23 ms·
Tell HN: Somebody implemented something I wrote a blog about
So a while ago I wrote about how 2FA was missing a key feature: https://syslog.ravelin.com/2fa-is-missing-a-key-feature-c781c3861db https://syslog.ravelin.com/2fa-is-missing-a-key-feature-c781...
Having not had any feedback on it in a while and the idea not taking off, today somebody messaged me to say that had implemented it in their product.
1. Obviously I think this is great and more secure
2. Tell people about things you do that they played a part it- it might just make their day.
- deleted 4y ago[deleted]
- mikessoft_gmail 4y agoI don't know of anyone who does 2FA this way.
- tra3 4y agoThat’s awesome. I was expecting a lament on how an amazing startup idea was stolen and monetized by someone else. Glad I’m wrong and the world is a little bit better.
- qorrect 4y agoHey me too, a little sunshine this morning :).
- tinmandespot 4y agoExact same sentiment :)
- NiagaraThistle 4y agoSame here. Came to say the same and to explain how i publicly share all my 'great' ideas publicly even though so many friends think I'm nuts in case someone 'steals it' and makes a successful startup from my idea. My answer: "Great for them. At least they had the determination and focus to follow through with bringing the idea to fruition when I couldn't."
- dhosek 4y agoPeople tend to overvalue ideas. I see this all the time in writing where people are worried someone will steal their great idea for a story. The truth of the matter is that it’s unlikely that you’ve come up with something truly new and in any event, ideas tend to breed and multiply. I will never write all the stories and novels that I have jotted down in my notebook before I die and there are more every day.
- qorrect 4y agoOn that note though, is there a way to protect your story if you want to pitch it to a publisher, or anywhere else ? Like a registry for story ideas ?
- aardvark179 4y agoNot really, and it’s not a problem. Ideas for stories are abundant, the ability to turn them into finished books or scripts is much rarer.
- Gene_Parmesan 4y agoThere's no IP protection for ideas for stories. Regardless, almost no fiction shop is going to agree to print a book on spec, just off a story pitch. Write the book first. Then you already have protection, in the form of copyright (which is automatic and doesn't require registration).
- ncmncm 4y agoIf an idea is any good, you generally have to fight tooth and nail to get anybody to listen to it, and put in a hundred times that to get anybody to understand it, and that again to act on it. If you don't directly control how that happens they will implement it fundamentally wrongly. But after it is finally implemented more or less correctly, everyone will agree that the idea was trivial and obvious, and they had already thought of it themselves, in exactly the form where they first encountered it, even if that is actually not quite right.
- Aethylia 4y agoCongratulations! Really good to hear, and definitely a nudge to me to let people know when their blog was useful.
- hanoz 4y agoCool, well done. Hope the idea gets picked up by a few more developers here. If you don't mind I'm just just pasting the URL into a comment to make it a link: https://syslog.ravelin.com/2fa-is-missing-a-key-feature-c781c3861db https://syslog.ravelin.com/2fa-is-missing-a-key-feature-c781...
- frakkingcylons 4y agoYes! That’s such a nice feeling. One of my GitHub projects was used in a demo at Google Cloud next a while ago. the presenter was considerate enough to attribute the project to me by name during the demo and even sent me an issue just letting me know about it. That was so nice! Absolutely people should do this.
- waynecochran 4y agoI actually had someone take one of my personal iOS apps from GitHub (https://github.com/wcochran/calfoo https://github.com/wcochran/calfoo) and submit it to the app store as if it was theirs. Someone else told me -- I was gobsmacked that someone was so brazen. Oh well, I didn't license it. It had special features that only mattered to me (and would be inappropriate for general use).
- rgbrenner 4y agoJust fyi, if something is unlicensed, then other people can only use it under fair use. You’re the copyright holder automatically upon publishing and retain all rights. If you intend to let people do anything, then you need to explicitly put it in the public domain or use an appropriate license. It’s very unlikely they can legally do what you’re describing… but it’s up to you to enforce it.
- langsoul-com 4y agoMost people wouldn't enforce it. Thousands in legal fees, chasing someone across different timezones and the sheer amount of work isn't worth it unless it's a legit business. Copyright laws really fail for those without money.
- Rygian 4y agoI would consider that as a bug, not as a feature. If the login panel behaves differently on a correct password than on a wrong password, that's an information leak that must be fixed. Authentication must be evaluated and rejected only when all factors are already provided, and the rejection error should not disclose which of the factors failed. So, with a proper login panel, my 2FA being asked does not mean that someone has my password. Edit: this is, for example, the recommendation from PCI to separate "Multi-Step Authentication" from true "Multi-Factor Authentication": https://www.pcisecuritystandards.org/pdfs/Multi-Factor-Authentication-Guidance-v1.pdf https://www.pcisecuritystandards.org/pdfs/Multi-Factor-Authe...
- Semaphor 4y agoYou make a good point, but does anyone do that? I’ve been using a PW manager so long, I don’t really enter incorrect passwords.
- DangitBobby 4y agoI don't know of anyone who does 2FA this way.
- rexfuzzle 4y agoThis was posted above: https://www.isnic.is/en/site/login https://www.isnic.is/en/site/login First time I've seen it too
- Rygian 4y agoMy employer does it for products requiring PCI certification. Our PCI auditor recommends it even though it's not a formal requirement of PCI v3.
- darkarmani 4y agoThat sounds like a terrible trade-off that makes people more likely to write down passwords on post-it notes or in a clear-text file to cut-n-paste. Especially if you lock accounts after a 10 tries or so (or PCI's ridiculous low number of tries).
- Ayesh 4y agoThe Iceland NIC does this (https://www.isnic.is/en/site/login https://www.isnic.is/en/site/login). Customer support burden when the lose the 2FA key is solved by adding a hefty fee (around €100) to recover it. No webauthn support yet though.
- rexfuzzle 4y agoInteresting- I think that is the first time I've seen password and 2FA code on the same page. Guess that means you may not know if your password or 2FA code is incorrect depending on the error page
- soco 4y agoOr the login process should just go ahead and ask the 2FA either way - and just fail you in the end without explaining why. And then notify only behind the scenes via mail that the password was correct but the 2fa wrong. That would be the way to handle it. I'd receive such notifications from time to time - I mix up the 2FA accounts sometimes, other times I'm slow typing and it expires - but I can live with that little extra email.
- Ayesh 4y agoAll my TOTP prompts (on websites I run) account for such delays and clock skews by checking against the previous and next TOTP. So even if the user is a little bit late to enter the OTP, I can still validate it and complete authentication.
- throwaway2037 4y agoThis is standard practice with big corporate RSA remote login.
- joshmanders 4y agoHonestly I'm shocked reading this. I _NEVER_ considered that scenario. Now I will be doing this in all my apps. Thank you!
- darkhorn 4y agoGmail has those features for some years.
- rexfuzzle 4y agoNot AFAIK- they email you when a new device logs in, or a new location, but I've never seen one from a wrong 2FA code
- ezekg 4y agoRelated: I think it's surprising how many services leak whether or not a password is correct. E.g. bad password => error, good password => 2FA prompt. You should verify a user's second factor before password.
- jve 4y ago> leak whether or not a password is correct Errm, could you elaborate what is the issue here?
- deleted 4y ago[deleted]
- ezekg 4y agotl;dr: The code should verify the user's second factor before the user's password. Consider this, scenario A: 1. When attacker enters a username and bad password. then they receive a bad password error. 2. When attacker enters a username and good password, then they receive a 2FA prompt. And then scenario B: 1. When attacker enters a username and bad password, then they receive a 2FA prompt. 2. When attacker enters a username and good password, then they receive a 2FA prompt. In scenario A, the website leaks password validity to the attacker. In the case of a brute force attack, the attacker can use the 2FA prompt as a signal that they found a good password. Scenario B does not leak that information, because the second factor was wrong or missing. More concretely, this pseudo-code: if user.authenticate_with_password(password) if user.authenticate_with_second_factor(code) # ... else raise InvalidSecondFactorError end else raise InvalidPasswordError end Should instead be this pseudo-code: if user.authenticate_with_second_factor(code) if user.authenticate_with_password(password) # ... else raise InvalidPasswordError end else raise InvalidSecondFactorError end Hope that makes sense. :)
- Eleison23 4y agoBut which 2FA prompt should they receive? If MFA can be configured using myriad choices, should a user be prompted to "Insert security key" or "Input security code" or "Send code to your email/SMS" or "Tap YES on your mobile device"? Since you can't know a priori what the second factor will look like, I'd say it's troublesome to try and present a challenge to every user regardless of their MFA configuration.
- jonas-w 4y agoI don't know about wrong 2fa codes but bitwarden notifies you if you have an "unfinished" 2fa login. If you type username and password correctly and then don't type in your totp token it will notify you.
