Live data from Hacker News

Viewing profile — timmyc123

timmyc123

HN member
Joined
Wed, Mar 24, 2021, 5:43 PM UTC
HN karma
20
Public activity
62 items

About timmyc123

No profile information was provided.

Recent public activity

  1. comment
    Comment #49014382

    Still taking feedback and questions for an upcoming consumer centric "What's a passkey?" site. https://forms.gle/wmaydkzmUp2eKfJG7 Original post: https://news.ycombinator.com/item?…

  2. comment
    Comment #49013802

    You can use any credential manager you choose for Microsoft Account passkey.

  3. comment
    Comment #49013692

    https://mobileidworld.com/apple-introduces-cross-platform-pa... https://support.google.com/chrome/answer/13068232?hl=en&co=G... https://1password.com/blog/import-autofill-organize-…

  4. comment
    Comment #47852850

    We’re building an interactive resource to demystify passkeys for both the general public and more technical users. We’re aggregating questions to ensure our FAQ and interactive gui…

  5. story
  6. comment
    Comment #47221011

    > The essay has a condescending attitude towards the normie computer user who can't possibly be expected to know, but it's precisely the normie computer user who would never get th…

  7. comment
    Comment #47220949

    You can use any credential manager you choose. It is an open ecosystem. If you don't want to use a cloud service, don't. You can self-host many credential managers. There are also …

  8. comment
    Comment #47220872

    Hey I'm the guy you're talking about. Always easy to crap on people when you selectively quote what they said. The core pieces you left out are: > I don't quite understand why requ…

  9. comment
    Comment #47220785

    > Too bad the spec is stupid and requires password managers to be identifiable so servers can deny the "insecure ones". There is no requirement that credential managers identify th…

  10. comment
    Comment #47183983

    Not sure what you mean. In most cases, passkeys sync across your devices.

  11. comment
  12. story
  13. comment
    Comment #46312405

    > stored on a YubiKey/Secure Enclave/TPM and that was what made them resident. Stored in an authenticator/credential manager in general, not specific to a security key, secure encl…

  14. comment
    Comment #46308356

    Not really. The attestation model defined for workforce (enterprise) credential managers/authenticators doesn't really work in practice for consumer credential managers.

  15. comment
    Comment #46307525

    A passkey is a discoverable credential (aka resident key) in spec terminology. But the type of credential has no relationship to attestation (which is not used in the consumer pass…

  16. comment
    Comment #46307507

    The dialog provided by the browser or OS usually tells you where the passkey is saved.

  17. comment
    Comment #46307499

    Copy and paste in clear text? Yes, I don't think that's a good idea. Download to disk in clear text? Yes, I don't think that's a good idea. Years and years of security incidents wi…

  18. comment
    Comment #46307468

    If a website were to attempt to do this, you (or your credential manager) could simply change the AAGUID to match another credential manager.

  19. comment
    Comment #46307454

    Attestation is not used in the consumer passkey ecosystem.

  20. comment
    Comment #46306328

    Hi, Tim Cappalli here. Not sure how stating that my (an individual) opinions on a topic are evolving is interpreted as "threatened the KeypassXC developers". If you've been followi…

  21. comment
    Comment #46306280

    This is one of the core use cases for why FIDO Cross-Device Authentication was created. To be able to use a passkey to sign in on a shared device, a device you don't control, or a …

  22. comment
    Comment #46306274

    > it’s discouraged Why do you say that? There are billions of synced passkeys being used by users with some of the largest sites and services in the world.

  23. comment
    Comment #46306266

    Not exactly. For example, the default credential manager on Android is Google Password Manager, which works on Windows, macOS, iOS, and Ubuntu. There are also dozens of other third…

  24. comment
    Comment #46306239

    I used the technical name for the capability, but you've likely run into it before. If there is no passkey on the local device, a QR code will appear which you can scan with your p…

  25. comment
    Comment #46306217

    Unclear how this quoted comment relates to what I was replying to (which was about exporting / backing up your credentials). But I'll respond. > Will I always be able to use any cr…