Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
csuwldcat
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
X401: HTTP-Native Identity Exchange for the Agentic Web
(proof.com)
6 points
by
csuwldcat
3mo ago
|
0 comments
2.
▲
The Future Is AI's Proof of Work
(backalleycoder.com)
7 points
by
csuwldcat
7mo ago
|
0 comments
3.
▲
by
csuwldcat
9mo ago
Yes, this is true, however, that means an external actor is able to execute arbitrary code in your origin, so they could also trick the user into signing malicious payloads with even the native passkey itself. There's more downside to
4.
▲
by
csuwldcat
9mo ago
Hmm, can you provide further details? I'm using it on Android in Chrome and Brave, and it works fine.
5.
▲
by
csuwldcat
9mo ago
That would either mean you have arbitrary, malicious code executing in the bound origin (the origin was hacked and shipped malicious code), or you allowed random callers externally to take signatures out of the boundary - don't do eith
6.
▲
by
csuwldcat
9mo ago
You can run the PassSeed code/mechanism on your own domain or localhost to ensure it's not subject to malicious host exfiltratuon. I agree that one should only trust a foreign host with low-security uses under this scheme.
7.
▲
by
csuwldcat
9mo ago
A roaming authenticator does not have access to a CTAP mechanism to query the platform’s credential store. CTAP defines how the platform queries a roaming authenticator, in that direction. There is no CTAP command whereby an authenticator q
8.
▲
by
csuwldcat
9mo ago
There's also the specific case of synced passkeys, which aren't exposed to CTAP management APIs for external parties, only to the OS/platform itself. You seem tied to a narrative where a user can install a native app that get
9.
▲
by
csuwldcat
9mo ago
It's not just about the WebAuthn API, you're talking about passkeys as if their key bundles are freely accessible to random userland actors, which is absurd. If that were the case, many assurances the platform makes would be out t
10.
▲
by
csuwldcat
9mo ago
The underlying CTAP implementations are only used by the platform to facilitate core activities, they are not used to expose key pairs to external parties. Please link to where any API offers up public keys to external userland actors, and
11.
▲
by
csuwldcat
9mo ago
No need for the "oh dear"-ing before you provide evidence. I'm not aware of any command for fetch or enumeration of public keys in CTAP (was rather confident it doesn't provide any such thing). Care to link to what you w
12.
▲
by
csuwldcat
9mo ago
It's a deliberate architectural decision that passkey authenticators not allow any retrieval or enumeration of key pairs - they don't even have internal APIs for it. This holds true for all known implementations, as it is a core p
13.
▲
by
csuwldcat
9mo ago
The interesting thing about Passkeys is that they are only ever output in the client create() call, and the platform does not retain them for disclosure after that, so if you don't send them out of the origin boundary, they are treated
14.
▲
by
csuwldcat
9mo ago
Saw your post above - I didn't "assert falsehoods", both are missing major browser support: https://caniuse.com/mdn-api_credentialscontainer_get_publick... https://caniuse.com/mdn-api_credenti
15.
▲
by
csuwldcat
9mo ago
I addressed this in the post - neither is available across all major browsers: https://backalleycoder.com/posts/passseeds-an-experiment-in-... Ironically, you could make a pollyfill for the PRF functionality with this.
16.
▲
by
csuwldcat
9mo ago
How it's better: automatically synced across all a user's devices, not subject to manual interactions with input fields (you can't programmatically request/regen passwords the same way you can with this). I did use AI fo
17.
▲
by
csuwldcat
9mo ago
Just sounded cooler , and I was on the team that worked on Passkeys at Microsoft, so I wanted to poke them a bit (in a friendly way).
18.
▲
PassSeeds – hijacking Passkeys to unlock new cryptographic use cases
(backalleycoder.com)
58 points
by
csuwldcat
9mo ago
|
40 comments
19.
▲
by
csuwldcat
9mo ago
Passkeys can be hijacked to serve as cryptographic seed material that is securely synced across all of a user’s devices, enabling the generation of a wide range of cryptographic keys. This allows Passkeys to power use cases far beyond what
20.
▲
by
csuwldcat
8y ago
Also take a look at DIF's Identity Hub - a large-scale initiative that goes far beyond a social server/mailbox, and incorporates solutions for the identity issues people here have flagged: https://github.com/decent
21.
▲
by
csuwldcat
9y ago
This is unrelated to any previous demo/work Accenture has shown. (I work on this @ MSFT)
22.
▲
by
csuwldcat
9y ago
Other way around: the sat system supports Bitcoin, not BCash.
23.
▲
by
csuwldcat
9y ago
Correct - you can increase the units in circulation without destroying the purchasing power of those who currently hold the asset, which is a huge advantage over traditional fiat currency.
24.
▲
by
csuwldcat
9y ago
Property is subject to bubbles, and in almost any economic recession prices of real estate tend to fall (demand drops, and sellers/supply grows). Bitcoin is a far better asset hedge, as it possesses almost every property of commodities
25.
▲
by
csuwldcat
9y ago
False - mining in Bitcoin (which is really just transaction processing) is based on a math/crypto difficulty algo, and the system automatically adjusts itself every ~two weeks to fit the load/prevalence of miners and their block-f
26.
▲
by
csuwldcat
9y ago
Bitcoin is a store of value that will long-term net-increase as true monetary bubbles, like this: http://imgur.com/a/0ZoDu , pop and cause their base currencies to long-term net-decrease.
27.
▲
by
csuwldcat
9y ago
I went to a Cal State university - it was a joke.
28.
▲
by
csuwldcat
9y ago
Drug purchasing sites have actually helped reduce violence and crime associated with prohibited items/activities. I'm more nervous about where authoritarian government is taking us.
29.
▲
by
csuwldcat
9y ago
You forgot to account for two significant factors: that 40% of Californians pay no state income tax, and that California dramatically skews toward higher brackets paying for the state's expenditures - the top 1% already pay an absurdly
30.
▲
by
csuwldcat
9y ago
He should have just flown to Oklahoma instead: http://reason.com/blog/2017/01/27/what-happens-when-doctors-...
More ›