Viewing profile — PassageNick
PassageNick
HN member- Joined
- Wed, Aug 10, 2022, 5:41 PM UTC
- HN karma
- 23
- Public activity
- 42 items
- HN profile
- View on Hacker News ↗
About PassageNick
Recent public activity
-
comment
Comment #34973831
This is a great question. I think the biggest barrier to adoption is lack of end user demand for the service. That is followed by people not understanding/believing the incredible …
-
comment
Comment #34972442
It is not clear to me what they are implementing here. There is not mention of passkeys anywhere.
-
comment
Comment #34972435
Not sure I follow.... Biometrics are very difficult to impossible to reproduce short of physical coercion.
-
comment
Comment #34957810
Passwordless is actually MFA -- Something you have (your device) Something you are (your biometric) Those are definitely two factors that are required to be together for passwordle…
-
comment
Comment #34887681
>> I hate having to rely on having my phone handy to log into anything. This isn't the case. Nothing about passkeys says you need your phone to login on a website with your laptop,…
-
comment
Comment #34887631
The problem with legislation like this is that it eliminates the possibility of better solution. What happens if someone invents a better interface than USB 3.0? Or better, why wou…
-
comment
Comment #34455641
No -- every origin has it's own Public/Private key that is stored on the TPM chip on your device. The TPM is designed specifically for securing these keys. Each passkey is a modest…
-
comment
Comment #34455490
That's a great article, thanks. In fact, it's a fantastic article. I read it a couple of weeks ago, and learned a lot. Thanks. Apple's changes do degrade security, but I think it i…
-
comment
Comment #34454602
....and can you explain the cookie theft thing a bit more?
-
comment
Comment #34454582
If you can take a photograph of someone's fingerprint and reproduce it, how, exactly, does one use that?
-
comment
Comment #34443595
They cannot block access. The passkeys are actually stored on your devices in a Trusted Platform Module. When moved to the cloud, they are E2E encrypted, and the transferring platf…
-
comment
Comment #34443111
Passwordless is MFA -- something you are and something you have. I'm not a yubikey expert, but I don't believe that losing your Yubikey will open up your company to a breach. For a…
-
comment
Comment #34432947
You own your own passkeys on your own device, ultimately. Google/Apple/MS have no ownership or knowledge of the actual keys.
-
comment
Comment #34432934
Fair enough.
-
comment
Comment #34432928
Re: Yubikey -- I confess I don't know. The folks in r/yubikey definitely will, though. The "Big Three" are on the FIDO board, along with 1Password. They can't really do the extingu…
-
comment
Comment #34429816
The threat surface of a password based system is like Lake Superior. The threat surface of a passkey based solution is like a small puddle after a rain. How is there a "reduction" …
-
comment
Comment #34429099
Yeah, it is non-trivial to implement, but not impossible. Some folks go that route. There are SaaS solutions that implement it for you and make it easy to include in your app.
-
comment
Comment #34428316
(Full disclosure: I work at https://passage.id ) WebAuthn is the short name for the "FIDO Alliance Web Authentication Protocol". "Passkey" is the trade name (that Apple tries to ow…
-
comment
Comment #34261503
That's a quality aphorism.
-
comment
Comment #34261469
It seems strange to me that anyone would go anything but Cloud Native today.
-
comment
Comment #34261421
It's amazing how the attitude about not wanting to put data in the vendors hands has changed over the last ten years. I remember having a hard time to convince our CEO to use BitBu…
-
comment
Comment #34261260
(Note: I work for Passage.id, now part of 1Password...) Auth is pretty easy to implement, but difficult to get and keep right. Then there are the nooks and crannies that crop up an…
- story
- story
- story