Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sebk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
sebk
4y ago
Besides storage itself, the Postgres compute layer has a good amount of (transient) state that doesn't lend itself to either compute nodes or clients springing in and out of existence in a serverless environment. For instance, a fresh
62.
▲
by
sebk
4y ago
The Car Connectivity Consortium recently standardized Digital Key Release 3.0 (see https://global-carconnectivity.org/ ) which leverages UWB to provide precise, real-time spatial data that promises to be very effective at pr
63.
▲
by
sebk
4y ago
I don't disagree that it will be hard, but I think that ultimately all that is needed for this to be possible is a standard TPM API that lets you export key material wrapped in a public key (corresponding to another TPM, presumably) on
64.
▲
by
sebk
4y ago
I agree that this is an important next step in making WebAuthn accesible enough to supplant passwords. Note that once you're recovering your password, you've already lost access to your end-to-end encrypted data like keychain, and
65.
▲
by
sebk
4y ago
Microsoft, Google, and Apple recently announced support and commitment for multi-device credentials, which you can share between devices in the same "sync fabric". See some discussion on Hacker News here: https://news.y
66.
▲
by
sebk
4y ago
It's on the other portion of FIDO2: CTAP, short for Client to Authenticator Protocol. Your authenticator (A TPM, a YubiKey, maybe a phone) verifies your biometrics, pin, or presence before signing a request for the client (the browser,
67.
▲
by
sebk
4y ago
I don't disagree, but fundamentally, you're talking about burden for IT operators. The opposite of burden is convenience, and that's fine to be charged for, in my book. An app implementing strong authentication might not offe
68.
▲
by
sebk
4y ago
Relying on severing SSO access for this purpose is not enough. Those SaaS can be running processes that don't require an online user, or could support non-SSO API keys, or could still be taking up license seats. SSO in general is not a
69.
▲
by
sebk
4y ago
From a security engineering perspective I think strong authentication should be table stakes, and the proliferation of WebAuthn is a good starting point. For most enterprise companies it also likely makes sense from a risk management perspe
70.
▲
by
sebk
4y ago
Small nitpick, but that's still consistent as in ACID. I think what you mean is it wouldn't be consistent in the CAP sense (it wouldn't be linearizable). TFA does say that read-replicas will be present at every edge location,
71.
▲
by
sebk
4y ago
Not having ports with constant capabilities is a source of customer dissatisfaction when devices work when plugged in independently but not together. Consider for instance the new 14" and 16" MacBook pros: They got rid of the 4th
72.
▲
by
sebk
4y ago
FIDO needs to improve their communications and marketing if they hope to gain adoption, if they can't even get to the HN crowd. TFA also gets passwordless wrong, see As ZDNet notes, Apple, Google and Microsoft already support these pa