Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
thekeyper
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
31.
▲
by
thekeyper
5y ago
Nail on the head. That's the problem that the secret sauce solves. Without going too much in to it (because I don't think it's a very defensible moat at the moment), the phone sees stuff on the screen other than the QR code,
32.
▲
by
thekeyper
5y ago
Ah yes, thanks for pointing that out. The iOS app store listing is ancient and terrible. The Google Play store listing is a bit better, but still from a time when I was doing all the design work :)
33.
▲
by
thekeyper
5y ago
I don't have much inside info, but the contents of the QR codes on Alibaba, JD.com, and others differ substantially, so I suspect each is building their systems in-house, though in China, I would think there's more of an establish
34.
▲
by
thekeyper
5y ago
Keyri makes less sense for smartphone-only applications. The primary case we solve for is applications that have both mobile and desktop web interfaces. Phones are already essentially considered trusted devices, whether auth there happened
35.
▲
by
thekeyper
5y ago
Thanks very much for the heavily referenced post. As an aside, I built the prototype of this last year in a vacuum without knowing any passwordless solutions other than FIDO2 systems. My cofounder disabused me of the notion that this was a
36.
▲
by
thekeyper
5y ago
The general crypto scheme (auth based on signed requests) is the same as SQRL. Differences: (1) SQRL employs one identity that users use across multiple SQRL-enabled services. Keyri-enabled accounts are not portable/natively-shareable
37.
▲
by
thekeyper
5y ago
> WiFi calling usually also supports texts over wifi. True, but WiFi calling remains opt-in for most carriers (and I suspect it'll remain so given the incentives in play). I don't have stats on WiFi calling adoption, but anecdo
38.
▲
by
thekeyper
5y ago
I used "OpenID" in the text as shorthand for OIDC. To be clear, Keyri is not OpenID / OIDC for preserving privacy and making the Keyri API a fail- and compromise-secure system.
39.
▲
by
thekeyper
5y ago
Private keys are backed up via iCloud Keychain (on iOS) and Android KeyStore (on Android). Both are encrypted systems and are the backbone of Apple and Google password managers, respectively. On the device, private keys live in the phone&#x
40.
▲
by
thekeyper
5y ago
Thanks. Yes, the concept is to productize the WhatsApp/Discord UX. Keyri differs from them on how it works behind the scenes for increased security and ease of integration. BTW - QR login is much more prevalent in China. Just about eve
41.
▲
Launch HN: Keyri (YC S21) – Secure smartphone-based passwordless authentication
69 points
by
thekeyper
5y ago
|
90 comments