- spiffytech 4y agoYears back, every web browser's built-in password manager locked up the page when submitting a login form, waiting for the user to answer "do you want to save this password?" before proceeding. I thought that was silly: how do I know if I want to save the password before I've seen whether it's correct? Which I can't see until the form is submitted. At the time I was using Opera, so I wrote in to their customer support suggesting that the prompt appear after the new page loaded. I never heard back, but a couple months later their next major release implemented exactly that behavior. A few months after that, every other browser followed suit. I can't have been the only one bothered by the existing behavior, but given how long browsers had worked that way before I wrote in, I like to tell myself that the timing wasn't a coincidence, and that my little suggestion rippled out into a change that made a small thing better for the whole world :)
- em-bee 4y agoi still see this behavior in firefox. the save password popup disappears by the time the page is loaded. and it baffles me every time how that is supposed to be useful.
- deleted 4y ago[deleted]
- iforgotpassword 4y agoThe stupid thing is that it already is async and not locking up like it was in the very old days op refers to. They were just so clever as to add a timeout after which that dialog closes, regardless of whether the page actually finished loading. So on a slower page you end up with the popup disappearing while the page is still (mostly) blank and you don't know yet whether the credentials were correct. I think just clicking in a blank spot (or the text fields) in that dialog stops the timeout, but it's one of these things I'm not actually sure about and it's almost like a cargo cult kind of ritual...
- kevincox 4y agoI find that it usually sticks around long enough. But I agree that it should stay open at least until I interact with something else. On the bright side it just collapses into a "key" icon in the URL bar that you can click to open it back up and save the password.
- Lendal 4y agoAs 2FA adoption spreads, the possibility increases that someone could be using 2FA but not know the rule about not reusing a password. This feature improves the spread of that gospel. It seizes the opportunity to impress an abstract concept to the technically-challenged in a way that is no longer abstract. I like it.
- NKosmatos 4y agoBravo!!! Such a simple (and more secure) change to the way 2FA works. This should be the standard and also mandatory in many similar cases. Good for you and for sharing this improvement, that’s the mentality all of us should have. Reminds me on how Volvo shared the 3 point safety belt patent with everyone else so as to make all cars safer, instead of keeping it to themselves I order to profit [ https://www.forbes.com/sites/douglasbell/2019/08/13/60-years-of-seatbelts-volvos-great-gift-to-the-world/?sh=52a6809a22bc https://www.forbes.com/sites/douglasbell/2019/08/13/60-years... ].
- jimmydddd 4y agoRe: Volvo's good deed -- In contrast, Edward Land (the Polaroid camera guy) came up with a system for polarizing car headlights and windshields to lessen glare from oncoming headlights in 1948. Apparently, none of the car manufacturers implemented it because there was nothing to gain financially from such a safety feature. https://www.polarization.com/land/land.html https://www.polarization.com/land/land.html
- spuz 4y agoOWASP actually includes this suggestion in their guidance for implementing MFA: https://cheatsheetseries.owasp.org/cheatsheets/Multifactor_Authentication_Cheat_Sheet.html https://cheatsheetseries.owasp.org/cheatsheets/Multifactor_A... > When a user enters their password, but fails to authenticate using a second factor...: > ... > Notify the user of the failed login attempt, and encourage them to change their password if they don't recognize it. > The notification should include the time, browser and geographic location of the login attempt. > This should be displayed next time they login, and optionally emailed to them as well
- Cthulhu_ 4y agoYeah I thought it weird that you only get an e-mail that someone logged in under a new account - passing the 2fa. But they should send one after correct username / password too. I don't mind getting an e-mail as another form of 2fa, but that has its own issues.
- travisjungroth 4y agoI think the email is just a failure notification, not a second factor.
- effnorwood 4y ago
- mooreds 4y agoSuch a great idea! I filed a feature request on our GH issues list to implement this: https://github.com/FusionAuth/fusionauth-issues/issues/1888 https://github.com/FusionAuth/fusionauth-issues/issues/1888
- wannabebarista 4y agoI had a similar experience and it certainly made my day! I wrote some code to parse nested JSON and fill a hole in a tutorial. Here's my relevant post: https://bcmullins.github.io/parsing-json-python/ https://bcmullins.github.io/parsing-json-python/. Here's the plug for the project using my code: https://github.com/sinnfeinn/microweather https://github.com/sinnfeinn/microweather.
- zoomablemind 4y agoIt's a nice courtesy from the product authors/implementors. Not only it's polite, it also acknowledges your contribution to the idea, not sure to which extent it is formally. All in all it is a great feeling to see your idea getting a concrete life. In a way, reporting an issue and a possible improvement to any product you care about is an essence of collaboration. Open source further helps to contribute by augmenting such effort with a skill to implement it.
- alittlecringe 4y ago
- AlwaysRock 4y agoI havnt done this in many years but for a while I was making creative content that was published online. Once in a while someone would contact me saying they liked what I did. I started doing the same. If I read an article I liked a lot I would contact the person and tell them I liked it and why. About half the time they responded with Thanks. I didnt do this with NYT writers or anything. Just people who clearly dont get paid/paid much to make this content but I found it useful/interesting/helpful. I think that stuff goes a long way and it really doesnt take that long to do. I've got a tech podcast now and about once every month or two someone contacts me to say they liked it or something nice. It's a huge reason why I keep doing it. I know that sounds silly but the internet can be such a black hole. A little feedback goes a long way.
- miqueturner 4y agoThis was a good comment. Keep it up!
- avg_dev 4y agoI tend to see a lot more negativity than positivity as the default response so I like this thread.
- whatsdoom 4y agoI have a little blog that occasionally gets hits when the SEO winds blow my way and twice people have reached out thanking me for a post. It's made my whole month! And encourages me to keep posting stuff. So I really appreciate that you do that, I should make an effort to do the same. I write the blog as more of documentation for myself than something to share, but knowing that I've helped someone else is icing on the cake.
- clarge1120 4y agoReally enjoyed the insightful view. I bet it starts a fire on the internet.
- mncharity 4y agoAFAIR, a 1980's MIT AI Lab "how to do research" memo, suggested as one way to build things: describe what you'd like to build, and maybe someone else will be inspired to do it, long before you'd have gotten around to it.
- mikewarot 4y agoI'm still waiting for the Memex, you would think someone did it between 1945 and now, but nope. 8(
- bilekas 4y agoWe implemented something that avoids the original articles, 2FA notification. After your password is approved before 2FA you get an email. So even if someone is somehow using the right 2FA you are aware. Our thinking was the mosly likely outcome was someone would hit 2FA, not have the code and so close the request without even entering a bad code. Apart from that though, it is always nice to get recognition for the stuff you put out there. I know I should do it more myself too.
- lupire 4y agoBut email can be delayed for hours or days.
- bilekas 4y agoThat's pretty rare in our scenario, also it still would apply to the original post ?
- kevincox 4y agoIf you are going to send login notifications anyways this makes sense. Since the user will either want to know about the login or the failed 2FA. However if the user doesn't enable login notifications I think it makes sense to give a short timeout to wait and see if the authentication is successful. If the auth is successful you can skip the alert.
- redsummer 4y ago
- EGreg 4y agoI agree but there is an even more serious security feature almost all 2FA misses: Telling the user what action they are authorizing by reading back the numbers. That “bank rep” on the phone? They are probably trying to log into your account, or withdraw cash, not verify that you are the right person to send the refund back to. It would save a lot of problems. Also you should be getting an alert on all your devices whenever transactions over X amount per Y time occur, and you should have an opportunity to reverse them for 24 hours (even for debit cards). Also you should be able to make windows during which time it would be longer than 24 hours, such as a Jewish holiday or when out of range. This wouldn’t apply to recurring transactions.
- PeterisP 4y agoYes, that's a cool feature - the Smart-ID app used by many banks in Baltic countries as a second factor does that, it states e.g. the payment and amount you're authorizing before you do so.
- flippinbits 4y agoActually, PSD2 SCA (Strong Customer Authentication) talks about requiring 2 different elements (out of knowledge, possession, inference) for authentication, while also requiring that information on which one was wrong when authentication failed, to not be disclosed. This directive needs to be implemented by all payment processors in EU (I am not an expert on this). We have implemented such a system at a company I worked at, where we also took into account the credential stuffing aspect as you talk about it. It is quite challenging to ensure no information leaks (in content and in other request parameters, including response times) when users transition from the partially (un)authenticated state (username + password) towards 2FA. I have to say that security aspect is noticeable in a significant drop in credential stuffing attacks volume, but usability wise I see why this is not a popular approach :). I personally hate it, especially when 2FA that is used is TOTP.
- sagebird 4y agoAlso, if someone logs in with correct username and password and -does not- attempt to try the 2FA, I also want to know about it.
- kevincox 4y agoYeah, it should basically be a timeout. If within a few minutes of entering the correct password a correct second factor is not provided then it should notify the user. I think you can probably skip notifying on a single failed OTP code to avoid spamming the user when they make a typo (or are a bit too slow for TOTP) but if you were very paranoid you could also send in this situation.
- coenhyde 4y agoWhen Apple released the very first iPod, I wrote to Steve Jobs to tell him that I would buy it if it was a phone too, as i don't want to carry two devices. I doubt I was the only one who had this thought, but I like to think i influenced the development of the iPhone. I never received a response from Steve.
- teekert 4y agoAh but you didn’t add that you wanted it to be an internet communicator as well! Only would you have been able to claim some credits ;)
- egberts1 4y agoI once wrote something obscure. About communication piggybacked over TCP/IP without changing any one bit of packet data. https://egbert.net/blog/articles/pulse-width-covert-channel.html https://egbert.net/blog/articles/pulse-width-covert-channel.... Some 20 years later, a guy posted on GitHub. https://vimist.github.io/2019/01/30/Steganographic-Packets.html https://vimist.github.io/2019/01/30/Steganographic-Packets.h... And made my day.
- nishnik 4y agoFive years back, YouTube didn't have the feature to queue your videos on the fly. You could have created a playlist, but then it is the same sequence of songs every time. So I hacked a chrome extension to add/remove songs to a dynamic queue saved on your LocalStorage[1]. Later, YouTube added the queue feature. Sometimes I go on long hikes and think that it wasn't merely a coincidence. :) [1]: https://github.com/nishnik/Play_Next https://github.com/nishnik/Play_Next
- Kalanos 4y agoNormies: what the heck he stole your idea :angry:
- wallfacer 4y agoIf any Spotify devs are here, please let me explore and add songs, artists and albums to my library without “hearting” it. I often just want to follow up later by “adding to my library,” and it feels weird to “LOVE” it before ever hearing it. I really feel pain when I hear something terrible that I’ve already “liked” and consider the impacts to my algorithm. Please distinguish between “like” and “save.” A simple “plus sign” or really any other symbol that signifies “adding to a collection” without “liking” connotations (stars are out too).
- scetron 4y agoOof! They used to have this for Songs, then they removed the feature, and I lost the major way I used Spotify. I used it to make sure I could listen to music offline while traveling and it was an infuriating few flights before I could download everything again.
- why-el 4y agoNow that you opened this forum for Spotify feedback: If I do "like/heart" a few songs and then go to the Radio based on one of them, please don't show the songs I already liked in that Radio. I mean, I already "liked/saved" them, why are they appearing in my discovery phase?
- a_t48 4y agoDisagree on that - Radio is not just for discovery but also for easy random playlist creation.
- posix86 4y agoThat's one of their best features!! I'm using discovery bcs I want to listen to tracks similar to the one i use as a basis. If they mix some of my liked tracks in there that are similar too (which they usually are), that makes it even more enjoyable. Idk about you, but I use Spotify to listen to good music.
- gmueckl 4y agoI'd like to have a different tiny change in the "Song Radio" feature: if you start playing that playlist, skip the song it's based on if it was recently played or is currently playing. It's mildly annoying when you switch to that feature after stumbling across an interesting track and the first thing you hear is the same track again.
- gjvc 4y agothat'll teach you
- teekert 4y agoSome 10 years ago I pointed out the lack of ssl or starttls on my mail provider’s smtp servers. This was the Netherlands biggest provider Transip they said it was an interesting observation that they were going to discus, some months later I go a big announcement over email about their new secure email platform, yes it was all the same but now with ssl.
- avg_dev 4y agoThis is a heartwarming post and I enjoyed all of the comments. As an aside I would recommend using U2F over OTP. This article explains some of the benefits: https://www.yubico.com/blog/otp-vs-u2f-strong-to-stronger/ https://www.yubico.com/blog/otp-vs-u2f-strong-to-stronger/
- theappanalyst 4y agoI enjoyed when a french hacker used information from my blog to set off all the alarms of Bird scooters in Lyon France for an evening. I had written about (what I considered as) a vulnerability that allowed remote triggering of Bird Scooter alarms (Bird disagreed of course) on my blog [1]. I then saw this github repo linked in the comments for setting off alarms of Bird scooters [2] and reached out to the author. The author let me know that they had used the info in my blog to script a tool for setting off Bird Scooters en masse. They then targeted the script at all the scooters in Lyon and subsequently fell asleep. When they woke up the noticed the end point was disabled... Bird had taken the action to disable the API endpoint in response of course. Probably would've been easier to fix before someone scripted it out but it made for a fun story. [1] https://theappanalyst.com/bird.html https://theappanalyst.com/bird.html [2] https://github.com/pcouy/bird-whisperer https://github.com/pcouy/bird-whisperer
- canjobear 4y agoThe main feature that 2FA needs is non-existence.
- CobrastanJorji 4y agoIf you have better options, I'm all ears.
- posix86 4y agoI asked Notion to implement inline LaTex, bcs it's the last thing missing for me to use Notion during math lectures. They did so a couple weeks later, even told my I was part of the reason they did!
- makz 4y agoI once sent Apple feedback about how activity monitor was missing some metric, I don’t remember what it was. Never heard back from them but in the next OS X release it was there.
- Minor49er 4y agoI've noticed several services in the past that have blocked someone at the 2FA step (either due to getting to that stage and leaving or attempting and failing), then notified the account owner that a login was attempted. I think we just don't hear about it too often because not everyone who has compromised credentials also has 2FA enabled on their accounts in most publicized hacks
- forrestthewoods 4y ago> Tell people about things you do that they played a part it- it might just make their day. Agree so much! I’ve met numerous people, often co-workers, who say “oh I know you I used your blog post”. Wish they’d have shot me a quick email! It’s always a nice surprise when someone reaches out to say thanks.
- _dain_ 4y agoA few months ago I had a ghastly time trying to take a bike along with me for a multi-stage train journey across the UK. Trainline is good about abstracting away the (pointless) differences between the train operating companies -- it's just a single interface and you never have to know which company operates which section of the route. But this abstractions breaks the minute you want to bring a bike on board -- you need to contact each company separately, and each one has its own bespoke and annoying way of doing it. Some by phone, some by email, some through their website (that you need an account for), some by social media(!). So I emailed Trainline's customer support saying how lovely it would be, if bike reservations were as seamless as people reservations, and to pass along the idea to their dev team. Lo and behold, while booking a journey the other day I noticed a new option for bike reservations on the route planner interface, that I'd never seen before. I haven't had opportunity to use it yet, but I hope it works well, and I'd like to think that it was my email that tipped the scales into it getting implemented (Lord knows I can't have been the first to ask for it).
- punnerud 4y agoAbout 10 years ago I e-mailed OxfordDictionary asking if they could change the webpage so you could start typing your search right away, and not have to click the search area first. It made my day when they some days later had implemented it, and emailed me back with a message that they now had implemented it.
- markdown 4y agoA few years ago I tweeted them to say that they had a word definition wrong. They changed it!
- jaxn 4y agoI emailed Tim O’Reilly in ~2001 and suggested they release PDF versions of their “Pocket Guide” reference books. I wanted to be able to have all of my pocket guides on my Sharp Zaurus (Linux handheld with keyboard, color screen, and Wi-Fi). He went for it and offered me PDF copies of every Pocket Guide as a thank you.
- weaksauce 4y agogreat stuff rexfuzzle! that is indeed something that should be part of the standard security of apps nowadays. it costs surprisingly little to clone a phone number and get those 2fa requests on a new phone so any heads up would be great to know.
- quickthrower2 4y agoIf anyone in the 2FA business is reading this, I find the Google authenticator process annoying! Unlock phone, find app, scroll to find which code to use, wait for it to time out (maybe) then enter code manually on desktop PC. Could this be made smoother?
- rlpb 4y agoFIDO solves this. The process is: push button.
- v64 4y ago> Tell people about things you do that they played a part it- it might just make their day. Thank you for putting this out there! I once reverse engineered the protocol for a popular mobile game so I could write my own client for it and posted my library online for others to do the same without any expectation it'd ever get seen. Months later, I received an email from someone reverse engineering the protocol as well for different purposes. They got stuck on a particularly difficult issue I also encountered (and documented), and googling it led them to my library, saving them hours of future work. It definitely made my day and I'm still very proud of that project because of that. Edit: There's a second part too! I just remembered that I've posted this story on HN before, and the last time I did a dev for the game emailed me saying he looked over the code and was impressed that I was able to figure out so much despite their deliberate efforts to keep the protocol locked down. Another great day!
- duckmysick 4y agoImpressive story! Did the devs try to further obfuscate the protocol after they discovered your library?
- v64 4y agoBy that point, I no longer played and the game had gone through a rewrite that used a new API, so my library no longer worked and I never updated it for v2.
- drengus 4y agoI made a github-codespaces-ish development environment using GCP and terraform mere months before githbu announced codespaces: https://lockwood.dev/development/remote/2020/03/17/experiments-in-infrastructure-for-remote-work.html https://lockwood.dev/development/remote/2020/03/17/experimen... But also, the idea was kind of obvious given the way VSCode was going with its ssh plugins.
- HorizonXP 4y agoThis is precisely what I love about the Internet and humanity. Recently, I got into RC cars. I was watching a YouTube video discussing the long-term issues that can arise with the particular model I own. In the video, the presenter mentions that “maybe you could 3D print something” to help address a deficiency in the vehicle design. I just purchased a 3D printer, and thought, “Maybe I can design it myself.” Lo and behold, someone already did, and cited the same YouTube video as their inspiration: https://www.thingiverse.com/thing:4982263 https://www.thingiverse.com/thing:4982263 How amazing and cool is that??!
- est 4y ago> a service that notifies you if your 2FA code was entered incorrectly Even better, let the login pass after some incorrect credential guesses, the login goes to a random fake account.
- call-me-al 4y agoI filled in a market research survey for Hetzner they sent me by email. There were many questions on how can we do better, etc. I suggested to use the fact that they are Germans to convey high-quality and attention to details. Months later, I received a promotional email by them in which they were using almost word by word what I had suggested. I guess this one is on me, Hetzner.
- userbinator 4y agoDid you intend the pun? A "key" feature? ;-)
- anshumankmr 4y agoNo kidding -> I am a beta tester for Whatsapp on Android (I don't really do anything much nowadays but some years ago I wrote a feature request for it that there should be a way for a small business to communicate with it's users (my parents own a small business). A couple of years later, Facebook rolled out a Whatsapp for Businesses API. So you maybe have me to thank for this (I don't really believe that my message really caused this to happen, it's for sure a weird coincidence to me)
- archon810 4y agoCan you share who implemented it?
- jawadch93 4y ago
- langsoul-com 4y agoThe email notification for incorrect 2fa entry seems like a great idea. We already get emails for suspicious login attempts, which isn't too useful as it's probs brute force and guessing. Too bad it requires mass adoption to become a norm.
- dfhdfh 4y agoytrytryrtet
- Jenny_Wengerd 4y ago
- robotwizard 4y agoWho implemented it?
- thimkerbell 4y agoDo people generally find it easy to find a channel for telling the product maker about the bug or potential improvement?
- Bedon292 4y agoIf something bugged me enough I really wanted to provide feedback, I don't think I have ever not found a way to send it. There is normally some way to do it but definitely can be tricky. GitHub issues, feedback forms, or even just the contact us page on their website. Not guaranteed to get a response, but at least an attempt was made. And it certainly can take a level of dedication and technical knowledge not everyone might have.
- hamoid 4y agoOnce I realized that Flash .swf files could be compressed to half the size using gz, so I sent an e-mail to Macromedia suggesting that they zip their files. The next version had that feature enabled by default, which made me happy :-) Also, at the time when interactive maps had 4 arrows to click and move North, South, East and West I developed a map using Flash and MapServer where you could drag the map around with the mouse. I sent a message to Google to show my work and they replied saying it was cool. Later Google maps came out with such an interface. I'll never know if my messages had any impact but I can still dream they were my inventions :-)
- minifyre 4y agoI once contacted Patreon about re-adding support for non-SMS-based 2FA & while the customer service agent didn't seem to entirely understand, they did forward my request to the dev team when I asked. A few days/weeks later, it was back[1]. I'm grateful for all those involved who made that happen, as most companies don't listen when contacted about 2FA. And tangentially, while I can't be as certain about my involvement in this next part, Nickelodeon eventually uploaded a non-pixelated version of ATLA on Google Play shortly after the second time I contacted them. I still can't understand how an MS Paint quality version was uploaded in the first place, but I'm glad no one else will have to suffer through that like my brother did. [1] https://blog.patreon.com/TOTP-two-factor-authentication https://blog.patreon.com/TOTP-two-factor-authentication