Live data from Hacker News

Viewing profile — raron

raron

HN member
Joined
Wed, Dec 29, 2021, 2:52 AM UTC
HN karma
232
Public activity
129 items

About raron

No profile information was provided.

Recent public activity

  1. comment
    Comment #49017289

    > We shouldn’t just give up because everything is inherently insecure. True, but no sane way to mass revoke Passkeys from stolen / lost device is just bad design.

  2. comment
    Comment #49014536

    That could work, but then the service needs to implement complex non standardized authentication mechanism outside of Passkeys. You will have 14 different services with 15 differen…

  3. comment
    Comment #49014433

    > It is not feasible to remove password login or some other recovery login method. Then passkeys doesn't provide any real value if you have other less secure recovery option. Let's…

  4. comment
    Comment #49013288

    > You generate another passkey is your answer. How do you do that? The exact same way you do today. How can I do that, if Passkeys are the only option to log in? If I can just use …

  5. comment
    Comment #49012374

    I don't think that would work either. Let's say I have a new account and a single Passkey in the TPM of PC1. I want to log in from PC2, too. How can I do that? (I know there is som…

  6. comment
    Comment #48825641

    The enforcement of GDPR is more or less nonexistent for big companies. Even if they get fined, that is just cost of business for them. In the text nothing prevents the manufacturer…

  7. comment
    Comment #48768001

    > Use short expirations And now you can use time correlation attack to unmask people.

  8. comment
    Comment #48767936

    I think that depends on how do you define PII. I suspect the ZKP proof or token is practically unique and related to you, so I could be personal data if you use the definition from…

  9. comment
    Comment #48727823

    It is not using ZKP. Zero knowledge proof is mentioned as an optional experimental feature in the next release. https://ageverification.dev/av-doc-technical-specification/d...

  10. comment
    Comment #48711477

    > if I wanted to buy a device with a new type of connector, I should have been able to You are. Nothing prevents the manufacturers to support other better charging solutions than U…

  11. comment
    Comment #48666534

    Some people argue that it is just for more government surveillance and control, but the government already could access your bank and card transactions and freeze or confiscate you…

  12. comment
    Comment #48654961

    The difference is more a financial or legal thing, than a technical one. From an users' perspective paying with digital Euro would work more-or-less the same as you pay today with …

  13. comment
    Comment #48654071

    It gets interesting when the two system interacts. Friends visiting the US told me that at the POS terminal they had to choose credit card despite paying with a Visa/Mastercard deb…

  14. comment
    Comment #48653976

    AFAIK the ECB wants to have both things. Digital Euro being a CBDC could open up a lot of possibilities, but they want an unified payment system, too, and that would be a nice firs…

  15. comment
    Comment #48653959

    Not really. Euro cash today is paper / plastic banknotes and metal coins. Your account in the bank is not really cash you own, it is more like the banks liability towards you. If y…

  16. comment
    Comment #48653904

    I theory it should be more. The ECB claims you will be able to hold and spend a (limited amount of) digital euro offline (without internet connection).

  17. comment
    Comment #48653552

    That's interesting argument. Here it is usual to have a daily limit on debit cards. You can not spend more money than that, so a thief can not drain your account. Also many banks g…

  18. comment
    Comment #48639982

    Probably it depends on what part of the world you are and on what is your goal, what you want to optimize for. In many countries there are usual systematic weather events where all…

  19. comment
    Comment #48616600

    Microchip has some "chip-scale atomic clock"s, not much bigger than an OCXO, but a lot more expensive. https://www.microchip.com/en-us/product/csac-sa65

  20. comment
    Comment #48485931

    > They also over index fear of LargeCo stealing IP That seems to be a bold statement considering the whole business of this LargeCo is based on stolen IP.

  21. comment
    Comment #48313064

    This. If AMD / Xilinx would publish the documentation what you would need to use their chips, probably very few would use Vivado or ISE.

  22. comment
    Comment #48201902

    Not yet, but it is easy to imagine many ways it would be used for DRM.

  23. comment
    Comment #48201850

    > The point of SynthID is to make generated images identifiable, in an attempt to prevent 1984-esque situations where you can't believe your eyes and ears. You can still use tradit…

  24. comment
    Comment #48078030

    Maybe that's changes by country, but here bank transfers are basically final and can not be cancelled or recalled. Why would a bank cover your losses from their profits?

  25. comment
    Comment #48077987

    Chargebacks exists for (EU style) debit cards, too. It doesn't need to be simple just available, so if the merchant disappears with your money or someone uses your stolen card, the…