Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dvzk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
31.
▲
by
dvzk
3y ago
That is not Apple’s stated design at all. If you read Apple’s passkeys security document, it claims that the private keys are synchronized with iCloud and are recoverable following the loss of all devices. Non-exportable passkeys using the
32.
▲
by
dvzk
3y ago
> When you point this out to advocates, you'll get an entirely different argument This is a very common argumentation tactic, and it usually exposes that the first argument(s) are just a front for our actual axiomatic belief (whic
33.
▲
by
dvzk
3y ago
sudoedit and visudo are mandatory on a host machine given the tendency for sudoers parse failures. Defaults env_keep = "" ? Oops, I guess sudo no longer works.
34.
▲
by
dvzk
3y ago
That would be a great improvement for technical users. But also consider that the target for Authy is the average mobile user. I’m not unconvinced that the typical backup password looks like S3cr3tP@s$w0rd, which no amount of key stretchin
35.
▲
by
dvzk
3y ago
Yes. Depending on the threat model, it may or may not be better. Many organizations won't be allowing remote passkey sign-in for employees. For people at home, the elimination of passwords will reduce rates of phishing and credential-s
36.
▲
by
dvzk
3y ago
Sorry, that's only speculation, since I haven't had more time to analyze the database. If you read Apple's passkey security document, it claims that passkeys are distributed identically across devices. And that you can recove
37.
▲
by
dvzk
3y ago
https://support.apple.com/guide/security/escrow-security-for... https://support.apple.com/guide/security/secure-icloud-keych... https://support.apple.com/en-us/HT213
38.
▲
by
dvzk
3y ago
Passkey objects on macOS are encrypted at rest within the iCloud Keychain sqlite database in Library/Keychains/*/. It shouldn't be too hard to adapt the keychain extraction tools that exist. I don't know why you wou
39.
▲
by
dvzk
3y ago
Like 99% of people in this thread, you are conflating distributed non-device-bound credentials (passkeys) with hardware security keys.
40.
▲
by
dvzk
3y ago
You authenticate to a cloud escrow provider using any of your account's other associated devices. If you have none, because Yellowstone erupted while you were away, and someone also yoinked your phone in the ensuing chaos, then you inp
41.
▲
by
dvzk
3y ago
Cryptocurrencies are a spectacularly bad counterexample. If password-derived private keys had ever become commonplace, the ensuing theft would have absolutely dwarfed the losses from lost wallet keys. I'm not sure if there's even
42.
▲
by
dvzk
3y ago
I suspect the vast majority of Authy backups use passwords trivially susceptible to brute-force attacks despite only 1000 (!!!) iterations of PBKDF2. If Authy wanted to do things right, it would generate local encryption keys instead of ask
43.
▲
by
dvzk
3y ago
How does this unknown Delaware company support 12 employees working on a free mobile app? There's zero verifiable information available about its history, and the founder seems to be heavily involved in cryptocurrency.
44.
▲
by
dvzk
3y ago
For one thing, it's common for enthusiasts to replace stock components. A serial number stamped onto the frame isn't useful all the time, especially if the frame itself is secondhand. If someone takes your >$2,000 carbon wheels
45.
▲
by
dvzk
3y ago
Huh, thanks, I wrongly assumed that Passkeys inherited WebAuthn’s attestations for hardware-backed keys. I guess organizations will need to ban Passkeys internally.
46.
▲
by
dvzk
3y ago
Yes. When TOTP debuted, it was aimed at and designed by security engineers. Keeping secrets on-device was and is correct for serious uses. Google Authenticator is a victim of its own popularity. Fortunately, the field moved on, and we now h
47.
▲
by
dvzk
3y ago
Authy used to share its SDK TOTP codes with attackers via account recovery, and no backup password was needed. SMS hijacking led to authenticator takeover on Authy SDK-using sites like Coinbase. Which is partly why Authenticator and co. wer
48.
▲
by
dvzk
3y ago
Things open source developers say because they don’t have experience with binary analysis. Not to say that Apple’s reviewers are going to be looking at IDA or Ghidra dumps, but they can see added capabilities, frameworks, symbols, or assemb
49.
▲
by
dvzk
3y ago
That is Apple's statement, but I'd be surprised if 50% of iOS/macOS users noticed any significant change with lockdown mode on. Unless you are using shared albums or answering unknown facetime calls, there isn't much imp
50.
▲
by
dvzk
3y ago
When I first looked into this, free Apple developer accounts also could only use limited app entitlements: so no network extensions, VPN profiles, Apple push notifications, or other capabilities. NetworkExtension is basically the only reaso
51.
▲
by
dvzk
3y ago
I admit I’m completely out of my depth when it comes to this field — I don’t even typically care about AI — but Eliezer’s response looks really bad to anyone in research. Asking for a citable and thorough written argument is as basic a requ
52.
▲
by
dvzk
3y ago
I assume my private messages are always public record, so I don’t get this mindset. My first thought when messaging someone is, “What if they screenshot or leak this conversation?” or “What if their message history is subpoenaed?” It never
53.
▲
by
dvzk
3y ago
macOS already does all of that for all programs. I think the main problem here is that macOS only protects certain directories and not others. Programs can request access to Documents or Downloads, or they can request full-disk access (e.g.
54.
▲
by
dvzk
3y ago
Custom keychains are also available if you worry about malware dumping unlocked keychain data via kernel privilege escalation (to bypass ACLs). For critical items that you decrypt once a year, it doesn't make much sense to use the resi
55.
▲
by
dvzk
3y ago
GitLab initially copied GitHub’s UI, virtually identically, and the CEO advertised GitLab in every thread that involved GH for over a year. It didn’t seem that many people on HN cared, because GitLab was “open source” and ethics didn’t appl
56.
▲
by
dvzk
3y ago
> So, Mono is alive and well inside every version of .NET since 5. The official mono project is no longer under active development since the acquisition of Xamarin and the reassignment of core Mono team members to .NET Core. Microsoft’s
57.
▲
by
dvzk
3y ago
> .NET Core ( dotnet at the CLI ) has replaced .NET Framework and ( by implication ) has replaced Mono as well. That is what I think the post above is trying to say. dotnet build (from the modern .NET CLI) can compile .NET SDK projects t
58.
▲
by
dvzk
4y ago
Sorry! I shouldn't have assumed that it was a retort. Mono's latest supported .NET framework (v4.8) is four years old, or even older if you include the general movement to .NET Core, and it only supports C# versions <= 9.0 (via
59.
▲
by
dvzk
4y ago
Yes, and this is tantamount to suggesting that Python developers should be satisfied with Python 2.0 (arguably 1.0 if you do F# development). Mono is effectively dead and abandoned, and it only exists now for historical reasons.
60.
▲
by
dvzk
4y ago
If anyone thinks this, I sincerely hope you re-evaluate. The difference between doing sports and exercise and doing none is often being disabled or in pain in your 30s and 40s, versus being in near peak physical shape. I meet too many peopl
More ›