Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> When you upload a pgp key to keybase, it encrypts the key again, using your keybase device key.

Except that long time ago, when device keys didn't even exist, there was a feature on Keybase website that allowed to upload a PGP private key encrypted only by your account password (which was never transmitted to Keybase in plaintext though – it was scrypted in browser when logging in, too – but this still means your private key was as secure as your password, which isn't a good practice in my opinion).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: