Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
PassageNick
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
PassageNick
4y ago
This is a great question. I think the biggest barrier to adoption is lack of end user demand for the service. That is followed by people not understanding/believing the incredible increase in user experience and security. It's al
2.
▲
by
PassageNick
4y ago
It is not clear to me what they are implementing here. There is not mention of passkeys anywhere.
3.
▲
by
PassageNick
4y ago
Not sure I follow.... Biometrics are very difficult to impossible to reproduce short of physical coercion.
4.
▲
by
PassageNick
4y ago
Passwordless is actually MFA -- Something you have (your device) Something you are (your biometric) Those are definitely two factors that are required to be together for passwordless to work
5.
▲
by
PassageNick
4y ago
>> I hate having to rely on having my phone handy to log into anything.<< This isn't the case. Nothing about passkeys says you need your phone to login on a website with your laptop, for instance.
6.
▲
by
PassageNick
4y ago
The problem with legislation like this is that it eliminates the possibility of better solution. What happens if someone invents a better interface than USB 3.0? Or better, why would anyone bother when a better interface couldn't be u
7.
▲
by
PassageNick
4y ago
No -- every origin has it's own Public/Private key that is stored on the TPM chip on your device. The TPM is designed specifically for securing these keys. Each passkey is a modest amount of data, and I don't see a person ha
8.
▲
by
PassageNick
4y ago
That's a great article, thanks. In fact, it's a fantastic article. I read it a couple of weeks ago, and learned a lot. Thanks. Apple's changes do degrade security, but I think it is important to note that even with those deg
9.
▲
by
PassageNick
4y ago
....and can you explain the cookie theft thing a bit more?
10.
▲
by
PassageNick
4y ago
If you can take a photograph of someone's fingerprint and reproduce it, how, exactly, does one use that?
11.
▲
by
PassageNick
4y ago
They cannot block access. The passkeys are actually stored on your devices in a Trusted Platform Module. When moved to the cloud, they are E2E encrypted, and the transferring platform has zero knowledge of your keys. Currently, you cannot
12.
▲
by
PassageNick
4y ago
Passwordless is MFA -- something you are and something you have. I'm not a yubikey expert, but I don't believe that losing your Yubikey will open up your company to a breach. For a typical passwordless solution, losing your phone
13.
▲
by
PassageNick
4y ago
You own your own passkeys on your own device, ultimately. Google/Apple/MS have no ownership or knowledge of the actual keys.
14.
▲
by
PassageNick
4y ago
Fair enough.
15.
▲
by
PassageNick
4y ago
Re: Yubikey -- I confess I don't know. The folks in r/yubikey definitely will, though. The "Big Three" are on the FIDO board, along with 1Password. They can't really do the extinguish thing, and it really isn'
16.
▲
by
PassageNick
4y ago
The threat surface of a password based system is like Lake Superior. The threat surface of a passkey based solution is like a small puddle after a rain. How is there a "reduction" in security here?
17.
▲
by
PassageNick
4y ago
Yeah, it is non-trivial to implement, but not impossible. Some folks go that route. There are SaaS solutions that implement it for you and make it easy to include in your app.
18.
▲
by
PassageNick
4y ago
(Full disclosure: I work at https://passage.id ) WebAuthn is the short name for the "FIDO Alliance Web Authentication Protocol". "Passkey" is the trade name (that Apple tries to own) for the "stuff"
19.
▲
by
PassageNick
4y ago
That's a quality aphorism.
20.
▲
by
PassageNick
4y ago
It seems strange to me that anyone would go anything but Cloud Native today.
21.
▲
by
PassageNick
4y ago
It's amazing how the attitude about not wanting to put data in the vendors hands has changed over the last ten years. I remember having a hard time to convince our CEO to use BitBucket in 2011 because our precious code (that no one wou
22.
▲
by
PassageNick
4y ago
(Note: I work for Passage.id, now part of 1Password...) Auth is pretty easy to implement, but difficult to get and keep right. Then there are the nooks and crannies that crop up and appear and get discovered that you have to be aware of a
23.
▲
by
PassageNick
4y ago
Well, no, that is not right. Passkeys most definitely not available to someone who steals your phone.
24.
▲
by
PassageNick
4y ago
WebAuthn is two-factor. In order to login, you have to provide 'something you have' (your device) and 'something you are' (your face, fingerprint, etc.)
25.
▲
by
PassageNick
4y ago
Passkeys cannot be taken or stolen by force.
26.
▲
by
PassageNick
4y ago
WebAuthn is not at all like saving your password in your browser. Passkeys (i.e.private keys) are stored in a virtually impregnable Trusted Platform Module and not available. Even if someone steals your device, they cannot access your pass
27.
▲
by
PassageNick
4y ago
The passkeys are stored in a Trusted Platform Module, and as far as I know, it is basically impregnable, even with access to the physical device.
28.
▲
What Is WebAuthn and How Does It Work?
(passage.id)
1 points
by
PassageNick
4y ago
|
0 comments
29.
▲
by
PassageNick
4y ago
The reason I ask is that I see certifications all over the place. Frankly, I couldn't care less about them, but wonder why some folks seem to want them and feel that they are valuable.
30.
▲
Ask HN: Do any of you care about developer certifications?
1 points
by
PassageNick
4y ago
|
4 comments
More ›