Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
markkum
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
markkum
12y ago
Supporting multiple devices is a hard problem. We worked for a long time to enable it. Not Bitcoin protocol specific, but some words about our asymmetric key based multi-device solution here; https://www.mepin.com/lost-devic
2.
▲
by
markkum
12y ago
Funnily; the reason to outsource is exactly about not putting all your eggs in the same shared basket. You outsource the 2nd factor and keep the first factor (passwords) in-house. Implementing everything in-house is a "same shared bask
3.
▲
by
markkum
13y ago
I can use similar arguments; a user can be tricked to enter an OTP to a phishing site. For that the hacker does not need to time the attack to the same second, so it's much much easier attack for the hacker. 'No 2FA' is the r
4.
▲
by
markkum
13y ago
Note that MePIN does not collect or need user's phone number, e-mail address or any other user information. You can use MePIN fully anonymously.
5.
▲
by
markkum
13y ago
Unfortunately there are several cases where users have entered an OTP code for another user. The recent high profile case was with World of Warcraft's OTP.
6.
▲
by
markkum
13y ago
Don't want to argue, but yes it would. It would stop the user for a second, giving time to the brain to process for a while what's going on.
7.
▲
by
markkum
13y ago
This is now fixed. Thanks for the kick.
8.
▲
by
markkum
13y ago
First; the user does not have to care about OS, browser, ip address or location. Though those can be shown to a user if the service provider wants. Authorization requests can only be initiated at the back-end by authorized service providers
9.
▲
by
markkum
13y ago
Of course user behavior has to be considered. The MePIN app does allow the user to set up a personal PIN code, so an authorization would then require the PIN code and a tap.
10.
▲
by
markkum
13y ago
The solution is based on Public Key Infrastructure (PKI). Each authorization must be signed with the user's private key. The app is managing and protecting the keys and certificates, so user does not have to figure out key/cert ma
11.
▲
by
markkum
13y ago
Working on it.
12.
▲
by
markkum
13y ago
The service is distributed and hosted at 3 continents with 3 different hosting providers, so we take this seriously. Other than that; You own your users and user database. No user data is stored at MePIN servers.
13.
▲
by
markkum
13y ago
It's easier because you only need to tap the app to verify. No need for OTP codes, though OTP is a fallback if your device is offline.
14.
▲
Show HN: The easiest 2-factor auth
(developer.mepin.com)
27 points
by
markkum
13y ago
|
29 comments
15.
▲
by
markkum
13y ago
This is the London I remember from early morning July 8th, 2005, the morning after the bombings. Was walking around to find a ride to the airport, couple of blocks from the double-decker wreck. Wish not to experience the same again.
16.
▲
by
markkum
13y ago
Well, yes and no. On iOS you can somewhat rely on keychain, but when the device is jailbroken all the local "simple API" security is gone. Generic Android doesn't really have anything that I would call secure, so there a seri
17.
▲
by
markkum
13y ago
The cool generalized version does exist :). Check out https://www.mepin.com/ We've got RSA 2048 keys on iOS, Android and a separate smartcard USB key, and do 2-factor login and transaction authorization with a simple t
18.
▲
by
markkum
14y ago
Hi, a new developer section for the site is in the works. Stay tuned.
19.
▲
by
markkum
14y ago
If you want something better for your site; check out MePIN https://www.mepin.com/
20.
▲
by
markkum
15y ago
You can sign in without username and password to OpenID enabled sites with your smartphone and Mepin; https://www.mepin.com/
21.
▲
by
markkum
15y ago
Here's an example Neko.io message for you; "I'm on a meditation trip in India. If you really need to bother me, here's my travel schedule and emergency number; https://neko.io/m/g4hF/xcjZq85lyL9TTAjefE1GLw/xGf_TME2-G9YRl... Neko.io is a u
22.
▲
by
markkum
15y ago
Not really. Clear text messages on Fb Friend List or G+ Circles are indexed and affects your profile (towards advertizers and others), whereas Neko.io messages are encrypted and truly private. Also, the Neko.io friend list spans across any
23.
▲
by
markkum
15y ago
We (Meontrust Inc, the provider of Neko.io and Mepin.com) would be happy to provide public key crypto (PKI) for such a service or project. Neko.io authentication, i.e. Mepin, is based on PKI.
24.
▲
by
markkum
15y ago
Unfortunately this is true for now. Obviously we are going to launch other device support and means to sign in. I hope you left a vote at the site about your preferred device platform.
25.
▲
by
markkum
15y ago
Clickable links; https://neko.io/ https://www.mepin.com/
26.
▲
Neko.io adds a splash of real privacy to Facebook and elsewhere around the web
3 points
by
markkum
15y ago
|
3 comments
27.
▲
OTP is annoying, use PKI
(mepin.com)
2 points
by
markkum
15y ago
|
0 comments
28.
▲
by
markkum
15y ago
Check out https://neko.io/ ... we are scrambling/encrypting messages into URLs which you can then share on Facebook, Twitter or where-ever.
29.
▲
by
markkum
15y ago
Yes, you can post the secret message links to your Twitter account.
30.
▲
by
markkum
15y ago
Many thanks for the feedback! You get an Access Code from the site, which you should enter on the Mepin app, which then logs you in. Try again, it's cool, thanks!
More ›