Live data from Hacker News

Viewing profile — arnarbi

arnarbi

HN member
Joined
Mon, Apr 30, 2012, 1:20 PM UTC
HN karma
1,541
Public activity
483 items

About arnarbi

Icelandic. SWE @ Google. Security, authentication, authorization. Work on WebAuthn, FIDO & passkeys.

[ my public key: https://keybase.io/arnar; my proof: https://keybase.io/arnar/sigs/lf4Zbpd04PZPXu_eZyGhPVoef2BuJ0p5VUuzV8ZXD4I ]

Recent public activity

  1. comment
    Comment #48874010

    I think it’s a little different. The restaurant fee isn’t a fee for something “extra”, it’s just a blanket extra charge on everything. It’d be like the airline sold you a ticket fo…

  2. comment
    Comment #48866877

    Restaurant owners interviewed in the media here in SF are directly quoted saying they can’t do that because “customers would notice”, or think “oh that’s expensive, I can’t eat out…

  3. comment
    Comment #48136085

    Scorched Earth was also my first hacking target. Found out that your cash balance and weapons inventory was all stored in a mysterious .ini file and you could just edit it.

  4. comment
    Comment #48016328

    Best "friendmaker" hobby I know is sailing. It's in general a very newcomer friendly hobby, which is both important as a newcomer yourself as well as for meeting new people once yo…

  5. comment
    Comment #47591395

    It's more like workers on a large oil tanker using bicycles to move around it, rather than trying to use another oil tanker.

  6. comment
    Comment #46970710

    > why they're attributed to AI? I don’t think they mean scrapers necessarily driven by LLMs, but scrapers collecting data to train LLMs.

  7. comment
    Comment #45701702

    We did not, no. Just wrote up the report and moved on.

  8. comment
    Comment #45690766

    Back in college (~2008) we implemented this with a 7 foot tall back-projected screen and a couple of Wii remotes after seeing Johnny Lee’s video. The nice thing with that screen wa…

  9. comment
    Comment #45055841

    It is not based on TB but it is heavily informed by those efforts. See here: https://github.com/w3c/webappsec-dbsc#what-makes-device-boun... However, DBSC as an API and protocol is…

  10. comment
    Comment #45055708

    > why they don't have TLS try and always create a client certificate per endpoint to proactively register on the server side That is effectively what Token Binding does. That was u…

  11. comment
    Comment #44521498

    Services can certainly make this safer by providing means to get more restricted credentials, so that users can deputize semi-trusted delegates, such as agents vulnerable to inject…

  12. comment
    Comment #44367937

    It’s the same thing: https://fidoalliance.org/passkeys/

  13. comment
    Comment #43871449

    This is a very good point, and one the DBSC team thinks about a lot. In the short term it's about economics: Infostealer malware today scales really well because it can a) exfiltra…

  14. comment
    Comment #43729834

    There are many sailing schools around SF, but one that stands out is https://www.cal-sailing.org/ - as it's by far the least expensive and low-commitment option to get on the water…

  15. comment
    Comment #43719937

    There was a pretty good video on this a couple of years ago: https://www.youtube.com/watch?v=QFv3QPNU6hw

  16. comment
    Comment #43646662

    Garfield is certainly (meant to be) real, but I've never seen a strip that confirms that Jon can actually hear Garfield's thoughts. I think that's why Garfield minus Garfield works…

  17. comment
    Comment #43291983

    It’s not induction. It’s just the contrapositive of “if you can solve the simpler problem then you can solve the harder problem”

  18. comment
    Comment #43002449

    You used to be required to adopt an Icelandic forename - not surname. You still kept your original name (if you wanted) and it was up to you which one you used on practice. But as …

  19. comment
    Comment #42703658

    Is that really price discrimination? “Enthusiasts” might have legitimate reasons for preferring hardcover (durability, aesthetics, etc) and are willingly and knowingly paying extra…

  20. comment
    Comment #42701611

    > They are (or were) refusing to provide any indication to those other companies that these are not, in fact, the same people That is not quite true, the sub field will be differen…

  21. comment
    Comment #42526302

    “They” in this case included me and this was a deliberate fix for poor UX many years ago. We definitely thought about it and we used to blink only the key that had a credential fro…

  22. comment
    Comment #42519187

    Chrome on desktop did: https://developer.chrome.com/docs/identity/webauthn-signal-a...

  23. comment
    Comment #42448030

    I have the same fantasy. I think it’s appealing because I imagine they’d be able to appreciate all the amazing things behind it more than most people, dead or alive.

  24. comment
    Comment #41833416

    Stained glass won’t (I think) shift any frequencies. It will attenuate different frequencies differently, but it won’t make up new ones. So when the signal frequency changes, you’l…

  25. comment
    Comment #41833352

    > What am I missing? The tree blowing in the wind will introduce its own amplitude (brightness) fluctuations. It will be hard for you to tell which amplitude changes are signal fro…