# Discourse Keybase Proof

**URL:** https://meta.discourse.org/t/discourse-keybase-proof/115239
**Category:** Feature
**Tags:** pr-welcome
**Created:** [April 16, 2019, 4:22pm UTC](https://meta.discourse.org/t/discourse-keybase-proof/115239 "2019-04-16T16:22:48Z")
**Posts on this page:** 1
**Showing post:** 7

<div class="post-metadata">

### Author: ![nealmcb](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nealmcb/32/107350_2.png) [@nealmcb](https://meta.discourse.org/u/nealmcb)
#### Post date: [May 15, 2019, 5:47pm UTC](https://meta.discourse.org/t/discourse-keybase-proof/115239/7 "2019-05-15T17:47:49Z")

</div>

I note that there have been lots of conversations in this forum over at least the last 4 years showing a strong desire for encrypted communications in Discourse. And they usually end up noting that it is a really hard problem, especially when encrypted group chats are considered, and that integrating with Keybase is a recommended alternative for a variety of reasons.

So I would advise those who really do want convenient, robust, encrypted communications to support this integration work, which is far easier than the work already in process, and does provide group chats and much more, all reliably tied to users based on their Discourse persona.

Here are a few references, starting with a wise quote from co-founder [Sam Saffron](https://meta.discourse.org/u/sam)[sam](https://meta.discourse.org/u/sam)[co-founder](https://meta.discourse.org/g/team) about flaws with any web-based solution like Discourse:

> [@Encrypted PGP Messaging](https://meta.discourse.org/t/encrypted-pgp-messaging/19149/53):
>
> The underlying issue is that you can not trust the server if you want truly secure messaging between members. This means that the software used to encrypt and decrypt stuff should not be sent from the discourse server. I second what was said here, you want something like keybase or signal for secure comms, you have to invest in training here. Treat the info you have on Discourse as potentially leaked, there are just too many vectors. People hosting the service, web browser caches on local comp…

Note that Keybase solves this by having native clients for many platforms.

Next up, on the current [Discourse Encrypt project](https://meta.discourse.org/t/discourse-encrypt-rfc/107918/26)

> > Sam, would there be any way to extend this functionality to a category/threads (and allow by groups?)

> Absolutely not, this is not in scope and not planned even 3 iterations out.

Next, the [RFC for Discourse Encrypt](https://meta.discourse.org/t/encrypted-personal-messages/98765) which notes that they also don’t plan to properly address the multiple device or loss-of-key issues that Keybase is designed to get right:

> the UI clearly explains that if she forgets this secret she will **NEVER** have access to her encrypted messages anymore

So again, please note that Keybase is now easy to integrate with, and that it solves problems that other solutions aren’t even planning to address.

---

_[View the full topic](https://meta.discourse.org/t/discourse-keybase-proof/115239)._
