Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
raron
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
raron
16d ago
Is that really that impractical? With a quick calculation 50 ms time offset would mean about 20 meter difference. You can get that accuracy with NTP over residential internet and a better TCXO could hold that for a day. You could sync clo
2.
▲
by
raron
2mo ago
> We shouldn’t just give up because everything is inherently insecure. True, but no sane way to mass revoke Passkeys from stolen / lost device is just bad design.
3.
▲
by
raron
2mo ago
That could work, but then the service needs to implement complex non standardized authentication mechanism outside of Passkeys. You will have 14 different services with 15 different options. I don't think that's really user-friend
4.
▲
by
raron
2mo ago
> It is not feasible to remove password login or some other recovery login method. Then passkeys doesn't provide any real value if you have other less secure recovery option. Let's say I have a bank account, going to the branch
5.
▲
by
raron
2mo ago
> You generate another passkey is your answer. How do you do that? The exact same way you do today. How can I do that, if Passkeys are the only option to log in? If I can just use a password to log into a website without Passkeys, then P
6.
▲
by
raron
2mo ago
I don't think that would work either. Let's say I have a new account and a single Passkey in the TPM of PC1. I want to log in from PC2, too. How can I do that? (I know there is some trickery with Bluetooth, but I haven't seen
7.
▲
by
raron
2mo ago
The enforcement of GDPR is more or less nonexistent for big companies. Even if they get fined, that is just cost of business for them. In the text nothing prevents the manufacturer to stream the vide of your face to their servers all over t
8.
▲
by
raron
3mo ago
> Use short expirations And now you can use time correlation attack to unmask people.
9.
▲
by
raron
3mo ago
I think that depends on how do you define PII. I suspect the ZKP proof or token is practically unique and related to you, so I could be personal data if you use the definition from GDPR. With ZKP the entity and the original verifier shouldn
10.
▲
by
raron
3mo ago
It is not using ZKP. Zero knowledge proof is mentioned as an optional experimental feature in the next release. https://ageverification.dev/av-doc-technical-specification/d...
11.
▲
by
raron
3mo ago
> if I wanted to buy a device with a new type of connector, I should have been able to You are. Nothing prevents the manufacturers to support other better charging solutions than USB-C. In fact many notebooks has their proprietary connec
12.
▲
by
raron
3mo ago
Some people argue that it is just for more government surveillance and control, but the government already could access your bank and card transactions and freeze or confiscate your money.
13.
▲
by
raron
3mo ago
The difference is more a financial or legal thing, than a technical one. From an users' perspective paying with digital Euro would work more-or-less the same as you pay today with card, bank transfer or something based on QR codes. But
14.
▲
by
raron
3mo ago
It gets interesting when the two system interacts. Friends visiting the US told me that at the POS terminal they had to choose credit card despite paying with a Visa/Mastercard debit card issued by an European bank. By the way, here ba
15.
▲
by
raron
3mo ago
AFAIK the ECB wants to have both things. Digital Euro being a CBDC could open up a lot of possibilities, but they want an unified payment system, too, and that would be a nice first job for digital Euro.
16.
▲
by
raron
3mo ago
Not really. Euro cash today is paper / plastic banknotes and metal coins. Your account in the bank is not really cash you own, it is more like the banks liability towards you. If your bank fail, you loose the money you held in the bank
17.
▲
by
raron
3mo ago
I theory it should be more. The ECB claims you will be able to hold and spend a (limited amount of) digital euro offline (without internet connection).
18.
▲
by
raron
3mo ago
That's interesting argument. Here it is usual to have a daily limit on debit cards. You can not spend more money than that, so a thief can not drain your account. Also many banks give you multiple accounts (you can transfer between the
19.
▲
by
raron
3mo ago
Probably it depends on what part of the world you are and on what is your goal, what you want to optimize for. In many countries there are usual systematic weather events where all renewable production goes to basically nothing for few days
20.
▲
by
raron
3mo ago
Microchip has some "chip-scale atomic clock"s, not much bigger than an OCXO, but a lot more expensive. https://www.microchip.com/en-us/product/csac-sa65
21.
▲
by
raron
3mo ago
> They also over index fear of LargeCo stealing IP That seems to be a bold statement considering the whole business of this LargeCo is based on stolen IP.
22.
▲
by
raron
4mo ago
This. If AMD / Xilinx would publish the documentation what you would need to use their chips, probably very few would use Vivado or ISE.
23.
▲
by
raron
4mo ago
Not yet, but it is easy to imagine many ways it would be used for DRM.
24.
▲
by
raron
4mo ago
> The point of SynthID is to make generated images identifiable, in an attempt to prevent 1984-esque situations where you can't believe your eyes and ears. You can still use traditional methods to manipulate images, too, so I don&#x
25.
▲
by
raron
4mo ago
Maybe that's changes by country, but here bank transfers are basically final and can not be cancelled or recalled. Why would a bank cover your losses from their profits?
26.
▲
by
raron
4mo ago
Chargebacks exists for (EU style) debit cards, too. It doesn't need to be simple just available, so if the merchant disappears with your money or someone uses your stolen card, there is a way you can get your money back. With bank tran
27.
▲
by
raron
4mo ago
> A payment should be a bank transfer. Anything more complicated is just something that is to be exploited by middle-men. I disagree with that. Payments (especially online and contactless ones) should have some form of buyer protection,
28.
▲
by
raron
4mo ago
It can, in fact there is even an open standard for that: https://en.wikipedia.org/wiki/EPC_QR_code By the way credit card companies do a lot more than Wero, SEPA or any other similar instant payment solution (e.g. char
29.
▲
by
raron
4mo ago
Wero is just another private company trying get their cut of payment fees. You can do the same thing with SEPA Instant Payment (or some member states outside of the Eurozone have their own similar thing). I don't see why Wero should ex
30.
▲
by
raron
5mo ago
You could just jail the CEO or who was responsible for the security at that agency / company.
More ›