Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jwally
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
91.
▲
by
jwally
2y ago
I find it extra ironic that experian is now pimping a service to aggregate and cancel your subscriptions - but if I want to freeze my children's credit reports I have to have a notarized original of their birth certificate and bring it
92.
▲
by
jwally
2y ago
Can't recommend privacy.com enough for literally this use case. If I have to spend more than five minutes trying to figure out how to cancel - I'm just turning off my card...
93.
▲
by
jwally
2y ago
musing: It feels like Google has a reputation of creating a bunch of products and killing them off within 3-5 years. It seems like this helps with initial adoption of the product (backed by Google!) but erodes trust in the brand every time
94.
▲
by
jwally
2y ago
> saying no to such humbling offers is tough Minor pet peeve: misuse of the word "humbling". A $23B offer is not humbling (on my planet at least). Humbling would be turning this offer down and then failing to get enough interes
95.
▲
by
jwally
2y ago
Its not so much replay attacks I'm trying to solve for here ( although putting the instantiating user's IP address in the JWT seems like it would do a lot to thwart that ) I think the main thing here is preventing anyone from usin
96.
▲
by
jwally
2y ago
tbh, I haven't worked with JWT's a _ton_, so apologies if there's an _obvious_ better way to do something, lol. I think you're right. Just sign the JWT that's going over as a header (as its a string), and add a sign
97.
▲
by
jwally
2y ago
TBH, I'm not an expert here. What you're describing looks like webauthn which is used to verify the identity of a user by creating a private key on their HSM/TPM when the user signs up, and usually requires biometrics or a PI
98.
▲
by
jwally
2y ago
I'll have to check that out, thanks! If it can store live objects - its perfect. IDB is neat because it can store a PrivateKey Object whose `extractable` attribute has been set to false. So when you try to see the crypto data, you cann
99.
▲
by
jwally
2y ago
> The recommendation for IP address in the JWT is good, but I don't understand your last recommendation of 1) sending the JWT, 2) additionally sending the base64 JWT in a header 3) sending the signature in the header. The crypto.sub
100.
▲
by
jwally
2y ago
OH FFS!!!! Serves me right having ChatGPT add commentary and me not double checking. This is what it should be: const keyPair = await crypto.subtle.generateKey( { name: "ECDSA", namedCurve: "P-256"
101.
▲
by
jwally
2y ago
Its an extremely solid idea, fast, and able to be rolled out without any modifications to the browser. I'd love to see IDPs adopt the concept. Coupled with passkeys; it seems like it would be extremely difficult to break into someone e
102.
▲
Show HN: Storing Private Keys in the Browser Securely
(github.com)
10 points
by
jwally
2y ago
|
14 comments
103.
▲
by
jwally
2y ago
Also, juvenile shenanigans with links to goatse et al being placed on the local plumber's van feels like an easy win for 17 yo boys everywhere.
104.
▲
by
jwally
2y ago
I don't know how well it would scale, but from an ease-of-use perspective it feels like Quishing (eyes roll - QR Phishing) is a plague waiting to explode. "Just scan this and donate to the red cross!". My kid's afterscho
105.
▲
by
jwally
2y ago
I've used firefox with adblock/ublock since I first learned about it 20-ish years ago. I have a vpn on my phone primarily because I can do dns adblocking. I gave up most news and social media around COVID times, and haven't w
106.
▲
Show HN: Secure Session Cookie Scheme Using Existing Tech
3 points
by
jwally
3y ago
|
0 comments
107.
▲
by
jwally
3y ago
Using the TPM for this feels _way_ over-engineered for what its trying to accomplish. Also, just tinkering with webauthn; it feels slow on the client side - which is fine if you're authenticating, but murder if you're signing some
108.
▲
Chrome to Prevent Session Hijacking via TPM
(pcmag.com)
2 points
by
jwally
3y ago
|
1 comments
109.
▲
by
jwally
3y ago
That's an extremely good point I hadn't thought of. If a customer fails this, their internal risk score goes up, which should increase the scrutiny/friction of future interactions between them and the bank.
110.
▲
by
jwally
3y ago
This is what I had in mind. Bank.com hires pen-testers to trick people to go to Bank.evil, spill their ID/Password/OTP.
111.
▲
by
jwally
3y ago
The idea is to preemptively 'harden' your customers against real phishing attacks by exposing them to controlled, simulated ones. By increasing their wariness and increasing their suspicion of fraudulent communications, you'r
112.
▲
by
jwally
3y ago
That's a really good point, and its a tough needle to thread. So my train-of-thought goes something like: If my customers are going to get hacked, its better they get hacked by my good-guys than actual criminals. If they're more s
113.
▲
Ask HN: Should Banks Phish Their Own Customers
21 points
by
jwally
3y ago
|
63 comments
114.
▲
by
jwally
3y ago
With SMS otp, it's possible to associate 2 phone numbers (or more) to a single account. That way if my wife and I can use her Amazon account. Can the same paradigm be grafted to pass-keys/webauthn? Maybe a useful flow could be You
115.
▲
by
jwally
3y ago
100% this. I can't imagine anyone is going to recommend consuming more micro plastics; but as far as how to improve your overall wellbeing this is probably 15 or 16 on the list. Most people would be better off focusing on getting contr
116.
▲
by
jwally
3y ago
The publication itself feels inflammatory and click baity. Innuendo and "just asking questions" Some of the other headlines: >Radical Plan to Stop 'Doomsday Glacier' Melting to Cost $50 Billion >Breakthrough: Model
117.
▲
by
jwally
3y ago
Dumb question, but with respect to fingerprinting - how is this any worse than cookies, service workers, or localstorage?
118.
▲
by
jwally
3y ago
I got an sms from "Nikki Haley" the other week asking me to join some political rally. This has SUCH potential for abuse. A) spreading misinformation. Not hard to confuse people that their polling location is closed but the inconv
119.
▲
by
jwally
3y ago
Maybe insurance companies can give discounts for installing their app that "locks" your phone while in motion. If you're the passenger and want to unlock the phone...take a selfie? More psychology than tech here. This wouldn&
120.
▲
by
jwally
3y ago
>Criminals then send a Google Drive link to the staff saying that it contains an image of the passport. Instead the link downloads malware on to staff computers and automatically searches the hotel computers for Booking.com access. How d
More ›