This saddens me because I think the concept behind Upspin is powerful. Is it really that much of a resource drain to drop the key server? I imagine it could run on a $10/mo VPS.
This is the first time I've heard of this but "All the users are connected through a central key server at key.upspin.io, which holds the public key and directory server address for each user"[1] sounds like they reinvented PGP's key server. To the best of my knowledge one can have arbitrary metadata in a published key[2], with the benefit that it's subject to revocation just like any other part of the key. I believe that's the whole idea that keybase.io was trying to build upon, although them orphaning their infra when Zoom bought them isn't lost on me
Comments
This saddens me because I think the concept behind Upspin is powerful. Is it really that much of a resource drain to drop the key server? I imagine it could run on a $10/mo VPS.
This is the talk that introduced Upspin: https://www.youtube.com/watch?v=ENLWEfi0Tkg
This is the first time I've heard of this but "All the users are connected through a central key server at key.upspin.io, which holds the public key and directory server address for each user"[1] sounds like they reinvented PGP's key server. To the best of my knowledge one can have arbitrary metadata in a published key[2], with the benefit that it's subject to revocation just like any other part of the key. I believe that's the whole idea that keybase.io was trying to build upon, although them orphaning their infra when Zoom bought them isn't lost on me
1: https://upspin.io/doc/arch.md
2: https://openpgp.dev/book/certificates.html#user-attributes-i...
I don’t understand why this is (was?) dead. Can someone address mdaniel’s comment and explain what is so egregious?