Jan 2, 2019 · 20m · a16z

a16z Podcast | Establishing Online Identity is Hard -- It Shouldn't Be

Max Krohn · 14m spoken Chris Dixon · 4m spoken Michael Copeland · 45s spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this episode of the a16z Podcast, Andreessen Horowitz partner Chris Dixon interviews Keybase co-founder Max Krohn about revolutionizing digital identity and public key encryption. They explore how Keybase connects cryptographic keys to social media footprints and client-side architecture to make end-to-end encryption accessible and practical for everyday users.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →

The host as informed peer 3.9 Guest teaching 2.4 Guest disagreement 0.3 The host pushing back 0.4
05100:0010:0020:000:53–3:05 · The host as informed peer 2/10 Founders' Background and Lessons from OkCupid Chris Dixon opens with a friendly background question about Max Krohn's history at OkCupid and SparkNotes. Max collaboratively connects social engineering and user onboarding lessons from online dating to public key infrastructure adoption.3:05–6:22 · The host as informed peer 7/10 Fundamental Principles of Public Key Encryption Chris Dixon actively demonstrates his own cryptographic knowledge, explaining 1990s key signing parties and how public keys are paired to individual identities. Max confirms and expands on the friend-of-a-friend trust graph concept.6:22–10:16 · The host as informed peer 7/10 Social Media Handles as Modern Identity Verification After Max explains legacy server architecture vulnerabilities, Chris intervenes with an expert breakdown of perimeter defense flaws and customized spear-phishing attacks. The dynamic remains highly collaborative and aligned.10:16–12:32 · The host as informed peer 3/10 Keybase Architecture and System Compromise Mitigation Chris asks a straightforward question about Keybase's threat model during a server compromise. Max educates on end-to-end client-side encryption and hardware key isolation.12:32–15:11 · The host as informed peer 5/10 Overcoming Password Friction with Cryptographic Signing Chris challenges the security community for blaming non-technical users for password failures rather than fixing UX friction. Max enthusiastically agrees and contrasts passwords with SSH-style cryptographic public key signing.15:11–17:41 · The host as informed peer 2/10 Open Source Philosophy and Developer Integration Chris prompts Max to explain Keybase's open source strategy. Max elaborates on building cryptographic trust through code auditability and avoiding forcing developers to reinvent low-level protocols.17:41–20:51 · The host as informed peer 1/10 Growth Hacking and Streamlining User Onboarding Max delivers a extended monologue on growth hacking crypto adoption, contrasting Keybase with legacy GPG tools whose steep learning curve deters non-experts. The host only steps in at the end to thank the guest.0:53–3:05 · Guest teaching 1/10 Founders' Background and Lessons from OkCupid Chris Dixon opens with a friendly background question about Max Krohn's history at OkCupid and SparkNotes. Max collaboratively connects social engineering and user onboarding lessons from online dating to public key infrastructure adoption.3:05–6:22 · Guest teaching 2/10 Fundamental Principles of Public Key Encryption Chris Dixon actively demonstrates his own cryptographic knowledge, explaining 1990s key signing parties and how public keys are paired to individual identities. Max confirms and expands on the friend-of-a-friend trust graph concept.6:22–10:16 · Guest teaching 2/10 Social Media Handles as Modern Identity Verification After Max explains legacy server architecture vulnerabilities, Chris intervenes with an expert breakdown of perimeter defense flaws and customized spear-phishing attacks. The dynamic remains highly collaborative and aligned.10:16–12:32 · Guest teaching 3/10 Keybase Architecture and System Compromise Mitigation Chris asks a straightforward question about Keybase's threat model during a server compromise. Max educates on end-to-end client-side encryption and hardware key isolation.12:32–15:11 · Guest teaching 3/10 Overcoming Password Friction with Cryptographic Signing Chris challenges the security community for blaming non-technical users for password failures rather than fixing UX friction. Max enthusiastically agrees and contrasts passwords with SSH-style cryptographic public key signing.15:11–17:41 · Guest teaching 2/10 Open Source Philosophy and Developer Integration Chris prompts Max to explain Keybase's open source strategy. Max elaborates on building cryptographic trust through code auditability and avoiding forcing developers to reinvent low-level protocols.17:41–20:51 · Guest teaching 4/10 Growth Hacking and Streamlining User Onboarding Max delivers a extended monologue on growth hacking crypto adoption, contrasting Keybase with legacy GPG tools whose steep learning curve deters non-experts. The host only steps in at the end to thank the guest.0:53–3:05 · Guest disagreement 0/10 Founders' Background and Lessons from OkCupid Chris Dixon opens with a friendly background question about Max Krohn's history at OkCupid and SparkNotes. Max collaboratively connects social engineering and user onboarding lessons from online dating to public key infrastructure adoption.3:05–6:22 · Guest disagreement 0/10 Fundamental Principles of Public Key Encryption Chris Dixon actively demonstrates his own cryptographic knowledge, explaining 1990s key signing parties and how public keys are paired to individual identities. Max confirms and expands on the friend-of-a-friend trust graph concept.6:22–10:16 · Guest disagreement 0/10 Social Media Handles as Modern Identity Verification After Max explains legacy server architecture vulnerabilities, Chris intervenes with an expert breakdown of perimeter defense flaws and customized spear-phishing attacks. The dynamic remains highly collaborative and aligned.10:16–12:32 · Guest disagreement 0/10 Keybase Architecture and System Compromise Mitigation Chris asks a straightforward question about Keybase's threat model during a server compromise. Max educates on end-to-end client-side encryption and hardware key isolation.12:32–15:11 · Guest disagreement 1/10 Overcoming Password Friction with Cryptographic Signing Chris challenges the security community for blaming non-technical users for password failures rather than fixing UX friction. Max enthusiastically agrees and contrasts passwords with SSH-style cryptographic public key signing.15:11–17:41 · Guest disagreement 0/10 Open Source Philosophy and Developer Integration Chris prompts Max to explain Keybase's open source strategy. Max elaborates on building cryptographic trust through code auditability and avoiding forcing developers to reinvent low-level protocols.17:41–20:51 · Guest disagreement 1/10 Growth Hacking and Streamlining User Onboarding Max delivers a extended monologue on growth hacking crypto adoption, contrasting Keybase with legacy GPG tools whose steep learning curve deters non-experts. The host only steps in at the end to thank the guest.0:53–3:05 · The host pushing back 0/10 Founders' Background and Lessons from OkCupid Chris Dixon opens with a friendly background question about Max Krohn's history at OkCupid and SparkNotes. Max collaboratively connects social engineering and user onboarding lessons from online dating to public key infrastructure adoption.3:05–6:22 · The host pushing back 0/10 Fundamental Principles of Public Key Encryption Chris Dixon actively demonstrates his own cryptographic knowledge, explaining 1990s key signing parties and how public keys are paired to individual identities. Max confirms and expands on the friend-of-a-friend trust graph concept.6:22–10:16 · The host pushing back 0/10 Social Media Handles as Modern Identity Verification After Max explains legacy server architecture vulnerabilities, Chris intervenes with an expert breakdown of perimeter defense flaws and customized spear-phishing attacks. The dynamic remains highly collaborative and aligned.10:16–12:32 · The host pushing back 0/10 Keybase Architecture and System Compromise Mitigation Chris asks a straightforward question about Keybase's threat model during a server compromise. Max educates on end-to-end client-side encryption and hardware key isolation.12:32–15:11 · The host pushing back 3/10 Overcoming Password Friction with Cryptographic Signing Chris challenges the security community for blaming non-technical users for password failures rather than fixing UX friction. Max enthusiastically agrees and contrasts passwords with SSH-style cryptographic public key signing.15:11–17:41 · The host pushing back 0/10 Open Source Philosophy and Developer Integration Chris prompts Max to explain Keybase's open source strategy. Max elaborates on building cryptographic trust through code auditability and avoiding forcing developers to reinvent low-level protocols.17:41–20:51 · The host pushing back 0/10 Growth Hacking and Streamlining User Onboarding Max delivers a extended monologue on growth hacking crypto adoption, contrasting Keybase with legacy GPG tools whose steep learning curve deters non-experts. The host only steps in at the end to thank the guest.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 0% · guest 100%0:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%
Sharpest disagreement ▶ 19:55 Mocking GPG manual page complexity

