Viewing profile — sufficient
sufficient
HN member- Joined
- Wed, Jul 23, 2014, 2:05 PM UTC
- HN karma
- 26
- Public activity
- 35 items
- HN profile
- View on Hacker News ↗
About sufficient
ex-maintainer of OpenKeychain
Recent public activity
-
comment
Comment #47149757
Thanks, that's interesting. We don't see all the smaller changes our competitors are doing. With heylogin, you could try our Quick Access feature. It pops up with a global shortcut…
-
comment
Comment #47148837
passkey support is currently in internal beta, but will be released soon. what kind of features have been removed from 1pw that you considered important?
-
comment
Comment #47143001
Hey, CEO and Co-Founder of heylogin here. Feel free to try out heylogin and let me what you think of it. I know we don't have feature parity with 1pw, but we try to innovate on the…
-
comment
Comment #37649360
You can try https://www.heylogin.com if you are looking for a new approach without a Master Password. I am one of the founders.
-
comment
Comment #34211904
Goldberg's answer "The 1Password Secret Key may not be the most user-friendly aspect of our human-centered design..." is unfortunately true. We experienced a lack of understanding …
-
comment
Comment #34151900
Just wrote a longer answer to the question below, hope that covers your question as well.
-
comment
Comment #34151782
You are asking the right & also complicated questions :) Let me first say that we are just finishing up a version 2 of our whitepaper that can answer all questions regarding the cr…
-
comment
Comment #34151463
maybe… I sort of agree it's not a huge hassle when recovering from another still functional 1Password installation. I still think that the initial flow of asking the user to print …
-
comment
Comment #34151117
I think we can do better in protecting vaults against offline brute force attacks. As written in the this post, 1Password uses a randomly generated "secret key" together with the u…
-
comment
Comment #34110308
This is a wake up to call to not build your security model on a user chosen master password! Since the vaults have been stolen, an offline brute force attack can be executed. This …
- story
-
comment
Comment #26125055
Yep, Nextcloud is using our SDK from https://hwsecurity.dev/ . We provide dual licensing for closed source and GPLv3 projects.
-
comment
Comment #26087616
Great work Fabian! Nice to see this work becoming open source. I am pretty new to fuzzing, please correct me if I am wrong: Since Jazzer fuzzes a Java application at runtime, can i…
-
comment
Comment #24132918
I agree that it's weird that they fixed it and didn't consider it a security issue. For the user it looked like it would provide two-factor authentication since the PIN is requeste…
- story
-
comment
Comment #20241153
We developed a vendor-independent FIDO U2F implementation for Android that works with Security Keys over NFC and USB. It's dual licensed under GPLv3 so you can inspect the source c…
- story
-
comment
Comment #20234980
I came to a similar conclusion: U2F hardware is the way to go. For some people, smartphones are becoming the only device they use. However, I am not fully convinced of using the de…
-
comment
Comment #16146966
On Android, we provide the OpenPGP implementation OpenKeychain that now also supports an impressive list of Security Tokens ( https://github.com/open-keychain/open-keychain/wiki/Se…
-
comment
Comment #13898452
Author of the paper here. Yup, in regards to Signal our findings are already obsolete :D I think that the new Signal developments are great. It is better to allow only one key veri…
-
comment
Comment #13898399
Author of the paper here. There is existing work on testing the feasibility of impersonating other person's voice. We discuss them in our related work section at the end of the pap…
- story
- story
- story
- story