Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jesseendahl
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
jesseendahl
1mo ago
Majority of second factors are phishable. If you are using a password (phishable) + a phishable second factor (any kind of 6 digit code that you need to type or paste into a text box), you are less secure than if you were using only a passk
2.
▲
by
jesseendahl
1mo ago
>They want you dependent on them and locked into their ecosystem. This is a strange conclusion to come to when clearly a lot of effort was put into developing an open standard (Credential Exchange Format) to make it easy and secure to mo
3.
▲
by
jesseendahl
1mo ago
>I thought the point of storing secrets in hardware TPM and not giving them out into userspace (i.e. passkeys instead of passwords) is protecting against malware as well. This was never a design goal of passkeys as far as I'm aware,
4.
▲
by
jesseendahl
2mo ago
Password managers do not architecturally, cryptographically make phishing impossible. Ultimately a user can still be tricked to copy/paste their passwords into fake websites, even when using a password manager. You could blame end-user
5.
▲
by
jesseendahl
2mo ago
Passwords are still significantly less secure than passkeys even when using a password manager.
6.
▲
by
jesseendahl
2mo ago
I like it. The high level UX of this idea feels very compelling to me as a "yes and" -- aka a world where vendors continue to offer end-to-end encrypted syncing within an ecosystem, but then this idea gets layered on to solve th
7.
▲
by
jesseendahl
2mo ago
> I don’t see hardware tokens (like Yubikey) in the list. Those are the only ones that provide a true second factor passkeys are not meant to be a second factor; they are meant to replace the password as a primary factor. >to protect
8.
▲
by
jesseendahl
2mo ago
There are some parts of this that are correct and other parts that are incorrect: >1. The idea was to provide a phishing resistant authentication method for enterprise users (companies loose quite a lot of money to phishing). This is inc
9.
▲
by
jesseendahl
2mo ago
This is the #1 most common misconception I see about passkeys. They do not make it more likely that you will lose access to your accounts. They actually have nothing to do with account recovery. They are just a stronger primary factor than
10.
▲
by
jesseendahl
2mo ago
>Passkeys and 2FA are a usability nightmare if you need to recover, or all the security vanishes if you put usable recovery mechanisms for the passkey or the second factor. Most providers continue to offer email-based recovery in the cas
11.
▲
by
jesseendahl
2mo ago
> Which defeats part of the point of passkeys in the first place in that they are supposed to be device-bound If you watch the original Apple WWDC talk presenting passkeys, you will find that they were always intended to sync, at least f
12.
▲
by
jesseendahl
3mo ago
This part of their requirements for how PCC is architected directly addresses your concern: “Verifiable transparency. Security researchers need to be able to verify, with a high degree of confidence, that our privacy and security guarantees
13.
▲
by
jesseendahl
4mo ago
No, it is not. And if you fall in love and want to get married to someone on a student visa, your fiancée should not need to leave the country for a year or two to wait for paperwork to process. Which is one of the real world impacts of thi
14.
▲
by
jesseendahl
5mo ago
This is true at companies that treat security as a checkbox driven by compliance. Not true at top-tier tech companies building software in product categories that by their nature have very high security requirements, like Fintech (e.g. Coin
15.
▲
by
jesseendahl
5mo ago
There are so many bots/trolls on HN now, it's crazy.
16.
▲
by
jesseendahl
5mo ago
What do you mean “just tap and hide a SMS”? Maybe my brain isn’t fully booted and I need more coffee, but I’m not understanding what this means.
17.
▲
by
jesseendahl
6mo ago
This story was recently on first page of HN: https://techcrunch.com/2026/03/18/fbi-is-buying-location-dat... This is the bill referenced at the end of the TechCrunch article: > Last week, Wyden and several
18.
▲
The Government Surveillance Reform Act of 2026 [pdf]
(wyden.senate.gov)
9 points
by
jesseendahl
6mo ago
|
2 comments
19.
▲
by
jesseendahl
7mo ago
You don't need to use anything from Apple/Google/Microsoft. Passkeys are just WebAuthn which is an open standard.
20.
▲
by
jesseendahl
7mo ago
Passwords are terrible UX for old people in my experience. They try use the same password everywhere, but then password complexity requirements mean they can't use the exact same password everywhere, and then they forget which varian
21.
▲
by
jesseendahl
7mo ago
>They bind you to your device/iCloud/Gaia account so if it gets stolen/banned you're out of luck This is the biggest myth/misconception I see repeated about passkeys all the time. It's a credential just like
22.
▲
by
jesseendahl
8mo ago
I am not sure if you missed my earlier comment, but it's directly applicable to this point you've repeatedly made: >If Apple believes this class of attack is no longer viable, that’s worth stating. To say it more directly this
23.
▲
by
jesseendahl
8mo ago
Apple's head of SEAR (Security Engineering & Architecture) just gave the keynote at HEXACON, a conference attended by the companies who make Pegasus such as NSO Group. That doesn't seem like avoiding the elephant in the room t
24.
▲
by
jesseendahl
8mo ago
Finneas (Billie Eilish's brother) isn't one for virtue signaling from what I've seen over the years from his posts. He keeps it very real and down to earth as far as celebrities go.
25.
▲
by
jesseendahl
9mo ago
Both of the major smartphone companies (Google and Apple) have pretty robust account recovery processes. Are you familiar with all the options they have? Your comment gives me the impression that you are making assumptions about what would
26.
▲
by
jesseendahl
9mo ago
There's nothing different about using a password vs. a passkey that makes it easier or harder for vendors to lock you out. I am not sure where this misconception comes from. Whatever process a vendor requires someone to go through in o
27.
▲
by
jesseendahl
9mo ago
(1) is already true today. There is no way for services to enforce whether a passkey is stored in software or hardware. (2) I understand you don't like the user experience. But to make a technical clarification: requiring a user action
28.
▲
by
jesseendahl
9mo ago
In theory any code could be written at any time that does something good or bad. Sure. But in reality, the people who actually work on these standards within the FIDO alliance do not want a world where every website/service makes arbit
29.
▲
by
jesseendahl
9mo ago
The primary credential a user relies on for logging in (whether it's a password or a passkey) is pretty unrelated to the the "lockout issue". The lockout issue is really the age old question of: what happens if I can't d
30.
▲
by
jesseendahl
10mo ago
People should be setting up Recovery Contacts so that they have a way of getting back into their Google account even if they lose all credentials (passwords and/or passkeys) and all their devices. https://blog.google/te
More ›