Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mwwaters
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
mwwaters
2mo ago
The Windows 11 ISO on a two year old Lenovo laptop did not have the Ethernet or WiFi driver. “Have Disk” also did not work for whatever reason when I downloaded the driver to a USB drive. I had to open up a command prompt within the Windows
2.
▲
by
mwwaters
2mo ago
The passkey method uses Bluetooth to ensure proximity.
3.
▲
by
mwwaters
2mo ago
The far bigger benefit is phishing resistance (with hardware-contained keys themselves being phishing-proof on a non-compromised system). It moves to the account recovery flows, but that can be much more difficult to phish.
4.
▲
by
mwwaters
3mo ago
The first FRED link shows how noisy that subgroup is. It’s bounced around with 83-84% during that time. It was 83.8% in March and 83.5% through much of 2024.
5.
▲
by
mwwaters
3mo ago
OAuth first and foremost is driven by getting secret information from, let’s say, Big Company. It’s understandable that there are many steps for some random Joe to get Google emails or Facebook DMs. OpenID piggy-backed on it by layering on
6.
▲
by
mwwaters
3mo ago
When I really dove into it, I understood mostly why all the complexity was all there if I cared about data at the identity provider . When it’s only used for SSO, it’s extreme overkill.
7.
▲
by
mwwaters
3mo ago
That is for whatever it considers reverse-engineering the model to try to create a competing one.
8.
▲
by
mwwaters
4mo ago
The “enough of us” is at least a majority of voters agreeing. I’m not sure what the alternative to that is.
9.
▲
by
mwwaters
4mo ago
For doing some reporting stuff internally, there isn’t a certification. But there are definitely humans who have to certify financial statements and communications for financial offerings.
10.
▲
by
mwwaters
5mo ago
SLAAC and link-local is very different from DHCP/NAT/etc. in IPv4 world. Link-local addresses are pretty arcane in IPv4 while they are a central idea in IPv6. That’s fine. As pointed out elsewhere, DHCP was relatively new when IPv
11.
▲
by
mwwaters
5mo ago
Yeah, that’s the issue. There is a lot of boilerplate or I can ask for ideas, but outside of boilerplate the review step make generation seemingly worse.
12.
▲
by
mwwaters
5mo ago
There’s certainly a lot of uncertainty. But pro-AI posts never seem to pin themselves down on whether code checked in will be read and understood by a human. Perhaps a lot of engineers work in “vibe-codeable” domains, but a huge amount of d
13.
▲
by
mwwaters
6mo ago
The scams are more sophisticated than getting gift cards to pay the IRS. A number saying that it’s from the bank will say they need to verify some account information. I have had to actually verify my “investment profile” with a major broke
14.
▲
by
mwwaters
6mo ago
I’ve heard the actual OEM cost is offset by the manufacturer getting paid for all the bloatware included.
15.
▲
by
mwwaters
6mo ago
Electricity price regulation, at least for transmission, has been a thing for states for 100+ years and federally since the 1930s. Pipelines and railroads also have price regulation of some sort. Monopolies, in these cases natural monopolie
16.
▲
by
mwwaters
6mo ago
Electric utilities face price caps and there are not electricity shortages. It depends on the level of market failure, but there are not a ton of hospitals to choose from regardless.
17.
▲
by
mwwaters
6mo ago
Medicare has overhead, but you’re not saying whether it is more than commercial insurance. The admin expense/profit portion of commercial insurers also don’t take into account provider admin costs (not to mention the huge amount of tim
18.
▲
by
mwwaters
7mo ago
The legal infrastructure for banking and securities ownership has long had defaults for liability assignment. For securities, if I own stock outright, the company has to indemnify if they do a transfer for somebody else or if I lack legal c
19.
▲
by
mwwaters
7mo ago
If the side loaded app does not have permission to use the passkeys and cannot somehow get the user to approve passkey access of the new app, that would be a good alternative to still allow custom apps.
20.
▲
by
mwwaters
7mo ago
In the case of some knowing or blindfully unknowing money mule in the chain or at the end of the chain, the intermediary or final banks may not be at fault. The bank could have followed KYC procedures in that somebody with that name actuall
21.
▲
by
mwwaters
7mo ago
The phisher’s app or login would be from a completely new device though. Passkeys are also an active area to defeat phishing as long as the device is not compromised. To the extent there is attestation, passkeys also create very critical po
22.
▲
by
mwwaters
7mo ago
There is some world where somebody scammed through sideloading loses their life savings, and every country is politically fine with the customer, not the bank, taking the losses. But for regular people, that is not really the world they wan
23.
▲
by
mwwaters
7mo ago
Maybe I’m biased working in insurance software, but I don’t get the feeling much programming happens where the code can be completely stochastically generated, never have its code reviewed, and that will be okay with users/customers&#x
24.
▲
by
mwwaters
7mo ago
I took this thread as asking whether PRs that are pulled in should be reviewed.
25.
▲
by
mwwaters
7mo ago
The issue in the late-90s was all the investment created a lot of real revenue for telecoms and other companies. Even though there were a lot of shenanigans with revenue, a lot of real money was spent on fiber and tech generally. But the re
26.
▲
by
mwwaters
7mo ago
In the expenditures for the economy making up GDP, not a lot of it screams “AI-able.” Page 9 here breaks down GDP on expenditure basis. https://www.bea.gov/sites/default/files/2026-01/gdp3q25-upda... Giv
27.
▲
by
mwwaters
9mo ago
It seems like the bigger day to day issue is the possibility of downgrades from STARTTLS or a server that doesn’t support TLS. Encryption in the GPG isn’t necessary or even would be unwanted (for a company to have records of all the emails)
28.
▲
by
mwwaters
2y ago
https end-to-end encrypts what’s in the address, except for the domain.
29.
▲
by
mwwaters
3y ago
I will say that for Google's Advanced Protection, I was convinced having a recovery phone added was okay. I just have a hardware key on my key chain and one on a pretty fireproof safe (which I got for other reasons). But I still added
30.
▲
by
mwwaters
3y ago
Having different passwords doesn't prevent phishing where you think you're logging into the service being phished. The hacker would also create a new TOTP on that service once they get in to that service.
More ›