Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Rafert
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
Rafert
6y ago
BoringSSL is still alive, Tink is something completely separate.
62.
▲
by
Rafert
6y ago
AFAIK Microsoft added token binding back in the Edge version based on Chromium. As other commenters pointed out, token binding is still part of the WebAuthn spec.
63.
▲
by
Rafert
6y ago
On Android any way you've set up to unlock the device can be used to also authenticate locally for unlocking the key material (stored inside a TEE): swipe pattern, finger print, PIN code, password, etc. Once that is done the key materi
64.
▲
by
Rafert
6y ago
Apparently git copied the 'master' name from bitkeeper, where it was used in conjunction with 'slave' branches: https://mail.gnome.org/archives/desktop-devel-list/2019-May/...
65.
▲
by
Rafert
6y ago
Time to send every employee a FIDO compatible security key, implement WebAuthn, and make it mandatory for employee login.
66.
▲
by
Rafert
6y ago
Link to that presentation: https://www.youtube.com/watch?v=rYzjKCIqUVk
67.
▲
by
Rafert
6y ago
It's not limited to POS - it has a way to pay during online checkout and tracks package deliveries.
68.
▲
by
Rafert
7y ago
Shopify tested it in production 2 years ago: https://engineering.shopify.com/blogs/engineering/shaping-th...
69.
▲
by
Rafert
7y ago
Costs might be lowering but not necessarily the fees charged: https://www.pymnts.com/visa/2020/report-visa-eyes-biggest-in...
70.
▲
by
Rafert
7y ago
https://www.immigration-quebec.gouv.qc.ca/en/immigrate-settl... mentions points?
71.
▲
by
Rafert
7y ago
Does disabling it (using # typed: ignore) for all files but in that folder work? https://sorbet.org/docs/static
72.
▲
by
Rafert
7y ago
The section title is correct: they're authenticators implemented in software, not relying on a TEE/TPM or any other bit of hardware for storing the keys. Apparently these don't run on on your CPU architecture and/or oper
73.
▲
by
Rafert
7y ago
> An Android phone itself can be used as a bluetooth hardware token, with Chrome on your laptop. If you're referring to the caBLE (cloud-assisted Bluetooth LE) transport: this is still being worked on ( https://github.com&
74.
▲
by
Rafert
7y ago
> They are stored on hardware tokens. Not necessarily: the WebAuthn spec mentions two other types of authenticators in the introduction section ( https://www.w3.org/TR/webauthn-1/#intro ): "Broadly, complian
75.
▲
by
Rafert
7y ago
Yes, that's what is recommended and most sites implement (AFAIK Twitter for some reason only permitting one :-/)
76.
▲
by
Rafert
7y ago
2.7 introduces `Enumerable#filter_map` for that. Example from the NEWS file: [1, 2, 3].filter_map {|x| x.odd? ? x.to_s : nil } #=> ["1", "3"]
77.
▲
by
Rafert
7y ago
> If the goal wasn't to require the key file-- why store the key handle there at all and not just derive it from data sent by the server as in a more typical U2F application? The only other advantage I see is potentially limiting so
78.
▲
by
Rafert
7y ago
That's covered in the article: > If this had happened in the 1980 accident, the rocket motors in the SRAMs, as well as the conventional explosives inside their W69 warheads, used to initiate the thermonuclear reaction, would very li
79.
▲
by
Rafert
7y ago
I used the Jaro-Winkler algorithm[0] for this and and it worked pretty well. It ranks common prefixes higher. [0]: https://en.wikipedia.org/wiki/Jaro%E2%80%93Winkler_distance
80.
▲
by
Rafert
7y ago
I thought of https://en.wikipedia.org/wiki/German_bombing_of_Rotterdam first. Here's the St. Lawrence church from the first picture of the article: https://parallel.co.uk/netherlands/#15/
81.
▲
by
Rafert
7y ago
With WebAuthn it doesn't have to be a USB fob - it can be built into your device too.
82.
▲
by
Rafert
7y ago
I'd point towards WebAuthn[0] as a reason why browsers implement CBOR, since that's much more widely supported. [0]: https://www.w3.org/TR/webauthn-1/#dependencies
83.
▲
by
Rafert
7y ago
With 2000+ people on that list the chances are pretty high there's at least one European included. At least this Dutch video game journalist complained on Twitter about his data being out there: https://twitter.com/twea
84.
▲
by
Rafert
7y ago
They have.
85.
▲
by
Rafert
7y ago
Still available on the GitLab instance linked from the home page: https://gitlab.potatofrom.space/kevin/potatofrom.space/blob/...
86.
▲
by
Rafert
7y ago
IRMA has existed for a while, it's a non-profit spinoff from a Dutch university. But to my knowledge it is nowhere as widely known or accepted by relying parties as DigiD[1], this system is run by the government and based on passing th
87.
▲
by
Rafert
7y ago
U2F is the legacy protocol, you should refer people to it's successor WebAuthn (and the FIDO2 hardware): https://webauthn.guide/ for an intro https://www.w3.org/TR/webauthn/ for the JS API
88.
▲
by
Rafert
7y ago
You're completely forgetting about non-native English speakers who use the long scale in their native language. They make mistakes or might even not be aware of the difference.
89.
▲
by
Rafert
7y ago
The salary he mentioned is 5k/month _after_ taxes, so 60k/year. Which according to a Polish income tax calculator I found would be about 85k/year EUR before taxes. With current rates that's about 95k USD. According to Nu
90.
▲
by
Rafert
7y ago
FWIW that is a really old spec. The FIDO 2.0 Bluetooth transport is described at: https://fidoalliance.org/specs/fido-v2.0-rd-20180702/fido-cl... But an article from VentureBeat[0] mentioned it's a new transp
More ›