Live data from Hacker News

Viewing profile — PassageNick

PassageNick

HN member
Joined
Wed, Aug 10, 2022, 5:41 PM UTC
HN karma
23
Public activity
42 items

About PassageNick

I'm the Developer Advocate at Passage. https://passage.id

Recent public activity

  1. comment
    Comment #34973831

    This is a great question. I think the biggest barrier to adoption is lack of end user demand for the service. That is followed by people not understanding/believing the incredible …

  2. comment
    Comment #34972442

    It is not clear to me what they are implementing here. There is not mention of passkeys anywhere.

  3. comment
    Comment #34972435

    Not sure I follow.... Biometrics are very difficult to impossible to reproduce short of physical coercion.

  4. comment
    Comment #34957810

    Passwordless is actually MFA -- Something you have (your device) Something you are (your biometric) Those are definitely two factors that are required to be together for passwordle…

  5. comment
    Comment #34887681

    >> I hate having to rely on having my phone handy to log into anything. This isn't the case. Nothing about passkeys says you need your phone to login on a website with your laptop,…

  6. comment
    Comment #34887631

    The problem with legislation like this is that it eliminates the possibility of better solution. What happens if someone invents a better interface than USB 3.0? Or better, why wou…

  7. comment
    Comment #34455641

    No -- every origin has it's own Public/Private key that is stored on the TPM chip on your device. The TPM is designed specifically for securing these keys. Each passkey is a modest…

  8. comment
    Comment #34455490

    That's a great article, thanks. In fact, it's a fantastic article. I read it a couple of weeks ago, and learned a lot. Thanks. Apple's changes do degrade security, but I think it i…

  9. comment
    Comment #34454602

    ....and can you explain the cookie theft thing a bit more?

  10. comment
    Comment #34454582

    If you can take a photograph of someone's fingerprint and reproduce it, how, exactly, does one use that?

  11. comment
    Comment #34443595

    They cannot block access. The passkeys are actually stored on your devices in a Trusted Platform Module. When moved to the cloud, they are E2E encrypted, and the transferring platf…

  12. comment
    Comment #34443111

    Passwordless is MFA -- something you are and something you have. I'm not a yubikey expert, but I don't believe that losing your Yubikey will open up your company to a breach. For a…

  13. comment
    Comment #34432947

    You own your own passkeys on your own device, ultimately. Google/Apple/MS have no ownership or knowledge of the actual keys.

  14. comment
    Comment #34432934

    Fair enough.

  15. comment
    Comment #34432928

    Re: Yubikey -- I confess I don't know. The folks in r/yubikey definitely will, though. The "Big Three" are on the FIDO board, along with 1Password. They can't really do the extingu…

  16. comment
    Comment #34429816

    The threat surface of a password based system is like Lake Superior. The threat surface of a passkey based solution is like a small puddle after a rain. How is there a "reduction" …

  17. comment
    Comment #34429099

    Yeah, it is non-trivial to implement, but not impossible. Some folks go that route. There are SaaS solutions that implement it for you and make it easy to include in your app.

  18. comment
    Comment #34428316

    (Full disclosure: I work at https://passage.id ) WebAuthn is the short name for the "FIDO Alliance Web Authentication Protocol". "Passkey" is the trade name (that Apple tries to ow…

  19. comment
    Comment #34261503

    That's a quality aphorism.

  20. comment
    Comment #34261469

    It seems strange to me that anyone would go anything but Cloud Native today.

  21. comment
    Comment #34261421

    It's amazing how the attitude about not wanting to put data in the vendors hands has changed over the last ten years. I remember having a hard time to convince our CEO to use BitBu…

  22. comment
    Comment #34261260

    (Note: I work for Passage.id, now part of 1Password...) Auth is pretty easy to implement, but difficult to get and keep right. Then there are the nooks and crannies that crop up an…

  23. story
  24. story
  25. story