Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
anderspitman
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
61.
▲
The good, the bad and the ugly of Apple Passkeys (2022)
(slashid.dev)
2 points
by
anderspitman
3y ago
|
0 comments
62.
▲
by
anderspitman
3y ago
The web may never be better than it was about 5 years ago, and that makes me very sad
63.
▲
by
anderspitman
3y ago
Ok this is awesome
64.
▲
by
anderspitman
3y ago
I think it mostly just evolved that way. OAuth started on the web and if you're using a browser anyway you might as well take advantage of HTML/JS rendering for the UI and cookies for secure storage.
65.
▲
by
anderspitman
3y ago
I would be very interested to see an implementation that doesn't. And I'm not being sarcastic. Even the device flow has you open a browser on another device.
66.
▲
by
anderspitman
3y ago
I do think it's pretty amazing that a basic modern authorization system essential has a hard dependency on a 20+ million lines of code web browser, even for native apps. And mostly just because we need a central location to store auth
67.
▲
by
anderspitman
3y ago
> People get bored fairly quickly, but the rare person never gets bored ever, and you have to be very careful of that person because they might be your best user or they might be a terrible person. And if you give them too much control t
68.
▲
WebAuthn vs. Passkeys
(blog.passwordless.id)
3 points
by
anderspitman
3y ago
|
1 comments
69.
▲
by
anderspitman
3y ago
It's not other than OAuth2 is the de facto standard for doing this sort of thing, for better or for worse. You could use a different protocol but developers are less likely to integrate with it.
70.
▲
by
anderspitman
3y ago
The most interesting thing to me about this is that apparently they offer an HTTP API for their VPN service. But I haven't been able to find any documentation for it. Are there any VPN providers that offer an OAuth2 API that would let
71.
▲
by
anderspitman
3y ago
Biography of the Pixel looks really good as well (by the other founder, Alvy Ray Smith). Been on my list for a while
72.
▲
by
anderspitman
3y ago
That picture was taken at a nostalgic symposium a few months ago. I'm very fortunate to live nearby and was able to attend. It was awesome. Got to meet a couple of my heroes. They livestreamed it as well: https://www.youtube
73.
▲
by
anderspitman
3y ago
I only looked at the main page and FAQ and only saw references to Linux. I'll have to dig into this later. Very curious how it works on Windows.
74.
▲
by
anderspitman
3y ago
What does cross platform mean in this context? It appears to be Linux only to me.
75.
▲
by
anderspitman
3y ago
That's awesome
76.
▲
by
anderspitman
3y ago
My main concern with passkeys is I'm not aware of a way to pre-authorize someone who doesn't yet have an account. For example, with email I can just grant X access to anyone who can prove they have access to Y email address. But p
77.
▲
by
anderspitman
3y ago
I think the first use cases of WebAuthn were targeted at MFA, but passkeys are definitely being advertised as replacing passwords as the primary/only factor (with the caveat that you'll also be expected to perform some sort of pin
78.
▲
by
anderspitman
3y ago
Do 1password/fastmail have functionality built in for this or do you just manually generate your emails based off a wildcard?
79.
▲
by
anderspitman
3y ago
Not sure I'm understanding you correctly. Can you share an example of what you mean?
80.
▲
by
anderspitman
3y ago
This is, in my opinion, the biggest gap in the market. Selfhosting shouldn't be any more difficult or less secure than running an app on your phone.
81.
▲
by
anderspitman
3y ago
I have to agree, the scrolljacking on this site is beautiful and horrific.
82.
▲
by
anderspitman
3y ago
Can you share links to the major ones (I'm aware of a couple like yunohost and cloudron)? What are the most important UX issues in your opinion? Disclaimer: I'm working on a docker launcher for selfhosting and want to solve some o
83.
▲
by
anderspitman
3y ago
Marth Lab | University of Utah | US | Full time | Frontend/full stack JavaScript The Marth Laboratory at the University of Utah is looking for a front-end web developer to join our burgeoning team to design, develop, and implement soft
84.
▲
by
anderspitman
3y ago
Doesn't currently meet all the OPs requirements, but I've been working on https://gemdrive.io/
85.
▲
Ask HN: Why does OAuth2 use tokens instead of key pairs?
2 points
by
anderspitman
3y ago
|
0 comments
86.
▲
Ask HN: Why does Facebook nearly but not quite implement OpenID Connect?
2 points
by
anderspitman
3y ago
|
0 comments
87.
▲
by
anderspitman
3y ago
Docker Desktop provides some compelling options for lowering the barrier of entry for selfhosting. Today you can take a Windows laptop and run just about any Linux service, with pretty fast networking and host disk access. No CLI experience
88.
▲
Crypto 101 – Introductory course on cryptography
(crypto101.io)
4 points
by
anderspitman
3y ago
|
0 comments
89.
▲
by
anderspitman
3y ago
Cloudflare Tunnel is a great service, but if you're looking for selfhosted alternatives I maintain a list here: https://github.com/anderspitman/awesome-tunneling
90.
▲
Official OpenId Connect Provider Tester
(openid.net)
2 points
by
anderspitman
3y ago
|
0 comments
More ›