Live data from Hacker News

Viewing profile — PranavBerry

PranavBerry

HN member
Joined
Thu, Aug 08, 2019, 9:27 AM UTC
HN karma
38
Public activity
30 items

About PranavBerry

No profile information was provided.

Recent public activity

  1. story
  2. story
  3. story
  4. story
  5. comment
    Comment #30166969

    Location: India Remote: Yes Willing to relocate: No (can work remotely according to another time zone) Technologies: Python (FastAPI, Flask, Django) JavaScript/TypeScript (React, R…

  6. comment
    Comment #29795957

    Remote: Yes Willing to relocate: No (but can work remotely according to another time zone) Technologies: JavaScript/TypeScript (React, React Native, Node.js) Python (FastAPI, Flask…

  7. story
  8. story
  9. story
  10. comment
    Comment #29407419

    Location: India Remote: Yes Willing to relocate: No (but can work remotely according to another time zone) Technologies: JavaScript/TypeScript (React, React Native, Node.js) Python…

  11. story
  12. comment
    Comment #29259155

    >If I'm a common person with one phone I had not thought about that but I think I can add push notifications if this is a problem. So on your phone you just tap the login with my a…

  13. comment
    Comment #29258265

    > plug my Yubikey into as many laptops as I would like. What if you don't own a physical key? > I have to trust you to not leak my 2FA. Authy does this already and so I don’t use A…

  14. comment
    Comment #29257679

    >Is your service going to be audited by independent third parties that vendors choose? Yes I am planning to do that. >How do people verify that your application is the legitimate v…

  15. comment
  16. comment
    Comment #29257442

    > FIDO Alliance is doing with WebAuthn Yes I looked into it, but it looks like WebAuthn does not support multiple devices (let me know if I am wrong). What if I want to login from …

  17. comment
    Comment #29257380

    >intercepting traffic or spoofing a site can copy/tamper/replace the QR code Will this be a problem with HTTPS? When you open a page, a request will be made to my server to generat…

  18. comment
    Comment #29255749

    >As for QR codes, those can be copied The QR code are unique for every login attempt. After you scan the QR code and enter your phone's pin, my authenticator will send a request to…

  19. comment
    Comment #29255294

    > SMS based 2fa has many other problems What are these problems? It will be great if you can list some of them, I'd like to read more in detail.

  20. story
    Why is using SMS bad for 2FA?

    I have read in a few places that using SMS is really insecure for 2FA. A few people on this thread (https://news.ycombinator.com/item?id=29004930) also said that SMS should be avoi…

  21. comment
    Comment #29140623

    Got it, but there will still be a network effect. You will just have to download it once and can add and manage accounts on a lot of websites.

  22. comment
    Comment #29140597

    >have a Msft Authenticator and a Google one I think you can just add all accounts to one authenticator. >make it work with one of these These authenticators, have no support for QR…

  23. comment
    Comment #29137741

    >agree with password-less. Does my idea sounds like something you would use? Will you download a authenticator app to avoid using user/pass?

  24. story
    What do you think of Scan QR to Login as a Service?

    I'm Ideating on offering Scan QR Code to Login as a Service. How it works? 1. Add your account to my authenticator app. 2. Whenever you need to sign-in, scan the QR code displayed …

  25. comment
    Comment #29064983

    >the website display the QR code and the phone scan it I'm exploring that right now, thx a lot. >I'm probably missing the point of your idea. It was mainly a way to do 2FA with a p…