Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
conorgil145
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
31.
▲
by
conorgil145
9y ago
Wouldn't it make even more sense to use the Web Crypto API instead of any JS crypto library loaded from the server?
32.
▲
by
conorgil145
9y ago
I have had a very similar idea for a tracking app for a looong time. This is by far the closest I've seen to my idea. I would definitely use something like this. However, I would primarily want to use a mobile app for daily tracking. I
33.
▲
by
conorgil145
9y ago
Authy desktop is definitely a step in the right direction in terms of UX on desktop. However, I dislike that I still need to manually search for the correct 2FA entry and copy/paste the code into the browser. I mentioned in another com
34.
▲
by
conorgil145
9y ago
Great conversation! > Are you sure your extension cannot identify a QR code, identify that it is a valid seed for 2FA, and capture that information before the page finishes rendering, before the malware would have a chance to 'see&#
35.
▲
by
conorgil145
9y ago
I agree that U2F is generally a more secure 2FA solution than soft tokens on a phone. If you use U2F (hardware), then what are you storing in your password manager (software)? Maybe, the 2FA secrets for sites that don't support U2F yet
36.
▲
by
conorgil145
9y ago
Wow, that is horrible. Given that, I would argue that, for all intents and purposes, they do not support TOTP then. An average user has zero chance of doing all of that correctly. Bummer the don't support it as a first class citizen in
37.
▲
by
conorgil145
9y ago
Interesting, I have not encountered that while using Authy on my phone (Android, Galaxy S5). I think that Authy has the best UX overall, especially when looking up a 2FA code, but generally because: - The overall design (color scheme, shape
38.
▲
by
conorgil145
9y ago
FYI, Amazon (retail) does support TOTP. Here is a direct link to the 2FA settings so you don't have to crawl through the account settings page looking for it: https://www.amazon.com/a/settings/approval .
39.
▲
by
conorgil145
9y ago
Sorry this is so long, but I felt it important to be relatively thorough. It sounds like there are 2 distinct attack vectors you are considering: malware installed on a trusted device and a local attacker gaining access to a trusted device.
40.
▲
by
conorgil145
9y ago
I have read about this a little from the user POV, but I have not yet used Authy to build a service which provides 2FA, so I do not understand the details enough to really talk intelligently about the differences. I do recall reading that A
41.
▲
by
conorgil145
9y ago
1passowrd has a good blog post explaining why using 1password for TOTP is not 2FA [1]. If someone gets into your password vault, then they have both authentication factors: your passwords (what you know) and your 2FA secrets (theoretically,
42.
▲
by
conorgil145
9y ago
I have used FreeOTP, Google Authenticator, Authy, and LastPass Authenticator. Of those options, I use Authy because it is also free and has hands down the best UX. However, I think that current solutions for soft token two factor authentica
43.
▲
by
conorgil145
9y ago
Some of the same exact questions that I had. It seems like an odd combination of features for one company to tackle. Building a secure password manager, for example, is non trivial and requires some serious security/crypto knowledge. D
44.
▲
by
conorgil145
9y ago
I lived in Denver for the past 2 years and agree with this assessment as well. The light rail has expanded lines in recent years to the airport and I have read that the plan is for that expansion to continue to eventually link Denver and Bo
45.
▲
by
conorgil145
9y ago
How would you possibly know which fingerprints to trust? Also, do you honestly think there is any hope for the average user to understand what that means and know what to trust and what not to trust? IMO, that is a massive step backwards in
46.
▲
by
conorgil145
9y ago
An email is like a postcard and every server which traffics it can read the full contents. The CC details are static and will not change once you receive them, so it is in effect sending the CC details to all MX servers that traffic the ema
47.
▲
by
conorgil145
9y ago
I just finished reading the book "Vagabonding: An Uncommon Guide to the Art of Long-Term World Travel", which basically promotes this exact train of thought. You may enjoy reading it if you are not already familiar.
48.
▲
by
conorgil145
9y ago
Sounds very cool and useful, but I think the site needs to do a better job of explaining exactly how it works. Do you need access to my Uber/Lyft credentials or app? Does this integrate with Uber/Lyft apps somehow, or does it find
49.
▲
Ask HN: Two factor authentication survey
3 points
by
conorgil145
10y ago
|
0 comments
50.
▲
by
conorgil145
10y ago
Thanks for the background on Duo. I'll definitely reach out once we have a beta to demo. We'd love to get some feedback from folks outside our immediate team!
51.
▲
by
conorgil145
10y ago
Ah! Duo is definitely one of the incumbents in the space that we looked at during our competitive analysis. As far as I understand it, your push based 2FA solution only works for sites which use Duo as the 2FA provider. Is that correct? I a
52.
▲
by
conorgil145
10y ago
Yup, you nailed it. That is exactly the plan. Any thoughts on that approach? Do you think you might be willing to update your current 2FA workflow to the one described above?
53.
▲
by
conorgil145
10y ago
As johnmaguire2013 guessed, we will have a browser extension which will request a 2FA code from the mobile app. The mobile app will receive a push notification and ask the user whether they would like to allow or deny the request for a seco
54.
▲
by
conorgil145
10y ago
Project: I am working on improving the 2 factor authentication (2FA) user experience for end users. Problem: 2FA is an east way to drastically improve one's security posture with many sites (e.g. AWS, Github, Google, Stripe, etc), but
55.
▲
by
conorgil145
10y ago
I would have found this incredibly useful when I was doing research to understand stock options that I have had in the past. Sounds like a really cool project. Keep at it! Also, to get a more accurate estimation, you will have to know the a
56.
▲
by
conorgil145
10y ago
I worked for an encrypted email company for ~4 years and I'm pretty familiar with the space. How do you solve the user experience problem associated with PGP in terms of sharing keys? You cannot send an encrypted email to someone you h
57.
▲
by
conorgil145
10y ago
Why did you decide not to use Vault? Did it fail to meet a requirement? Over kill? Learning curve? Other?
58.
▲
by
conorgil145
10y ago
I would be incredibly interested in data for all tech salaries.
59.
▲
by
conorgil145
10y ago
How much time do you spend to generate the $1500? Is this your full time job, or do you do it on the side? Do you have any plans to scale up somehow, or are you content with what you have going right now?
60.
▲
by
conorgil145
10y ago
I clicked the link and it was definitely not obvious how much it cost. I even clicked to add it to Slack and it didn't mention cost or anything. Pretty reasonable question.
More ›