Live data from Hacker News

Viewing profile — markkum

markkum

HN member
Joined
Thu, Mar 17, 2011, 7:11 PM UTC
HN karma
65
Public activity
51 items

About markkum

Founder & CEO of Mepin / Meontrust Inc. Serial entrepreneur, serial father, cereal lover ... password hater.

www.mepin.com

Recent public activity

  1. comment
    Comment #7976006

    Supporting multiple devices is a hard problem. We worked for a long time to enable it. Not Bitcoin protocol specific, but some words about our asymmetric key based multi-device sol…

  2. comment
    Comment #7975981

    Funnily; the reason to outsource is exactly about not putting all your eggs in the same shared basket. You outsource the 2nd factor and keep the first factor (passwords) in-house. …

  3. comment
    Comment #7078204

    I can use similar arguments; a user can be tricked to enter an OTP to a phishing site. For that the hacker does not need to time the attack to the same second, so it's much much ea…

  4. comment
    Comment #7078100

    Note that MePIN does not collect or need user's phone number, e-mail address or any other user information. You can use MePIN fully anonymously.

  5. comment
    Comment #7078001

    Unfortunately there are several cases where users have entered an OTP code for another user. The recent high profile case was with World of Warcraft's OTP.

  6. comment
    Comment #7077989

    Don't want to argue, but yes it would. It would stop the user for a second, giving time to the brain to process for a while what's going on.

  7. comment
    Comment #7077262

    This is now fixed. Thanks for the kick.

  8. comment
    Comment #7077059

    First; the user does not have to care about OS, browser, ip address or location. Though those can be shown to a user if the service provider wants. Authorization requests can only …

  9. comment
    Comment #7076811

    Of course user behavior has to be considered. The MePIN app does allow the user to set up a personal PIN code, so an authorization would then require the PIN code and a tap.

  10. comment
    Comment #7076764

    The solution is based on Public Key Infrastructure (PKI). Each authorization must be signed with the user's private key. The app is managing and protecting the keys and certificate…

  11. comment
    Comment #7076629

    Working on it.

  12. comment
    Comment #7076604

    The service is distributed and hosted at 3 continents with 3 different hosting providers, so we take this seriously. Other than that; You own your users and user database. No user …

  13. comment
    Comment #7076414

    It's easier because you only need to tap the app to verify. No need for OTP codes, though OTP is a fallback if your device is offline.

  14. story
  15. comment
    Comment #6747684

    This is the London I remember from early morning July 8th, 2005, the morning after the bombings. Was walking around to find a ride to the airport, couple of blocks from the double-…

  16. comment
    Comment #6169168

    Well, yes and no. On iOS you can somewhat rely on keychain, but when the device is jailbroken all the local "simple API" security is gone. Generic Android doesn't really have anyth…

  17. comment
    Comment #6168653

    The cool generalized version does exist :). Check out https://www.mepin.com/ We've got RSA 2048 keys on iOS, Android and a separate smartcard USB key, and do 2-factor login and tra…

  18. comment
    Comment #4084084

    Hi, a new developer section for the site is in the works. Stay tuned.

  19. comment
    Comment #4080166

    If you want something better for your site; check out MePIN https://www.mepin.com/

  20. comment
    Comment #3469910

    You can sign in without username and password to OpenID enabled sites with your smartphone and Mepin; https://www.mepin.com/

  21. comment
    Comment #3445839

    Here's an example Neko.io message for you; "I'm on a meditation trip in India. If you really need to bother me, here's my travel schedule and emergency number; https://neko.io/m/g4…

  22. comment
    Comment #3443009

    Not really. Clear text messages on Fb Friend List or G+ Circles are indexed and affects your profile (towards advertizers and others), whereas Neko.io messages are encrypted and tr…

  23. comment
    Comment #3442672

    We (Meontrust Inc, the provider of Neko.io and Mepin.com) would be happy to provide public key crypto (PKI) for such a service or project. Neko.io authentication, i.e. Mepin, is ba…

  24. comment
    Comment #3433745

    Unfortunately this is true for now. Obviously we are going to launch other device support and means to sign in. I hope you left a vote at the site about your preferred device platf…

  25. comment