Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mastahyeti
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
SSH Certificate Authentication for GitHub Enterprise Cloud
(github.blog)
4 points
by
mastahyeti
7y ago
|
0 comments
2.
▲
by
mastahyeti
9y ago
Which device are you using? With U2F, the browser doesn't send the name of the site to the authenticator.
3.
▲
by
mastahyeti
9y ago
From my testing of several hardware U2F implementations, the test-of-user-presence (touching the button) unlocks the device for an amount of time. During this time multiple authentication/registration will succeed without further user
4.
▲
by
mastahyeti
9y ago
I've only tested on Sierra, so I'm not terribly surprised that this doesn't work. Would you mind opening an issue so I can help debug? https://github.com/github/SoftU2F/issues/new
5.
▲
by
mastahyeti
9y ago
It is :-)
6.
▲
by
mastahyeti
9y ago
You still have to configure TOTP (SMS or App) 2FA before you can add a U2F device. That might change in the future.
7.
▲
by
mastahyeti
9y ago
My understanding is that the FF softtoken was intended to be temporary while they worked on their HID support. That might not be the case any longer though.
8.
▲
by
mastahyeti
9y ago
I think the greatest practical threat to TOTP is phishing. U2F, regardless of where keys are stored, binds a keypair to an origin. Only authentication requests from `github.com` can use the `github.com` keys. For my money, any U2F implement
9.
▲
Introducing Soft U2F, a Software U2F Authenticator for macOS
(github.com)
6 points
by
mastahyeti
9y ago
|
0 comments
10.
▲
HTTPS for GitHub Pages
(github.com)
248 points
by
mastahyeti
10y ago
|
100 comments
11.
▲
by
mastahyeti
10y ago
There is a known bug where leading whitespace can cause the key to not be parsed. Also, check that you're only trying to upload a single key, and not your entire keyring.
12.
▲
by
mastahyeti
10y ago
It shouldn't be necessary to push a new signed commit for old ones to start showing the "verified" badge. We do cache some of our templates though, so it may take a while for some pages to be updated.
13.
▲
by
mastahyeti
10y ago
GitHub Desktop doesn't support commit/tag signing at this point. Sorry.
14.
▲
LIKE injection
(githubengineering.com)
10 points
by
mastahyeti
11y ago
|
4 comments
15.
▲
GitHub supports Universal 2nd Factor authentication
(github.com)
128 points
by
mastahyeti
11y ago
|
79 comments
16.
▲
by
mastahyeti
11y ago
It's only included for browsers that support it. That's Chrome>45 and Firefox>43.
17.
▲
by
mastahyeti
11y ago
This isn't a concern with our implementation because a hash of the asset bundle is also included in the URL. This is a pretty common cache-busting technique for static assets and lets you send more aggressive cache directives to the br
18.
▲
by
mastahyeti
11y ago
Thanks. I updated the post and opened a PR to fix the README on sprockets-rails. https://github.com/rails/sprockets-rails/pull/273
19.
▲
Subresource Integrity
(githubengineering.com)
184 points
by
mastahyeti
11y ago
|
76 comments
20.
▲
View Issue/Pull Request Buttons for Gmail
(github.com)
44 points
by
mastahyeti
12y ago
|
4 comments
21.
▲
GitHub Security Bug Bounty
(github.com)
118 points
by
mastahyeti
13y ago
|
37 comments
22.
▲
by
mastahyeti
13y ago
We just added support for India. Try again.
23.
▲
by
mastahyeti
13y ago
There is a setting for a fallback number on https://github.com/settings/two_factor_authentication/config...
24.
▲
by
mastahyeti
13y ago
TOTP is standardized. http://tools.ietf.org/html/rfc6238
25.
▲
by
mastahyeti
13y ago
This is a separate issue. We just added the Private Token feature on the /settings/applications page. This is essentially a password, so we wanted to make sure that it required password confirmation. This will be behind sudo mode later toda
26.
▲
by
mastahyeti
13y ago
Adding a new email address is now behind "Sudo Mode"...
27.
▲
by
mastahyeti
13y ago
We use Rails CookieStore. The cookie does change when you enter sudo mode, so a session would have to be compromised while you are in sudo mode.
28.
▲
by
mastahyeti
13y ago
Just shipped it a couple minutes ago. Previously, we only had password confirmations for adding Public Keys.
29.
▲
D3 Visualization of Browser Feature Support
(btoe.ws)
1 points
by
mastahyeti
13y ago
|
0 comments
30.
▲
OS Safari, Content-Type, and XSS
(btoe.ws)
2 points
by
mastahyeti
13y ago
|
0 comments
More ›