Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sufficient
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
1.
▲
by
sufficient
7mo ago
Thanks, that's interesting. We don't see all the smaller changes our competitors are doing. With heylogin, you could try our Quick Access feature. It pops up with a global shortcut and is fully keyboard navigable. Let me know if s
2.
▲
by
sufficient
7mo ago
passkey support is currently in internal beta, but will be released soon. what kind of features have been removed from 1pw that you considered important?
3.
▲
by
sufficient
7mo ago
Hey, CEO and Co-Founder of heylogin here. Feel free to try out heylogin and let me what you think of it. I know we don't have feature parity with 1pw, but we try to innovate on the core user experience of logging into websites first. O
4.
▲
by
sufficient
3y ago
You can try https://www.heylogin.com if you are looking for a new approach without a Master Password. I am one of the founders.
5.
▲
by
sufficient
4y ago
Goldberg's answer "The 1Password Secret Key may not be the most user-friendly aspect of our human-centered design..." is unfortunately true. We experienced a lack of understanding on the user side that this secret key needs t
6.
▲
by
sufficient
4y ago
Just wrote a longer answer to the question below, hope that covers your question as well.
7.
▲
by
sufficient
4y ago
You are asking the right & also complicated questions :) Let me first say that we are just finishing up a version 2 of our whitepaper that can answer all questions regarding the cryptographic architecture including these scenarios. We&#
8.
▲
by
sufficient
4y ago
maybe… I sort of agree it's not a huge hassle when recovering from another still functional 1Password installation. I still think that the initial flow of asking the user to print something that looks complicated is something that turn
9.
▲
by
sufficient
4y ago
I think we can do better in protecting vaults against offline brute force attacks. As written in the this post, 1Password uses a randomly generated "secret key" together with the user-chosen master password. This "secret key&
10.
▲
by
sufficient
4y ago
This is a wake up to call to not build your security model on a user chosen master password! Since the vaults have been stolen, an offline brute force attack can be executed. This attack is no longer slowed down by online protection mechani
11.
▲
LastPass problems uncovered that make the incident so bad
(heylogin.com)
9 points
by
sufficient
4y ago
|
0 comments
12.
▲
by
sufficient
6y ago
Yep, Nextcloud is using our SDK from https://hwsecurity.dev/ . We provide dual licensing for closed source and GPLv3 projects.
13.
▲
by
sufficient
6y ago
Great work Fabian! Nice to see this work becoming open source. I am pretty new to fuzzing, please correct me if I am wrong: Since Jazzer fuzzes a Java application at runtime, can it be in principle also be used to fuzz a Java app without ha
14.
▲
by
sufficient
6y ago
I agree that it's weird that they fixed it and didn't consider it a security issue. For the user it looked like it would provide two-factor authentication since the PIN is requested, while in reality it's not verified. Thus,
15.
▲
Pin Bypass in Passwordless WebAuthn on Microsoft.com and Nextcloud
(hwsecurity.dev)
7 points
by
sufficient
6y ago
|
3 comments
16.
▲
by
sufficient
7y ago
We developed a vendor-independent FIDO U2F implementation for Android that works with Security Keys over NFC and USB. It's dual licensed under GPLv3 so you can inspect the source code or use it in your open source Android app: https:&
17.
▲
Show HN: Fido U2F on Android
(hwsecurity.dev)
5 points
by
sufficient
7y ago
|
1 comments
18.
▲
by
sufficient
7y ago
I came to a similar conclusion: U2F hardware is the way to go. For some people, smartphones are becoming the only device they use. However, I am not fully convinced of using the device itself as a U2F key. Then it's no longer a two-fac
19.
▲
by
sufficient
9y ago
On Android, we provide the OpenPGP implementation OpenKeychain that now also supports an impressive list of Security Tokens ( https://github.com/open-keychain/open-keychain/wiki/Security... ). In our newest rel
20.
▲
by
sufficient
10y ago
Author of the paper here. Yup, in regards to Signal our findings are already obsolete :D I think that the new Signal developments are great. It is better to allow only one key verification mechanism for unified usability and also use key co
21.
▲
by
sufficient
10y ago
Author of the paper here. There is existing work on testing the feasibility of impersonating other person's voice. We discuss them in our related work section at the end of the paper. I think on the long run, SAS will no longer be a su
22.
▲
Evaluation of VoIP encryption with ZRTP
(sufficientlysecure.org)
1 points
by
sufficient
10y ago
|
0 comments
23.
▲
How to use the gait (unique pattern how someone walks) for secure pairing?
(sufficientlysecure.org)
1 points
by
sufficient
10y ago
|
0 comments
24.
▲
A Study of Key-Fingerprints: Hex vs. Base32 vs. Wordlists Vs
(usenix.org)
11 points
by
sufficient
10y ago
|
4 comments
25.
▲
Surreptitious Sharing: Vulnerability in many popular Android apps
(ibr.cs.tu-bs.de)
1 points
by
sufficient
10y ago
|
0 comments
26.
▲
by
sufficient
11y ago
Yup, we are working on the remaining points, see https://www.openkeychain.org/k-9/ - Dominik
27.
▲
Android Privacy Guard is insecure
(openkeychain.org)
2 points
by
sufficient
11y ago
|
0 comments
28.
▲
by
sufficient
11y ago
OpenKeychain developer here. If you have any questions about certain fixed vulnerabilities or features, I am happy to answer any questions.
29.
▲
OpenKeychain 3.6: Security Audit and Tons of New Features
(openkeychain.org)
3 points
by
sufficient
11y ago
|
1 comments
30.
▲
by
sufficient
11y ago
If you are on Android, use OpenKeychain. We don't ask these questions. Instead, we have a simple wizard guiding you through the process of creating a key. We don't ask for the algorithms (RSA, DSA,...). We don't ask for User
More ›