Viewing profile — PranavBerry
PranavBerry
HN member- Joined
- Thu, Aug 08, 2019, 9:27 AM UTC
- HN karma
- 38
- Public activity
- 30 items
- HN profile
- View on Hacker News ↗
About PranavBerry
No profile information was provided.
Recent public activity
- story
- story
- story
- story
-
comment
Comment #30166969
Location: India Remote: Yes Willing to relocate: No (can work remotely according to another time zone) Technologies: Python (FastAPI, Flask, Django) JavaScript/TypeScript (React, R…
-
comment
Comment #29795957
Remote: Yes Willing to relocate: No (but can work remotely according to another time zone) Technologies: JavaScript/TypeScript (React, React Native, Node.js) Python (FastAPI, Flask…
- story
- story
- story
-
comment
Comment #29407419
Location: India Remote: Yes Willing to relocate: No (but can work remotely according to another time zone) Technologies: JavaScript/TypeScript (React, React Native, Node.js) Python…
- story
-
comment
Comment #29259155
>If I'm a common person with one phone I had not thought about that but I think I can add push notifications if this is a problem. So on your phone you just tap the login with my a…
-
comment
Comment #29258265
> plug my Yubikey into as many laptops as I would like. What if you don't own a physical key? > I have to trust you to not leak my 2FA. Authy does this already and so I don’t use A…
-
comment
Comment #29257679
>Is your service going to be audited by independent third parties that vendors choose? Yes I am planning to do that. >How do people verify that your application is the legitimate v…
- comment
-
comment
Comment #29257442
> FIDO Alliance is doing with WebAuthn Yes I looked into it, but it looks like WebAuthn does not support multiple devices (let me know if I am wrong). What if I want to login from …
-
comment
Comment #29257380
>intercepting traffic or spoofing a site can copy/tamper/replace the QR code Will this be a problem with HTTPS? When you open a page, a request will be made to my server to generat…
-
comment
Comment #29255749
>As for QR codes, those can be copied The QR code are unique for every login attempt. After you scan the QR code and enter your phone's pin, my authenticator will send a request to…
-
comment
Comment #29255294
> SMS based 2fa has many other problems What are these problems? It will be great if you can list some of them, I'd like to read more in detail.
-
story
Why is using SMS bad for 2FA?
I have read in a few places that using SMS is really insecure for 2FA. A few people on this thread (https://news.ycombinator.com/item?id=29004930) also said that SMS should be avoi…
-
comment
Comment #29140623
Got it, but there will still be a network effect. You will just have to download it once and can add and manage accounts on a lot of websites.
-
comment
Comment #29140597
>have a Msft Authenticator and a Google one I think you can just add all accounts to one authenticator. >make it work with one of these These authenticators, have no support for QR…
-
comment
Comment #29137741
>agree with password-less. Does my idea sounds like something you would use? Will you download a authenticator app to avoid using user/pass?
-
story
What do you think of Scan QR to Login as a Service?
I'm Ideating on offering Scan QR Code to Login as a Service. How it works? 1. Add your account to my authenticator app. 2. Whenever you need to sign-in, scan the QR code displayed …
-
comment
Comment #29064983
>the website display the QR code and the phone scan it I'm exploring that right now, thx a lot. >I'm probably missing the point of your idea. It was mainly a way to do 2FA with a p…