
Security products or privacy-focused products always seem to leave out theĬoercion aspect when it comes to actually secure a product. They need to formally charge you as a terrorist and then go through that The account unlocked - what more can they do. you have plausible deniability, they asked for the code, you gave it and
#Keybase 2fa code
If the person then is like, I don't believe you, give me the real 2fa code Ofc you could argue well if you don't keep activity up in the diversionĪccount that is going to fail, sure - that's not a reason to not provide Read this, 2 that goes to the real account, things are a lot more secure.

That as well, and if you had two setup, 1 that goes to the everyone can however with a 2nd factor, you then need to provide then they just open keybase and all your baseĪre belong to us. Like I'm at a certain chcekpointĪnd someone is like so, you want to keep going - unlock this screen you So if using lockdown - someone gets a hold of a device. i believe there really needs to be an application level barrier rather than "well if you give your device to someone and they tell you to unlock it, that's your fault, don't do that". once a device is authenticated if the device goes out of user-control it is on the user to revoke that device. Maybe keybase can't be 2fa'd effectively - that hasn't really been said in this thread though. and this forced compliance aspect is real and ever more invoked these days. sure it is more work, however, if the goal is privacy and security, it either is or it isn't. Security products or privacy-focused products always seem to leave out the coercion aspect when it comes to actually secure a product. pretty sure by this point they need to formally charge you as a terrorist and then go through that paperwork. If the person then is like, I don't believe you, give me the real 2fa code - you have plausible deniability, they asked for the code, you gave it and the account unlocked - what more can they do. ofc you could argue well if you don't keep activity up in the diversion account that is going to fail, sure - that's not a reason to not provide this feature/functionality. however with a 2nd factor, you then need to provide that as well, and if you had two setup, 1 that goes to the everyone can read this, 2 that goes to the real account, things are a lot more secure.

then they just open keybase and all your base are belong to us.

Like I'm at a certain chcekpoint and someone is like so, you want to keep going - unlock this screen you kind of have to do that. they can still just open the app and access everything.
