This is the first time I've heard of this but "All the users are connected through a central key server at key.upspin.io, which holds the public key and directory server address for each user"[1] sounds like they reinvented PGP's key server. To the best of my knowledge one can have arbitrary metadata in a published key[2], with the benefit that it's subject to revocation just like any other part of the key. I believe that's the whole idea that keybase.io was trying to build upon, although them orphaning their infra when Zoom bought them isn't lost on me
Comments
This is the first time I've heard of this but "All the users are connected through a central key server at key.upspin.io, which holds the public key and directory server address for each user"[1] sounds like they reinvented PGP's key server. To the best of my knowledge one can have arbitrary metadata in a published key[2], with the benefit that it's subject to revocation just like any other part of the key. I believe that's the whole idea that keybase.io was trying to build upon, although them orphaning their infra when Zoom bought them isn't lost on me
1: https://upspin.io/doc/arch.md
2: https://openpgp.dev/book/certificates.html#user-attributes-i...
I don’t understand why this is (was?) dead. Can someone address mdaniel’s comment and explain what is so egregious?