Viewing profile — jesseendahl
jesseendahl
HN member- Joined
- Mon, Jan 19, 2009, 9:03 AM UTC
- HN karma
- 605
- Public activity
- 269 items
- HN profile
- View on Hacker News ↗
About jesseendahl
https://twitter.com/jesseendahl
Recent public activity
-
comment
Comment #49178355
Majority of second factors are phishable. If you are using a password (phishable) + a phishable second factor (any kind of 6 digit code that you need to type or paste into a text b…
-
comment
Comment #49178342
>They want you dependent on them and locked into their ecosystem. This is a strange conclusion to come to when clearly a lot of effort was put into developing an open standard (Cre…
-
comment
Comment #49178276
>I thought the point of storing secrets in hardware TPM and not giving them out into userspace (i.e. passkeys instead of passwords) is protecting against malware as well. This was …
-
comment
Comment #49017563
Password managers do not architecturally, cryptographically make phishing impossible. Ultimately a user can still be tricked to copy/paste their passwords into fake websites, even …
-
comment
Comment #49017550
Passwords are still significantly less secure than passkeys even when using a password manager.
- comment
-
comment
Comment #49017530
I like it. The high level UX of this idea feels very compelling to me as a "yes and" -- aka a world where vendors continue to offer end-to-end encrypted syncing within an ecosystem…
-
comment
Comment #49012307
> I don’t see hardware tokens (like Yubikey) in the list. Those are the only ones that provide a true second factor passkeys are not meant to be a second factor; they are meant to …
-
comment
Comment #49012162
There are some parts of this that are correct and other parts that are incorrect: >1. The idea was to provide a phishing resistant authentication method for enterprise users (compa…
-
comment
Comment #49011660
This is the #1 most common misconception I see about passkeys. They do not make it more likely that you will lose access to your accounts. They actually have nothing to do with acc…
-
comment
Comment #49011605
>Passkeys and 2FA are a usability nightmare if you need to recover, or all the security vanishes if you put usable recovery mechanisms for the passkey or the second factor. Most pr…
-
comment
Comment #49011460
> Which defeats part of the point of passkeys in the first place in that they are supposed to be device-bound If you watch the original Apple WWDC talk presenting passkeys, you wil…
-
comment
Comment #48459453
This part of their requirements for how PCC is architected directly addresses your concern: “Verifiable transparency. Security researchers need to be able to verify, with a high de…
-
comment
Comment #48244768
No, it is not. And if you fall in love and want to get married to someone on a student visa, your fiancée should not need to leave the country for a year or two to wait for paperwo…
-
comment
Comment #47941018
This is true at companies that treat security as a checkbox driven by compliance. Not true at top-tier tech companies building software in product categories that by their nature h…
-
comment
Comment #47906177
There are so many bots/trolls on HN now, it's crazy.
-
comment
Comment #47904002
What do you mean “just tap and hide a SMS”? Maybe my brain isn’t fully booted and I need more coffee, but I’m not understanding what this means.
-
comment
Comment #47442158
This story was recently on first page of HN: https://techcrunch.com/2026/03/18/fbi-is-buying-location-dat... This is the bill referenced at the end of the TechCrunch article: > Las…
- story
-
comment
Comment #47191622
You don't need to use anything from Apple/Google/Microsoft. Passkeys are just WebAuthn which is an open standard.
-
comment
Comment #47191595
Passwords are terrible UX for old people in my experience. They try use the same password everywhere, but then password complexity requirements mean they can't use the exact same p…
-
comment
Comment #47191570
>They bind you to your device/iCloud/Gaia account so if it gets stolen/banned you're out of luck This is the biggest myth/misconception I see repeated about passkeys all the time. …
-
comment
Comment #46844732
I am not sure if you missed my earlier comment, but it's directly applicable to this point you've repeatedly made: >If Apple believes this class of attack is no longer viable, that…
-
comment
Comment #46843417
Apple's head of SEAR (Security Engineering & Architecture) just gave the keynote at HEXACON, a conference attended by the companies who make Pegasus such as NSO Group. That doesn't…
-
comment
Comment #46777878
Finneas (Billie Eilish's brother) isn't one for virtue signaling from what I've seen over the years from his posts. He keeps it very real and down to earth as far as celebrities go…