Hacker Newsnew | past | comments | ask | show | jobs | submit | CodeWriter23's commentslogin

Yeah. Arson-induced insurance fraud. Hope this helps.

This is the problem with governments who think they can synthesize value. They think all businesses can too.

If these communists succeed, they will use the very fact that a landlord cannot synthesize money to prove the landlord passed the cost to the tenant and seize the land.


aka the purpose of 'Ask' mode. These new tools require one to 'Think Different'

Nah, it's the transmission of the keys to Apple or Microsoft. We flatly rejected key escrow during the Clinton Administration, and I continue to reject it. And no, I absolutely do not trust their implementation of E2EE to mean there are no backdoors.

Are you aware that none of that is required when signing up for a site that supports passkeys?

I think there is some confusion here caused by sloppy use of terminology among FAANG and the standards groups. You’re right that, strictly speaking, Apple defined “passkeys” as synced credentials. And you’re also right to point out that, as a result, in order to consider them secure, you must trust Apple’s key storage and E2EE iCloud syncing, or the equivalent from other vendors. I wouldn’t blame you for being skeptical about synced credentials. The convenience may not be worth it for you.

However, crucially, synced credentials are just one type of FIDO2 credential. The other is a hardware-bound key from a “roaming” authenticator (aka a “security key”). These are never transmitted, never synced, and you can buy the security key hardware that generates and stores them from many different vendors, all of which are designed to be interoperable.

In other words, all passkeys are FIDO2, but not all FIDO2 are passkeys. Yet, when a website says it supports passkeys, it probably means it supports all FIDO2. And that’s because WebAuthn, the browser standard used to implement passkey registration and authentication on the web, supports all FIDO2 credentials, not just passkeys.

With WebAuthn (and most other systems), by default both platform authenticators (which would typically be synced, like you’re talking about, but not necessarily) and roaming authenticates (which would be typically be a USB security key, not synced) are allowed. I’ve occasionally stumbled upon sites that don’t allow platform authenticators, but I’ve never come across one that doesn’t allow roaming authenticators. It sounds like you want is the latter.

Apple could have avoided this mess by simply deciding that “passkeys” are the new name for “FIDO2 credentials” and then we could have synced passkeys and non-synced passkeys. But they apparently thought that was too confusing.


Ok, thanks for the explanation covering everything except the topic of my comment. And yes, I was aware. The point is, nobody (except those with a condescending PhD tone of voice) is aware of the loophole inherent in synchronizing passkeys.

When are they gonna make "macOS South Central"?

At the rate we're going, it would be "macOS America"

Don't give him ideas...

It comes between macOS Fresno and macOS Calexico.

Don't be a menace.

Don't be a snob.


macOS Skid Row

It's really not interesting at all. The US Destroyed that satellite to stop that information flow.

China has more intelligence/imaging satellites in space than the US does. I don't think it will stop the information flow.

And all they have to do is move them into position to gather intel on the Iran region to have them destroyed as well.

You think the US will destroy 230 Chinese intelligence satellites? LOL

The DEW announcement is the message "we destroyed your satellite, Xi"

The SIR-C/X-SAR was launched in the Shuttle Bay and used to map the entire surface of The Earth. Some would call that a munition. This article, following that event IS the confirmation.

Good:

Insta requiring login Facebook requiring login

Bad:

X requiring login


Good:

The Open Web

Bad:

Insta requiring login Facebook requiring login Xitter requiring login


What an absolute clown show. I don't see how anyone can trust WordPress (the company) going forward.

It's one lake.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: