Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
philnash
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
I built a new app and I don't know how I feel about it
(philna.sh)
3 points
by
philnash
4mo ago
|
0 comments
2.
▲
JavaScript date + 1 month = 9 months previous
(philna.sh)
1 points
by
philnash
9mo ago
|
1 comments
3.
▲
by
philnash
9mo ago
Ah, time zones. This is a real thing that happened to me so I wanted to share so that no one else ever finds out their date calculations are off by 9 months.
4.
▲
Top Mistakes I Made While Building AI Agents
(datastax.com)
2 points
by
philnash
2y ago
|
0 comments
5.
▲
Stop Nesting Ternaries in JavaScript
(sonarsource.com)
2 points
by
philnash
3y ago
|
0 comments
6.
▲
by
philnash
3y ago
It’s a calculator to help you hit your financial goals by breaking down the formula showing you: - how many sales you need per day - how many sales you need per month - monthly traffic
7.
▲
A comprehensive guide to the dangers of Regular Expressions in JavaScript
(sonarsource.com)
1 points
by
philnash
3y ago
|
0 comments
8.
▲
Node.js now includes built-in support for .env files
(philna.sh)
3 points
by
philnash
3y ago
|
0 comments
9.
▲
ES2023 introduces new array copying methods to JavaScript
(sonarsource.com)
1 points
by
philnash
3y ago
|
0 comments
10.
▲
The YAML document from hell – JavaScript edition
(philna.sh)
2 points
by
philnash
4y ago
|
0 comments
11.
▲
by
philnash
6y ago
Here's an idea about how to start with the mailbox sensor: https://www.twilio.com/blog/iot-mailbox-sensor-m2m-to-sms-fu... . This one sends an SMS when triggered, but you could certainly add it into Home Assistant
12.
▲
An Introduction to the Web Contact Picker API
(twilio.com)
1 points
by
philnash
7y ago
|
0 comments
13.
▲
Build a WhatsApp Chatbot with Ruby, Sinatra and Twilio
(twilio.com)
5 points
by
philnash
7y ago
|
0 comments
14.
▲
What people in tech had to say about JavaScript when it debuted in 1995 (2017)
(medium.com)
140 points
by
philnash
7y ago
|
235 comments
15.
▲
by
philnash
7y ago
I shy away from any rules that say you can’t mess something up simply by avoiding one thing, especially in this sort of case. Consider also that avoiding 2FA by SMS may avoid sim swap or recycle attacks, but it could also eliminate 2FA for
16.
▲
by
philnash
7y ago
There are a numbers of things here that are true. * Applications that take a phone number for one reason (2FA or otherwise) and also use it as a single factor for account reset are less secure in the case of number recyling. * Applications
17.
▲
by
philnash
7y ago
Further to this, it is also why I suggested the pattern workaround for older browsers. You shouldn't find yourself in too much trouble in a browser if you add an attribute to an element that it doesn't understand though, it will j
18.
▲
by
philnash
7y ago
This allows a developer to have all the benefit of the Authy API, including enhancing the experience using push authentication or dropping back to SMS if needed, as well as allowing users to use an authenticator app of their choice. It'
19.
▲
by
philnash
7y ago
You are absolutely right and I don't know where I read that (or why I believed it, given I had the spec open at the time too). I've updated the post, thank you for your help!
20.
▲
by
philnash
7y ago
The security hole there is using SMS as an account reset, which makes it a one factor solution (see other discussions of this in the thread). The error was in that implementation, not in SMS 2FA in general.
21.
▲
by
philnash
7y ago
Oops! Thank you for pointing this out, it is supposed to be "text". I have updated the post.
22.
▲
by
philnash
7y ago
Absolutely correct, I've even given talks on this. Check out slide 52, I think we're in strong agreement here: https://speakerdeck.com/philnash/2fa-wtf-at-pycon-singapore?... . I'm not advocating for poor
23.
▲
by
philnash
7y ago
But as I said towards the end of the previous comment, if you deem the threat to your users great enough that targeted SMS attacks are a problem, you can turn off that fallback.
24.
▲
by
philnash
7y ago
The Twilio 2FA API actually allows you to generate secrets and QR codes for generic authenticator applications now. Check out the documentation here: https://www.twilio.com/docs/authy/api/one-time-passwords#ot
25.
▲
by
philnash
7y ago
It is to do with SSO. I will pass off to my Twilio colleague Kelley to answer this with a post she wrote last year: https://www.twilio.com/blog/why-username-and-password-on-two... The nice thing about using autocomplet
26.
▲
by
philnash
7y ago
I’m actually paid to say that too ;) . In fact, SIM swapping isn’t the only weakness of SMS, take a look into the SS7 network and how that allows for a rogue operator to redirect SMS messages too. At Twilio, we have APIs for two factor auth
27.
▲
by
philnash
7y ago
Hello! I’m the author of this article. Thanks for posting! Here’s to the power of HTML attributes and better sign in experiences for everyone.
28.
▲
by
philnash
7y ago
SMS 2FA is still stronger than no 2FA.
29.
▲
Top errors from 1000+ Ruby on Rails projects (and how to avoid them)
(rollbar.com)
3 points
by
philnash
8y ago
|
0 comments
30.
▲
Better Passwords in Ruby Applications with the Pwned Passwords API
(twilio.com)
2 points
by
philnash
9y ago
|
0 comments
More ›