Live data from Hacker News

Viewing profile — csuwldcat

csuwldcat

HN member
Joined
Wed, Mar 12, 2008, 6:23 PM UTC
HN karma
150
Public activity
89 items

About csuwldcat

No profile information was provided.

Recent public activity

  1. story
  2. story
  3. comment
    Comment #46527123

    Yes, this is true, however, that means an external actor is able to execute arbitrary code in your origin, so they could also trick the user into signing malicious payloads with ev…

  4. comment
    Comment #46527083

    Hmm, can you provide further details? I'm using it on Android in Chrome and Brave, and it works fine.

  5. comment
    Comment #46527050

    That would either mean you have arbitrary, malicious code executing in the bound origin (the origin was hacked and shipped malicious code), or you allowed random callers externally…

  6. comment
    Comment #46524432

    You can run the PassSeed code/mechanism on your own domain or localhost to ensure it's not subject to malicious host exfiltratuon. I agree that one should only trust a foreign host…

  7. comment
    Comment #46524405

    A roaming authenticator does not have access to a CTAP mechanism to query the platform’s credential store. CTAP defines how the platform queries a roaming authenticator, in that di…

  8. comment
    Comment #46522999

    There's also the specific case of synced passkeys, which aren't exposed to CTAP management APIs for external parties, only to the OS/platform itself. You seem tied to a narrative w…

  9. comment
    Comment #46522865

    It's not just about the WebAuthn API, you're talking about passkeys as if their key bundles are freely accessible to random userland actors, which is absurd. If that were the case,…

  10. comment
    Comment #46522618

    The underlying CTAP implementations are only used by the platform to facilitate core activities, they are not used to expose key pairs to external parties. Please link to where any…

  11. comment
    Comment #46522545

    No need for the "oh dear"-ing before you provide evidence. I'm not aware of any command for fetch or enumeration of public keys in CTAP (was rather confident it doesn't provide any…

  12. comment
  13. comment
    Comment #46522263

    It's a deliberate architectural decision that passkey authenticators not allow any retrieval or enumeration of key pairs - they don't even have internal APIs for it. This holds tru…

  14. comment
    Comment #46521582

    The interesting thing about Passkeys is that they are only ever output in the client create() call, and the platform does not retain them for disclosure after that, so if you don't…

  15. comment
    Comment #46521502

    Saw your post above - I didn't "assert falsehoods", both are missing major browser support: https://caniuse.com/mdn-api_credentialscontainer_get_publick... https://caniuse.com/mdn-…

  16. comment
    Comment #46521471

    I addressed this in the post - neither is available across all major browsers: https://backalleycoder.com/posts/passseeds-an-experiment-in-... Ironically, you could make a pollyfil…

  17. comment
    Comment #46521379

    How it's better: automatically synced across all a user's devices, not subject to manual interactions with input fields (you can't programmatically request/regen passwords the same…

  18. comment
    Comment #46521283

    Just sounded cooler , and I was on the team that worked on Passkeys at Microsoft, so I wanted to poke them a bit (in a friendly way).

  19. comment
    Comment #46521085

    Passkeys can be hijacked to serve as cryptographic seed material that is securely synced across all of a user’s devices, enabling the generation of a wide range of cryptographic ke…

  20. story
  21. comment
    Comment #18010331

    Also take a look at DIF's Identity Hub - a large-scale initiative that goes far beyond a social server/mailbox, and incorporates solutions for the identity issues people here have …

  22. comment
    Comment #16368083

    This is unrelated to any previous demo/work Accenture has shown. (I work on this @ MSFT)

  23. comment
    Comment #15140269

    Other way around: the sat system supports Bitcoin, not BCash.

  24. comment
    Comment #14984744

    Correct - you can increase the units in circulation without destroying the purchasing power of those who currently hold the asset, which is a huge advantage over traditional fiat c…

  25. comment
    Comment #14975227

    Property is subject to bubbles, and in almost any economic recession prices of real estate tend to fall (demand drops, and sellers/supply grows). Bitcoin is a far better asset hedg…