Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
_wbpr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
_wbpr
10d ago
This line from quoted from the article? > security against man-in-the-middle attacks but face the higher probability scenario of losing access to your accounts The author says "security" against man-in-the-middle attacks. Are t
2.
▲
by
_wbpr
10d ago
Yes, there are several ways. You can use Google password manager on your MacBook. I believe 1Password and Bitwarden support this too. You can also use the Android phone itself as a passkey device with the QR code flow. The UX is obviously a
3.
▲
by
_wbpr
10d ago
> gaslighting That is some serious semantic bleaching! I’m not disputing the fact that “secure” has different meanings in different contexts. My point is that when we talk about the “security” of authentication methods, we almost always
4.
▲
by
_wbpr
10d ago
Reliability != security If a car breaks down every 50 miles we would call it unreliable. If a car’s doors don’t lock we would call it insecure.
5.
▲
by
_wbpr
10d ago
> Passkeys are grotesquely insecure. Lockout is a real risk, but there is nothing insecure about passkeys. Private keys stored on the secure enclave + biometrics or passcode before any signature is produced + origin binding mogs a static
6.
▲
by
_wbpr
10d ago
> A combination of randomly generated passwords stored inside a third-party password manager, paired with an independent TOTP app, gives control to the user without giving up the flexibility of plain text. No grandma, don’t use the unphi