Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Rafert
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
91.
▲
by
Rafert
7y ago
WebAuthn is the successor to U2F. This is just another transport (caBLE/"cloud assisted Bluetooth") for this standard in addition to NFC, USB and a direct connection to a Bluetooth authenticator (e.g. Feitian and Google Titan
92.
▲
by
Rafert
7y ago
Browser support is pretty good: https://caniuse.com/#feat=webauthn - and Google submitted the caBLE transport to the WebAuthn working group. Give it some time. And don't count out governments just yet, U2F got some lov
93.
▲
by
Rafert
7y ago
That's a bit snarky. As other commenters mentioned, it can leverage TEEs using the Android Keystore for secure storage. And the way WebAuthn works means users are protected in case of a database breach (it contains only public keys) an
94.
▲
by
Rafert
7y ago
Before the announcement I've seen references to a 'caBLE'/ 'cloud assisted Bluetooth Low Energy' transport on the Web Authentication mailing list and W3C spec GitHub issues, this is exactly that. The VentureBea
95.
▲
by
Rafert
8y ago
blog post by the author about the algo: https://brandur.org/rate-limiting
96.
▲
by
Rafert
8y ago
Feitian makes devices with Bluetooth support: https://www.ftsafe.com/Products/FIDO/Multi
97.
▲
by
Rafert
8y ago
Currently, it does not because the browser aborts when it loses focus: https://github.com/github/SoftU2F/issues/51
98.
▲
by
Rafert
8y ago
I'd like to point out that U2F has been superseded by WebAuthn[0]. It's backwards compatible with U2F keys and doesn't require a bunch of JS since support is built into browsers[1]. Some hard/software combinations allow
99.
▲
by
Rafert
8y ago
Is Transit ( https://transitapp.com/ ) available where you live? If there's no official API for realtime updates, it also allows you to share your GPS data to the rest of the app users for crowdsourcing this info. Overal
100.
▲
by
Rafert
8y ago
Benchmarks here: https://medium.com/@k0kubun/ruby-2-6-jit-progress-and-future... tl;dr: your Rails app is not faster with this feature in this version, but might be in the future.
101.
▲
by
Rafert
8y ago
In this case nobody can surely say it was only a vulnerability, which IMO warrants treating as a breach.
102.
▲
by
Rafert
8y ago
With a bit of searching I found "Guidelines on Personal data breach notification under Regulation 2016/679"[1] which states: > Although the GDPR introduces the obligation to notify a breach, it is not a requirement to do s
103.
▲
by
Rafert
8y ago
> It is not and never has been a norm for SAAS vendors to disclose internal vulnerabilities that have not been discovered independently by third parties. The bug sounds like it would need reporting to a data protection authority under th
104.
▲
by
Rafert
8y ago
That would mean that you trust the client completely to log somebody in. What's preventing somebody from bypassing the clientside bcrypt check? As long as the password is sent over a secure channels (TLS) and doesn't leak somewher
105.
▲
by
Rafert
8y ago
Interestingly their code checker is just a bunch of regular expressions: https://github.com/hyperloop-rails/static-checker - I would've expected custom Rubocop rules. Rubocop already knows about `where.first? =>
106.
▲
by
Rafert
8y ago
I feel refinements are best suited for libraries. E.g. compare this improvement to the CSV gem: https://github.com/ruby/csv/pull/30 which defines it only for itself, compared to ActiveSupport defining it glob
107.
▲
by
Rafert
8y ago
How is requiring a SMS token in addition to a password less secure than just requiring the password?
108.
▲
by
Rafert
8y ago
The logical follow-up question would be; how does it compare to fzy? :) https://github.com/jhawthorn/fzy
109.
▲
by
Rafert
8y ago
Uber uses Adyen.
110.
▲
by
Rafert
8y ago
> I don't feel like I know enough about it to know just how good it will be for the average person. It's the successor of the work Google did with Yubico that eventually led to Fido U2F. Google did some user research about the
111.
▲
by
Rafert
9y ago
It's not 18k req/s, but 80k: https://youtu.be/N8NWDHgWA28
112.
▲
by
Rafert
9y ago
U2F does NOT require a hardware key - only a secure cryptographic processor. It could be built into your laptop. There were some rumours floating around that Chromebooks would receive fingerprint scanner that would enable this. It would mak
113.
▲
by
Rafert
9y ago
This bit is a little buried, but it's the biggest win IMO: > With Google Pay, it’ll be easier for you to use the payment information saved to your Google Account On the web/in Android apps this allows you to pay with any credit
114.
▲
by
Rafert
9y ago
They forked: https://github.com/Shopify/turbograft to add partial page replacements. It was slated to be merged in TurboLinks 3 but that canned in favour of version 5. Their new Polaris components are using React thoug
115.
▲
by
Rafert
9y ago
Exactly. Medicinal marihuana or more recently MDMA for PTSD treatment ( https://news.ycombinator.com/item?id=15120656 ) all took a while too.
116.
▲
by
Rafert
9y ago
Because it's complicated and most people don't need that complexity at all. For some reason a lot of people happily jumped on the band wagon when this was released and started writing scripts to make it more bearable. If you have
117.
▲
by
Rafert
9y ago
Link for the curious and/or lazy https://www.w3.org/TR/webauthn/
118.
▲
by
Rafert
9y ago
The introduction of similar oBikes in Amsterdam and Rotterdam prompted comments from my friends seeing similar bad behaviour. Meanwhile I live in Montreal, where with the Bixi bikes you need to return them to a station (spread throughout th
119.
▲
by
Rafert
9y ago
> events following those described in my previous letter (referred to herewith as Epistle 2). If 'Epistle 3' does not mean 'Episode 3', then 'Gertie Fremont' does not refer to 'Gordon Freeman'. Tha
120.
▲
by
Rafert
9y ago
> Ruby has [...] likewise community gems with more robust functionality like Quasar. https://github.com/ruby-concurrency/concurrent-ruby for those wondering. Rails uses it as of version 5.
More ›