Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Zinggi
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
Zinggi
3y ago
Pretty sure you mean this one: https://thedailywtf.com/articles/The-Speedup-Loop
2.
▲
by
Zinggi
6y ago
In JS, my preferred way of handling json is heavily inspired by the elm json decoding way. I want my decoders to essentially do 2 things: 1. Transform received data into a data structure that is best suited for my app. This might involve co
3.
▲
by
Zinggi
6y ago
You shouldn't validate json. You should parse it, e.g. transform it into your desired data structure if it comes in in a valid shape. https://lexi-lambda.github.io/blog/2019/11/05/parse-don-t-va...
4.
▲
by
Zinggi
6y ago
You might be interested in lamdera. It abstracts away database access, data transport and data encoding between client end server. Here is a talk about it: https://www.youtube.com/watch?v=nSrucNcwlA8 If you're int
5.
▲
by
Zinggi
6y ago
Thank you! Well put.
6.
▲
by
Zinggi
8y ago
> the Android app requires no device permissions That's not true, it just uses the new way to ask for permissions. E.g. when you want to scan a QR code it requires the camera permission. But it only asks at that moment, not upfront
7.
▲
by
Zinggi
8y ago
Yep, from a user perspective it definitely looks like 2FA. In terms of technology it's of course completely different.
8.
▲
by
Zinggi
8y ago
Ah ok, got it. If you are already using KeePass than there is no reason to use NoKey, KeePass is great! > Not everyone has a million devices. I don't think that's fair. With 3 devices you're perfectly ok. Or even with only
9.
▲
by
Zinggi
8y ago
But wouldn't you agree that your brain + NoKey instead of a piece of paper as a backup would be more secure? And more convenient, as you don't have to type your passwords anymore. I don't wanna push you, just wanna give you s
10.
▲
by
Zinggi
8y ago
Exactly. Or even 3 if you make use of security level 3. The only exception is at the start when there are no passwords stored yet.
11.
▲
by
Zinggi
8y ago
When pairing a new device (or in this case a new browser), that device doesn't automatically get any keys! When adding a new device, to complete the setup you also have to be able to unlock a password group, for which you need another
12.
▲
by
Zinggi
8y ago
Yes, but it's a very bad idea. If you'd do this, you could unlock your passwords with a single device by confirming on Firefox or vice-versa on Chrome. This of course also means that if someone steals this device, they can unlock
13.
▲
by
Zinggi
8y ago
Oh, than I misunderstood, sorry. You're absolutely correct.
14.
▲
by
Zinggi
8y ago
Thanks. I was always wondering why others don't do this more often. I find it much easier to remember and type in a few words compared to a long number.
15.
▲
by
Zinggi
8y ago
> Doesn't this increase your attack surface greatly though? That's true. I suppose it's a trade off between protection against lost vs. smaller attack surface. > Since there's no master key, one has to only comprom
16.
▲
by
Zinggi
8y ago
You lose access to your passwords, that's the consequence of that approach. That's why it's a very good idea to pair as many devices as you can, e.g. an old phone, your work PC, etc. This way you're pretty save from any
17.
▲
by
Zinggi
8y ago
Hi all! This is my first time posting something to HN, so please be kind. I wanted to show what I’ve been working on for the last 6 months: NoKey, a password manager without a master password. Instead, you can unlock your passwords by confi
18.
▲
Show HN: NoKey, a Distributed Password Manager Without a Master Password
(github.com)
37 points
by
Zinggi
8y ago
|
27 comments