Viewing profile — csuwldcat
csuwldcat
HN member- Joined
- Wed, Mar 12, 2008, 6:23 PM UTC
- HN karma
- 150
- Public activity
- 89 items
- HN profile
- View on Hacker News ↗
About csuwldcat
No profile information was provided.
Recent public activity
- story
- story
-
comment
Comment #46527123
Yes, this is true, however, that means an external actor is able to execute arbitrary code in your origin, so they could also trick the user into signing malicious payloads with ev…
-
comment
Comment #46527083
Hmm, can you provide further details? I'm using it on Android in Chrome and Brave, and it works fine.
-
comment
Comment #46527050
That would either mean you have arbitrary, malicious code executing in the bound origin (the origin was hacked and shipped malicious code), or you allowed random callers externally…
-
comment
Comment #46524432
You can run the PassSeed code/mechanism on your own domain or localhost to ensure it's not subject to malicious host exfiltratuon. I agree that one should only trust a foreign host…
-
comment
Comment #46524405
A roaming authenticator does not have access to a CTAP mechanism to query the platform’s credential store. CTAP defines how the platform queries a roaming authenticator, in that di…
-
comment
Comment #46522999
There's also the specific case of synced passkeys, which aren't exposed to CTAP management APIs for external parties, only to the OS/platform itself. You seem tied to a narrative w…
-
comment
Comment #46522865
It's not just about the WebAuthn API, you're talking about passkeys as if their key bundles are freely accessible to random userland actors, which is absurd. If that were the case,…
-
comment
Comment #46522618
The underlying CTAP implementations are only used by the platform to facilitate core activities, they are not used to expose key pairs to external parties. Please link to where any…
-
comment
Comment #46522545
No need for the "oh dear"-ing before you provide evidence. I'm not aware of any command for fetch or enumeration of public keys in CTAP (was rather confident it doesn't provide any…
- comment
-
comment
Comment #46522263
It's a deliberate architectural decision that passkey authenticators not allow any retrieval or enumeration of key pairs - they don't even have internal APIs for it. This holds tru…
-
comment
Comment #46521582
The interesting thing about Passkeys is that they are only ever output in the client create() call, and the platform does not retain them for disclosure after that, so if you don't…
-
comment
Comment #46521502
Saw your post above - I didn't "assert falsehoods", both are missing major browser support: https://caniuse.com/mdn-api_credentialscontainer_get_publick... https://caniuse.com/mdn-…
-
comment
Comment #46521471
I addressed this in the post - neither is available across all major browsers: https://backalleycoder.com/posts/passseeds-an-experiment-in-... Ironically, you could make a pollyfil…
-
comment
Comment #46521379
How it's better: automatically synced across all a user's devices, not subject to manual interactions with input fields (you can't programmatically request/regen passwords the same…
-
comment
Comment #46521283
Just sounded cooler , and I was on the team that worked on Passkeys at Microsoft, so I wanted to poke them a bit (in a friendly way).
-
comment
Comment #46521085
Passkeys can be hijacked to serve as cryptographic seed material that is securely synced across all of a user’s devices, enabling the generation of a wide range of cryptographic ke…
- story
-
comment
Comment #18010331
Also take a look at DIF's Identity Hub - a large-scale initiative that goes far beyond a social server/mailbox, and incorporates solutions for the identity issues people here have …
-
comment
Comment #16368083
This is unrelated to any previous demo/work Accenture has shown. (I work on this @ MSFT)
-
comment
Comment #15140269
Other way around: the sat system supports Bitcoin, not BCash.
-
comment
Comment #14984744
Correct - you can increase the units in circulation without destroying the purchasing power of those who currently hold the asset, which is a huge advantage over traditional fiat c…
-
comment
Comment #14975227
Property is subject to bubbles, and in almost any economic recession prices of real estate tend to fall (demand drops, and sellers/supply grows). Bitcoin is a far better asset hedg…