Live data from Hacker News

Viewing profile — gre345t34

gre345t34

HN member
Joined
Mon, Jan 18, 2021, 1:40 AM UTC
HN karma
40
Public activity
21 items

About gre345t34

No profile information was provided.

Recent public activity

  1. comment
    Comment #41866900

    To be fair, the webauthn spec expressly forbids facilitating the extraction of credentials from the authenticator (though arguably even syncing between devices violates the spec).

  2. comment
    Comment #41866892

    Ideally you should not be able to determine whether a username is valid without authenticating.

  3. comment
    Comment #41866844

    If you got tricked into logging into goggle.com or something the FIDO2 auth would fail because a) the URL would not match the credential metadata and b) the resulting assertion, a …

  4. comment
    Comment #41866779

    A FIDO2 credential can be used for passwordless authentication, so long as the authenticator performs user verification (e.g. requires a PIN). This counts as 2FA because it's somet…

  5. comment
    Comment #36724576

    The article assumes quite a bit of knowledge of FIDO2 and your confusion is understandable. > How/why? What's the connection to passkeys or HSMs? Passkeys are implemented on top of…

  6. comment
    Comment #36720369

    Tell me about it. All of the terminology around FIDO is super confusing, and FIDO themselves make no effort to clarify or acknowledge the confusion. Everyone (including Yubico) use…

  7. comment
    Comment #36720061

    CTAP1 is only used for talking to old U2F keys. Additionally, U2F/CTAP1 does not support resident keys anyway (IIRC).

  8. comment
    Comment #36719989

    Primary issue with FIDO is not the specs themselves but the extremely confusing nomenclature that FIDO put zero effort into clarifying.

  9. comment
  10. comment
    Comment #36612981

    It's like murder but scaled up.

  11. comment
    Comment #35790170

    There's a certain amount of cosmic irony involved whenever someone calls LLMs 'stochastic parrots' or whatever.

  12. comment
    Comment #34760602

    The context is that US is developing high altitude balloons for detecting hyper-sonic weapons. Developing a technology and actively using in another country's airspace are quite di…

  13. comment
    Comment #34465950

    Yeah, kinda of disappointing for the author to disavow his own cautionary tale about AI, because obviously only meat can be conscious I guess.

  14. comment
    Comment #33879294

    Can you tell us how to determine which tasks require "understanding" and which don't, so that we may make accurate predictions about what tasks LLM's will be capable of in the futu…

  15. comment
    Comment #33315743

    As far as I can tell, it's a library that implements CTAP2 (which it erroneously refers to as webauthn).

  16. comment
    Comment #30396291

    Why should hackers be prosecuted for using systems as they're programmed?

  17. comment
    Comment #29375762

    Tell that to the Omicronians.

  18. comment
    Comment #26036563

    Because there are lenses in the headset that focus the two images at a set focal distant (between a couple of meters and infinity focus, depending on the headset). You need glasses…

  19. comment
    Comment #26032355

    You are confusing optical focus (like a camera lens or the lens in your eye) with stereopsis - the mechanism by which your brain detects depth information through parallax. The VR …

  20. comment
    Comment #26032292

    This is inaccurate. Unlike IRL in which objects can appear at varying focal distances, requiring the eye muscles to constantly adjust the focal distance of the eye, the two images …

  21. comment