Live data from Hacker News

Viewing profile — jesseendahl

jesseendahl

HN member
Joined
Mon, Jan 19, 2009, 9:03 AM UTC
HN karma
605
Public activity
269 items

About jesseendahl

i don't speak for my current or prior employer(s) - all posts are my own personal opinions.

https://twitter.com/jesseendahl

Recent public activity

  1. comment
    Comment #49178355

    Majority of second factors are phishable. If you are using a password (phishable) + a phishable second factor (any kind of 6 digit code that you need to type or paste into a text b…

  2. comment
    Comment #49178342

    >They want you dependent on them and locked into their ecosystem. This is a strange conclusion to come to when clearly a lot of effort was put into developing an open standard (Cre…

  3. comment
    Comment #49178276

    >I thought the point of storing secrets in hardware TPM and not giving them out into userspace (i.e. passkeys instead of passwords) is protecting against malware as well. This was …

  4. comment
    Comment #49017563

    Password managers do not architecturally, cryptographically make phishing impossible. Ultimately a user can still be tricked to copy/paste their passwords into fake websites, even …

  5. comment
    Comment #49017550

    Passwords are still significantly less secure than passkeys even when using a password manager.

  6. comment
  7. comment
    Comment #49017530

    I like it. The high level UX of this idea feels very compelling to me as a "yes and" -- aka a world where vendors continue to offer end-to-end encrypted syncing within an ecosystem…

  8. comment
    Comment #49012307

    > I don’t see hardware tokens (like Yubikey) in the list. Those are the only ones that provide a true second factor passkeys are not meant to be a second factor; they are meant to …

  9. comment
    Comment #49012162

    There are some parts of this that are correct and other parts that are incorrect: >1. The idea was to provide a phishing resistant authentication method for enterprise users (compa…

  10. comment
    Comment #49011660

    This is the #1 most common misconception I see about passkeys. They do not make it more likely that you will lose access to your accounts. They actually have nothing to do with acc…

  11. comment
    Comment #49011605

    >Passkeys and 2FA are a usability nightmare if you need to recover, or all the security vanishes if you put usable recovery mechanisms for the passkey or the second factor. Most pr…

  12. comment
    Comment #49011460

    > Which defeats part of the point of passkeys in the first place in that they are supposed to be device-bound If you watch the original Apple WWDC talk presenting passkeys, you wil…

  13. comment
    Comment #48459453

    This part of their requirements for how PCC is architected directly addresses your concern: “Verifiable transparency. Security researchers need to be able to verify, with a high de…

  14. comment
    Comment #48244768

    No, it is not. And if you fall in love and want to get married to someone on a student visa, your fiancée should not need to leave the country for a year or two to wait for paperwo…

  15. comment
    Comment #47941018

    This is true at companies that treat security as a checkbox driven by compliance. Not true at top-tier tech companies building software in product categories that by their nature h…

  16. comment
    Comment #47906177

    There are so many bots/trolls on HN now, it's crazy.

  17. comment
    Comment #47904002

    What do you mean “just tap and hide a SMS”? Maybe my brain isn’t fully booted and I need more coffee, but I’m not understanding what this means.

  18. comment
    Comment #47442158

    This story was recently on first page of HN: https://techcrunch.com/2026/03/18/fbi-is-buying-location-dat... This is the bill referenced at the end of the TechCrunch article: > Las…

  19. story
  20. comment
    Comment #47191622

    You don't need to use anything from Apple/Google/Microsoft. Passkeys are just WebAuthn which is an open standard.

  21. comment
    Comment #47191595

    Passwords are terrible UX for old people in my experience. They try use the same password everywhere, but then password complexity requirements mean they can't use the exact same p…

  22. comment
    Comment #47191570

    >They bind you to your device/iCloud/Gaia account so if it gets stolen/banned you're out of luck This is the biggest myth/misconception I see repeated about passkeys all the time. …

  23. comment
    Comment #46844732

    I am not sure if you missed my earlier comment, but it's directly applicable to this point you've repeatedly made: >If Apple believes this class of attack is no longer viable, that…

  24. comment
    Comment #46843417

    Apple's head of SEAR (Security Engineering & Architecture) just gave the keynote at HEXACON, a conference attended by the companies who make Pegasus such as NSO Group. That doesn't…

  25. comment
    Comment #46777878

    Finneas (Billie Eilish's brother) isn't one for virtue signaling from what I've seen over the years from his posts. He keeps it very real and down to earth as far as celebrities go…