In a very low-combativeness episode, Max offers his sharpest critique toward traditional PGP/GPG tool usability, scoffing at the notion that average programmers read GPG manual pages.

Hardest push from the host ▶ 12:28 Pushing back against security community dogma

Chris explicitly rejects the security industry's standard framing that places the blame on non-technical users for failing to maintain complex passwords.

Biggest teaching moment ▶ 14:20 Replacing password authentication with key signing

Max clearly explains how public key cryptographic signing eliminates password vulnerabilities, drawing on how SSH developers log into servers without passphrases.

The host holds their own ▶ 8:50 Detailed breakdown of perimeter security flaws

Chris demonstrates deep security expertise by framing perimeter defense as a guarded building filled with gold and explaining modern customized spear-phishing attack vectors.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
Founders' Background and Lessons from OkCupid 2100 Chris Dixon opens with a friendly background question about Max Krohn's history at OkCupid and SparkNotes. Max collaboratively connects social engineering and user onboarding lessons from online dating to public key infrastructure adoption.
Fundamental Principles of Public Key Encryption 7200 Chris Dixon actively demonstrates his own cryptographic knowledge, explaining 1990s key signing parties and how public keys are paired to individual identities. Max confirms and expands on the friend-of-a-friend trust graph concept.
Social Media Handles as Modern Identity Verification 7200 After Max explains legacy server architecture vulnerabilities, Chris intervenes with an expert breakdown of perimeter defense flaws and customized spear-phishing attacks. The dynamic remains highly collaborative and aligned.
Keybase Architecture and System Compromise Mitigation 3300 Chris asks a straightforward question about Keybase's threat model during a server compromise. Max educates on end-to-end client-side encryption and hardware key isolation.
Overcoming Password Friction with Cryptographic Signing 5313 Chris challenges the security community for blaming non-technical users for password failures rather than fixing UX friction. Max enthusiastically agrees and contrasts passwords with SSH-style cryptographic public key signing.
Open Source Philosophy and Developer Integration 2200 Chris prompts Max to explain Keybase's open source strategy. Max elaborates on building cryptographic trust through code auditability and avoiding forcing developers to reinvent low-level protocols.
Growth Hacking and Streamlining User Onboarding 1410 Max delivers a extended monologue on growth hacking crypto adoption, contrasting Keybase with legacy GPG tools whose steep learning curve deters non-experts. The host only steps in at the end to thank the guest.

Statements from this episode (12)

Prediction Not checkable as stated
Krohn: People will increasingly need digital identity mapping
“We started Keybase a little bit over a year ago just because we were convinced that in the future people would really see a need for mapping what they considered notions of identity that computers could understand.”
Max Krohn Jan 2, 2019 ▶ 1:03
Insight
Krohn: Consumer crypto onboarding shares challenges with early online dating platforms
“So in that respect, we think that our experience at OkCupid is very helpful for moving into something like getting crypto to be popular for more people. There's a lot of common elements of user recruitment and user onboarding and making people like the product…”
Max Krohn Jan 2, 2019 ▶ 2:42
Assertion Not checkable as stated
Dixon: Key signing parties were identity verification standard pre-social media
“It was the best practice until we had Twitter and Reddit and Facebook.”
Chris Dixon Jan 2, 2019 ▶ 4:36
Opinion
Dixon: Twitter handles offer better identity verification than physical driver's licenses
“You know, in some ways now The Twitter handle is, is, is almost more verification than their driver's license.”
Chris Dixon Jan 2, 2019 ▶ 6:47
Insight
Krohn: Systems should prevent servers from viewing plain-text user data
“The way we should be building systems is that If the server doesn't need to see the data or access the data that you're putting onto it, then it just shouldn't. There's no reason why it has to see it, then the data should be not available to the server in plai…”
Max Krohn Jan 2, 2019 ▶ 8:36
Opinion
Krohn: Perimeter security for major cloud providers is an impossible task
“It's just that they've chosen to do a job that's basically impossible, that, that no one can really do. Relative to all the threats that are lined up against them.”
Max Krohn Jan 2, 2019 ▶ 10:02
Assertion Supported
Krohn: Keybase servers store no user decryption keys
“If anyone ever breaks into the server, all they really get is a bunch of encryption, and Unlike with other systems, the key you need to decrypt the data is just not on the server. The only person who has a key is like, is the phone in your pocket or the deskto…”
Max Krohn Jan 2, 2019 ▶ 11:02
Opinion
Dixon: The security community unfairly blames non-technical users for breaches
“It feels like a lot of the security community just tries to push these the burden onto users and say, well, it's the user's fault for not doing all of these complicated measures when in fact, you know, of course the users mostly aren't technical and aren't sec…”
Chris Dixon Jan 2, 2019 ▶ 12:52
Insight
Krohn: Cryptographic public key signing is far superior to password authentication
“What you ought to be doing is signing a statement saying, I'm Max, and I want to log into this service, and the service would just have your public key. You know, Max is identified with this public credential, and as long as he's able to sign a statement with …”
Max Krohn Jan 2, 2019 ▶ 14:26
Insight
Krohn: Security software cannot be trusted unless the code is open source
“Because we're building software that we think people need to trust, there's no possible way that people can trust us unless they get to see what the code actually is and how the software we're writing is using crypto and is using The various things that we tal…”
Max Krohn Jan 2, 2019 ▶ 15:25
Insight
Krohn: Building crypto apps today is like forcing developers to implement TCP/IP
“I think the status quo is now, I mean, a good analogy would be like, you know, hey, you want to write Photoshop, but with photo sharing, you know, you first have to implement TCP IP before you can get that done. I mean, that's kind of the world we live in righ…”
Max Krohn Jan 2, 2019 ▶ 17:08
Insight
Krohn: Communication apps fail without low recipient onboarding friction
“We have to really allow the operation to go through as far as possible, as far as the sender is concerned, and then get the receiver onboarded also with minimum friction. And I think unless an application does that, it's doomed to fail.”
Max Krohn Jan 2, 2019 ▶ 19:10
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.