work. It was a really cool idea, but
| they had zero plans from the start for sustainability. They
| were clearly just shooting for an acquisition to pay off
| the VC and founders, leaving the tech to die in the curb.
| Makes me sad. I recognize it's a common pattern since
| forever, but this was the first one I felt personally let
| down by.
| Xeoncross wrote:
| Keybase open sourced some great stuff. I hope they will
| share the rest as well.
|
| If I had to choose between them not existing, or existing
| to be acquired then I'm glad they choose what they did.
| Sytten wrote:
| I feel HN as a double speak for startups. Lots of cheer
| for open source and free stuff, lots of hate for anything
| subscription-based, lots of noise for high salaries and
| then picachu surprise when stuff like this happens. If
| anything I am completely cynical on HN users and not much
| on startups getting bought...
| derefr wrote:
| There is a segment of the hacker community that believes
| that the _correct and noble_ purpose of a startup isn 't
| to build a stable company or find product-market fit, but
| rather to confuse VCs into temporarily paying some people
| to create the niche project they wanted to create anyway,
| but didn't have any way to keep the lights on while
| building; where the _correct and noble_ end-goal of such
| a project is to avoid acquisition, use up all its runway
| paying the employee salaries, and, upon shutdown, open-
| source the IP (and hook the employees up with their next
| startup doing the same thing.) That "shutdown and
| release FOSS" step is seen by this segment as not only
| the _intended_ outcome of the startup, but the entire
| purpose /mission of creating the startup in the first
| place. With any messaging to the contrary existing solely
| to make VCs complacent, rather than because the founders
| actually believe it.
| psadauskas wrote:
| That sounds _way_ better than making a handful of very
| wealthy people a little more wealthy, while leaving
| employees and customers in the cold after the
| acquisition. I wish that segment of the hacker community
| were larger...
| aliqot wrote:
| And a lot of us are the most able to pay for these things
| we use for free, but don't.
| panick21_ wrote:
| Actually lots of people asked to pay for the service and
| wanted them to accept money. Nobody is against
| subscription if it comes to things like remote resources.
| dcchambers wrote:
| Holding out hope that Zoom will open-source the server
| side of things and perhaps let a foundation take over
| maintenance/ownership of Keybase.
|
| There's clearly value there, but yeah they need to find a
| way to make it sustainable.
| ljm wrote:
| Portfolio startup/Startfolio: business (chiefly
| technical) created with the primary, if not sole, aim of
| acquisition by a larger startup
| howmayiannoyyou wrote:
| 100% on this. What made this sad was the mission of
| Keybase and its founder appears to have been b.s. in the
| face of enough zeroes on a check.
| coldpie wrote:
| Remember when they got roped into some lame
| cryptocurrency pump-and-dump scheme? Hahaha. The joys of
| having VC debt and no business model.
| blitzar wrote:
| > in the face of enough zeroes on a check ... roped into
| some lame cryptocurrency pump-and-dump scheme
|
| It turns out the number of zeros required was zero.
| VadimPR wrote:
| This is a shame, Keybase's future is looking increasingly rocky.
| Has anyone got alternatives for team-based secrets sharing in an
| open-source project?
|
| Github secrets is one place but that's a one-way, write-only
| street.
| capableweb wrote:
| Keybase been on life-support since 2020, when Zoom acquired
| them and moved the entire team over to work on Zoom instead. If
| you haven't already, put a reminder for the near future to
| migrate away from Keybase, at one point it will disappear.
| robertlagrant wrote:
| I like SOPS [0], but it might be a bit heavyweight. You can
| also use team versions of password managers for simpler tasks.
|
| [0] https://github.com/mozilla/sops
| photoGrant wrote:
| Sucks.
___________________________________________________________________
(page generated 2023-02-08 23:01 UTC)