@dansup @sean Security is no joke, but #Keybase is.
How many users’ privkeys are stored on KB’s servers (this was the default in the beginning, and last I looked, some of their services still required it) where badguys can exfiltrate them and assume those users’ “verified” identities?
A web of rel=me links, with a user-controlled index (signed with their own GPG key) does the same job without any “upload your privkey” shenanigans.