Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
lxgr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
lxgr
8d ago
Yes, I'd absolutely not use Apple or Google for my passkeys, even though they now at least seem to support exporting them to other platforms.
2.
▲
by
lxgr
8d ago
Then don't, there are several open source synchronizing passkey implementations!
3.
▲
by
lxgr
8d ago
Intellectual property is a legal fiction, not an empirical fact about the universe. It's as real as societies want it to be, and that view can change over time.
4.
▲
by
lxgr
8d ago
Why would you choose that over a synchronizing passkey manager? A third party OAuth provider puts you at the mercy of the service provider, the other can work fully on your client side even if the app provider were to disappear tomorrow. Th
5.
▲
by
lxgr
8d ago
Enrolling two devices stored in different locations for every sign up is extremely annoying. I suspect that most people that ostensibly do this actually only enroll one for non-critical accounts and then depend on some fallback mechanism.
6.
▲
by
lxgr
9d ago
A lot of (at least) New York bouncers seem to have dedicated barcode scanners or apps on their phones these days and scan every single license. I'm really not a fan.
7.
▲
by
lxgr
9d ago
This thread is about printing QR codes on physical cash. GGP explicitly said: > That's really neat! Seems potentially adaptable to paper currency--a verifiable QR code digital signature of the bill's serial number creates a cry
8.
▲
by
lxgr
9d ago
I have to say that I really don't love the idea of having my ID scanned (and definitely not stored, wink wink) every time I buy a drink etc. Having both paths available, depending on the "severity" and expected anonymity of t
9.
▲
by
lxgr
9d ago
The original e-cash paper is from 1983. Governments absolutely know this is possible. It's just much "too private" to get any political traction. At the very least, I suspect an acceptable modern alternative would either have
10.
▲
by
lxgr
9d ago
Yes, and then you have a signed piece of data that others can verify. How does that help you with preventing duplication of signatures? E-cash depends on the secrecy of the signed data , and immediate redemption with the issuer once it
11.
▲
by
lxgr
9d ago
Yes, but they're also not regular old merchant ships by any means. All existing ones see to be operated by a Russian government-owned corporation.
12.
▲
by
lxgr
9d ago
If you think about this for a minute, maybe you'll be able to form a theory for why this is already very common for military vessels, but not so much for unarmed civilian ones...
13.
▲
by
lxgr
9d ago
Blind signatures don’t work like that. Once you unblind them, they are very traceable. Chaumian e-cash can only be spent once for that reason.
14.
▲
by
lxgr
9d ago
It’s a bunch of static signed data, which is hard to modify but trivial to copy. Not exactly what you’d want for bank notes. NFC and a challenge-response protocol could work, though, like e.g. the one used in biometric passports.
15.
▲
by
lxgr
9d ago
Biometric passports, including US ones, have supported the same protocol for decades at this point.
16.
▲
by
lxgr
9d ago
The Austrian ID card does that. It’s a really blurry black-and-white photo only, but it’s still recognizable and I find it quite impressive that any type of photo (in addition to its public key signature) can fit into a QR code at all.
17.
▲
by
lxgr
9d ago
Revocation checking seems like a big gap, yeah. I’m not aware of any public revocation lists (but I’m also not super familiar with the industry), so I can only assume (hope?) that there are some shadowy but highly accurate databases that KY
18.
▲
by
lxgr
10d ago
I wonder why they're not doing something like DAA [1], which achieves the same privacy properties without a centralized server. [1] https://en.wikipedia.org/wiki/Direct_Anonymous_Attestation
19.
▲
by
lxgr
10d ago
Airdrop has been supported on many Android devices even outside the EU for a while now: https://www.android.com/quick-share/with-iphone/ Or you could just email/WhatsApp/... it.
20.
▲
by
lxgr
10d ago
They just have you tap your identity document against your phone. Works pretty well in my experience. The phone is just a relay to a remote server here, as newer ICAO machine readable travel documents intentionally don't support signat
21.
▲
by
lxgr
10d ago
ICAO doc 9303 validation is about 10 lines in Python (on top of importing the right packages) last time I did it around 2012. I doubt it has become harder since then.
22.
▲
by
lxgr
10d ago
No, you just didn't understand GPs point, i.e. that an image provenance/authentication system (such as Apple Reference Image) can eventually become a load-bearing and by extension anticompetitive component in a larger authenticati
23.
▲
by
lxgr
10d ago
> Insurance companies can monitor the light reflections from the flash that they control or monitor the accelerometer and compare the accelerometer values with the video that they receive. All of this data can be spoofed if it's not
24.
▲
by
lxgr
10d ago
ID document verification via NFC can't by itself replace also biometrically verifying the person purporting to be the one that the document belongs to. Without it, anyone with a stolen document can pass it. (I don't think there&#x
25.
▲
by
lxgr
11d ago
For rabbit holes, how do you get Gemini to do any research before answering? I've very recently had it hallucinate on me like it's 2023, and that was on Pro/Thinking, as far as I remember.
26.
▲
by
lxgr
11d ago
Exactly, and in some ways, DNS is even more centralized. At least there’s a choice of CAs independent of TLDs.
27.
▲
by
lxgr
11d ago
All that was true until fairly recently. Today, you can get certificates for free and there’s more transparency than ever thanks to CT. What would you suggest as an alternative? TOFU? I could see that for local applications (e.g. making mDN
28.
▲
by
lxgr
12d ago
That's great for people that don't have any online-capable payment method, but I'd consider it a huge step backwards for those that do and are comfortable using it.
29.
▲
by
lxgr
12d ago
I guess now would be a great time for browsers/OSes to ship a "trust this CA, but only for this TLD/list of domains" feature.
30.
▲
by
lxgr
12d ago
> you're going to be hit by ATM (read: middleman) fees every single time. This is highly country specific. In many countries, (at least domestic) ATM withdrawals are still free. > you massively increase your risk of getting hit b
More ›