Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
FlxMgdnz
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
FlxMgdnz
3mo ago
Thanks for mentioning Hanko. Data minimalism is one of our core values, so I’m really happy to see that appreciated.
2.
▲
by
FlxMgdnz
4mo ago
Thanks for listing Hanko as EU-based authentication provider. To be upfront about this, we’re still on AWS (Frankfurt), but "EU-owned" hosting/data regions will be available very soon.
3.
▲
by
FlxMgdnz
9mo ago
For user authentication there is at least one European alternative to Clerk, and that’s Hanko (I am the founder). Granted, Hanko Cloud is still running on AWS (Frankfurt), but we’re working on alternative EU data location options right now.
4.
▲
by
FlxMgdnz
2y ago
Thanks :) The js SDK is almost done, mostly the docs are still missing, so I'd say 2-3 weeks. For mobile SDKs we're currently evaluating Kotlin Multiplatform, ideally that can help us manage the overhead a bit. We'd love to r
5.
▲
Show HN: Hanko – Open-Source Auth and User Management for the Passkey Era
(hanko.io)
11 points
by
FlxMgdnz
2y ago
|
2 comments
6.
▲
by
FlxMgdnz
2y ago
Just dropping this here: https://fidoalliance.org/specifications-credential-exchange-...
7.
▲
by
FlxMgdnz
2y ago
The solution to most of the author's criticisms lies in not forcibly mixing Passkeys and WebAuthn-based 2FA. As long as you are satisfied with passkeys being "usernameless" (i.e. discoverable), you can offer a nice login flow
8.
▲
by
FlxMgdnz
2y ago
Hey, founder of Hanko.io here, we run passkeys.io. That behaviour is not intended. We've recently changed the demo to require authenticator attestation on passkey creation, that may have an impact on authenticator selection. But a quic
9.
▲
by
FlxMgdnz
3y ago
Thanks for posting the link. Founder of Hanko here, happy to answer any questions on passkeys or Hanko Auth.
10.
▲
by
FlxMgdnz
3y ago
As a COSS founder I love the visibility we get for the issues we put on Algora. We've awarded $855 to 7 external contributors so far and are more than happy with the results. The founder team is awesome - Ioannis and Zaf are great guys
11.
▲
by
FlxMgdnz
3y ago
Hey, quick note from the creator of passkeys.io: You can always enter your email address on the login screen and this will initiate a fallback auth flow via email passcode.
12.
▲
by
FlxMgdnz
3y ago
Such an identity provider does not exist unfortunately, at least not with enough users to justify an integration for you. Of course you can always set up your own SSO provider (with the tools listed in AHOHA's comment), but that one wo
13.
▲
by
FlxMgdnz
3y ago
Apple, Google, and Microsoft are working together closely on passkeys.
14.
▲
by
FlxMgdnz
3y ago
We’re building https://www.hanko.io It’s a passkey-first authentication solution for websites and mobile apps.
15.
▲
by
FlxMgdnz
4y ago
Not quite. Passkeys are WebAuthn "discoverable credentials", meaning they contain a user identifier as well as a private key for signing. When a site fully supports passkeys, you are able to sign in to your account without having
16.
▲
by
FlxMgdnz
4y ago
Hey, we've built exactly what you are describing: https://www.hanko.io You can go with either self-hosted or cloud. Cloud is free for up to 100 users. If you have any questions along the way: https://www.hanko.io
17.
▲
by
FlxMgdnz
4y ago
Hanko.io is an open source authentication and user management solution that is optimized for passkeys as the upcoming default login method. The frontend (login box for now, user profile coming soon) is a web component, allowing for a simple
18.
▲
by
FlxMgdnz
4y ago
We decided to go with email passcodes as fallback method because of the limitations we identified with magic links. The biggest issue was the inability to sign in on devices where the users don’t have access to their email account to click
19.
▲
by
FlxMgdnz
4y ago
For the sake of the demo, email validation has been disabled to make the account creation as simple as possible and to allow fake email addresses to be used.
20.
▲
by
FlxMgdnz
4y ago
Thank you for the feedback. We get this question a lot, and it is obviously not ideal right now. Things will get much better with passkey autofill very soon, though. See also: https://github.com/teamhanko/hanko/dis
21.
▲
by
FlxMgdnz
4y ago
At some point, the platforms may open their APIs and allow for 3rd party providers to hook in and do the syncing. It can be expected that most current password managers will do that asap.
22.
▲
by
FlxMgdnz
4y ago
There are very few opportunities in the wild where you can use passkeys with a real account and not just a tech demo that pops up a WebAuthn modal. We've built passkeys.io to showcase what's possible with passkeys from the perspec
23.
▲
by
FlxMgdnz
4y ago
The demo in it's current state is built with a web component using shadow dom. Unfortunately, most browsers do not support autofill in shadow dom yet. A newer version using light dom will be available soon. Email codes are just the fal
24.
▲
by
FlxMgdnz
4y ago
It really depends on your security requirements and where you're coming from or what you're comparing it to. There would be still many advantages over, say, passwords stored in a pw manager, such as no shared secrets across all si
25.
▲
by
FlxMgdnz
4y ago
Currently, only platform authenticators are supported to create passkeys with. Support for Security Keys is in development and will be available soon. Certain combinations of Linux distros and browsers will then support passkey creation as
26.
▲
by
FlxMgdnz
4y ago
Email OTP is just the fallback authentication method of the demo in case a user does not have access to the passkey(s) anymore. Depending on the real world scenario, fallback authentication may either be completely disabled as soon as passk
27.
▲
by
FlxMgdnz
4y ago
By the latest definition, Security Keys also store passkeys.