Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
PranavBerry
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Turkey does not favor Sweden and Finland’s membership in NATO
(bloomberg.com)
2 points
by
PranavBerry
4y ago
|
1 comments
2.
▲
Cartels might shorten LED bulb life, increasing emissions
(bloomberg.com)
21 points
by
PranavBerry
4y ago
|
7 comments
3.
▲
Online Ads Are on the Way to Becoming Less Creepy
(bloomberg.com)
6 points
by
PranavBerry
5y ago
|
3 comments
4.
▲
by
PranavBerry
5y ago
Location: India Remote: Yes Willing to relocate: No (can work remotely according to another time zone) Technologies: Python (FastAPI, Flask, Django) JavaScript/TypeScript (React, React Native, Node.js) Machine Learning (Numpy, Scikit-L
5.
▲
by
PranavBerry
5y ago
Remote: Yes Willing to relocate: No (but can work remotely according to another time zone) Technologies: JavaScript/TypeScript (React, React Native, Node.js) Python (FastAPI, Flask, Django) Machine Learning (Numpy, Scikit-Learn, Pandas
6.
▲
Vendors refusing credit cards issued by Indian banks
(thehindubusinessline.com)
1 points
by
PranavBerry
5y ago
|
0 comments
7.
▲
Better.com CEO Admits He ‘Blundered’ in Firing 900 Workers in a Zoom Call
(bloomberg.com)
1 points
by
PranavBerry
5y ago
|
0 comments
8.
▲
by
PranavBerry
5y ago
Location: India Remote: Yes Willing to relocate: No (but can work remotely according to another time zone) Technologies: JavaScript/TypeScript (React, React Native, Node.js) Python (FastAPI, Flask, Django) Machine Learning (Numpy, S
9.
▲
Did That Chatbot Just Make a Rude Joke?
(bloomberg.com)
2 points
by
PranavBerry
5y ago
|
0 comments
10.
▲
by
PranavBerry
5y ago
>If I'm a common person with one phone I had not thought about that but I think I can add push notifications if this is a problem. So on your phone you just tap the login with my authenticator button and approve the push notificatio
11.
▲
by
PranavBerry
5y ago
> plug my Yubikey into as many laptops as I would like. What if you don't own a physical key? > I have to trust you to not leak my 2FA. Authy does this already and so I don’t use Authy This is optional. You can choose not to hav
12.
▲
by
PranavBerry
5y ago
>Is your service going to be audited by independent third parties that vendors choose? Yes I am planning to do that. >How do people verify that your application is the legitimate version? How does the bank know if someone has tampered
13.
▲
by
PranavBerry
5y ago
> FIDO Alliance is doing with WebAuthn Yes I looked into it, but it looks like WebAuthn does not support multiple devices (let me know if I am wrong). What if I want to login from two different devices? I don't think that is possibl
14.
▲
by
PranavBerry
5y ago
>intercepting traffic or spoofing a site can copy/tamper/replace the QR code Will this be a problem with HTTPS? When you open a page, a request will be made to my server to generate a unique login attempt, the id of this unique
15.
▲
by
PranavBerry
5y ago
>As for QR codes, those can be copied The QR code are unique for every login attempt. After you scan the QR code and enter your phone's pin, my authenticator will send a request to my server. If everything is ok you will be logged i
16.
▲
by
PranavBerry
5y ago
> SMS based 2fa has many other problems What are these problems? It will be great if you can list some of them, I'd like to read more in detail.
17.
▲
Why is using SMS bad for 2FA?
17 points
by
PranavBerry
5y ago
|
26 comments
18.
▲
by
PranavBerry
5y ago
Got it, but there will still be a network effect. You will just have to download it once and can add and manage accounts on a lot of websites.
19.
▲
by
PranavBerry
5y ago
>have a Msft Authenticator and a Google one I think you can just add all accounts to one authenticator. >make it work with one of these These authenticators, have no support for QR codes so this would not be possible.
20.
▲
by
PranavBerry
5y ago
>agree with password-less. Does my idea sounds like something you would use? Will you download a authenticator app to avoid using user/pass?
21.
▲
What do you think of Scan QR to Login as a Service?
3 points
by
PranavBerry
5y ago
|
9 comments
22.
▲
by
PranavBerry
5y ago
>the website display the QR code and the phone scan it I'm exploring that right now, thx a lot. >I'm probably missing the point of your idea. It was mainly a way to do 2FA with a phone but no SMS/internet on phone. Howe
23.
▲
by
PranavBerry
5y ago
> TOTP and similar already solve the "phone is present but offline" issue. Thanks a lot, this invalidates my idea and I will not work further on it.
24.
▲
by
PranavBerry
5y ago
> How will a website be able to scan my phone's screen? Using your webcam. However from the comments it seems that there are a lot of devices without a webcam so my idea will not work.
25.
▲
by
PranavBerry
5y ago
If the phone not having a internet/network coverage was a problem, my idea could be useful. It also makes the phone a kind of hardware token, a user can login only if he has his phone. However from the responses it looks like this is n
26.
▲
by
PranavBerry
5y ago
> If the user needs to be loggedin somewhere, they must be online I will be using JWTs, with asymmetric signatures. An internet connection will only be needed while adding the device for 2FA. The JWT will be generated from the private ke
27.
▲
How do you handle 2FA?
16 points
by
PranavBerry
5y ago
|
26 comments