Hacker News new | past | comments | ask | show | jobs | submit | GoMonad's comments login

Which financial institutions use YubiKeys? I didn't think there were any. https://www.dongleauth.info/ doesn't have any banks that do.


I think that depends on the cut of beef. 36h is great for brisket or short rib. But 36h would be bad for fillet mignon.


I'm curious how fixing these sorts of events gets funded. I imagine the expense is massive. Is it insurance? Is the allocated amount anywhere near proportional to the money being lost to being stuck? Who eventually bears the cost?


I've used Anki (spaced repetition app) with some success. I haven't been particularly dedicated. However, I know it's something that many people use and get results.


History repeats itself. I remember the same problem when LTE rolled out.


FIDO/WebAuthn has been designed to be first factor authentication (passwordless) as well as 2FA.

Though, I agree lost and stolen devices are a problem whose solution space needs more exploring than simply multiple auth devices.


This is, of course, an active thread of discussion in the WebAuthentication working group.


Can you point me to that discussion? I'd love to read more about it.


Relevant Kurzgesagt https://youtu.be/yS1ibDImAYU

The gist: we could trap ourselves on earth for generations with space debris.


Adding to the list of alternatives: https://solokeys.com/ Open source hardware


The fingerprint reader on my Thinkpad X1 Carbon (gen 7) can work as a FIDO device. I just re-tested it on https://webauthn.io/ with Firefox in Windows 10. I'm guessing other fingerprint readers will too. You need to know that it will be considered a "Platform" device rather than a "Cross platform" device, which is what YubiKeys are considered.

Related but not answering your question: I haven't found any major website that support Platform FIDO devices. I'm guessing they only want 2FA devices which can roam between computers. I think that's unfortunate. Perhaps a good policy would be to allow Platform devices to be used after a Cross Platform device has been registered first. But there are few websites that support multiple FIDO keys to begin with.

How nice would it be to log into websites with your builtin fingerprint reader? The client side stuff seems ready to go.


Hey Matthias! I know this is off topic for the thread but thanks for jhead! I used it for years in order to sync up the exif times from friend's cameras when we traveled together. I was pleasantly surprised to see your name when looking at the man page.

Love your channel. All the best with your new little one!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: