![]() ![]() This is a positive indication of how Zoom is treating Keybase following its acquisition and a step to attenuate the worries that the community had concerning the real intentions of the video conference company. The bug bounty received by the Sakura Samurai team for this finding was $1,000, while the hacking group commented that Zoom was very responsive to their reports. The patched releases came out on January 23, 2021, so it’s been a full month already. If you are using an earlier version, make sure to update your Keybase client immediately. Keybase Book: Keybase Docs Chat Here is the technical documentation for chat: Crypto describes the use of cryptography in chat. Thus, CVE-2020-23827 has already been reported to the firm and subsequently fixed with the release of Keybase 5.6.0 for Windows and Keybase 5.6.1 for macOS and Linux. I wish apps just expired messages by default. The average user doesn’t understand data persistence, or secure destruction of data. Which is already too late for sensitive messages. The discovery of the flaws came thanks to Zoom's bug bounty hunting program when it acquired the project back in May 2020. Keybase allows you to revoke keys but that assumes you are aware that the device has been compromised. These users may have their devices seized by the police for analysis so that the “physical access” part wouldn’t be far-fetched for a significant portion of Keybase’s userbase. The best part about keybase is that is is. I like the fact that one does not have a limited search history. This is very bad, especially for users who have picked Keybase specifically to stay safe from authoritarian regimes. Keybase is not a single app, it is a suite of multiple apps and these apps are very likeable: Chat application: If you are a slack user and love the of inter company communication, Keybase runs a natively more secure Slack-esq chat app. Thus, if an attacker manages to establish local access onto the user’s machine, they could potentially access files that have supposedly been securely erased on Keybase. The app offers additional features to the website, such as the end-to-end encrypted chat, teams feature, and the ability to add files to and access private. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |