Which financial institutions use YubiKeys? I didn't think there were any. https://www.dongleauth.info/ doesn't have any banks that do.
HN user
GoMonad
I think that depends on the cut of beef. 36h is great for brisket or short rib. But 36h would be bad for fillet mignon.
I'm curious how fixing these sorts of events gets funded. I imagine the expense is massive. Is it insurance? Is the allocated amount anywhere near proportional to the money being lost to being stuck? Who eventually bears the cost?
I've used Anki (spaced repetition app) with some success. I haven't been particularly dedicated. However, I know it's something that many people use and get results.
History repeats itself. I remember the same problem when LTE rolled out.
Can you point me to that discussion? I'd love to read more about it.
FIDO/WebAuthn has been designed to be first factor authentication (passwordless) as well as 2FA.
Though, I agree lost and stolen devices are a problem whose solution space needs more exploring than simply multiple auth devices.
Relevant Kurzgesagt https://youtu.be/yS1ibDImAYU
The gist: we could trap ourselves on earth for generations with space debris.
Adding to the list of alternatives: https://solokeys.com/ Open source hardware
The fingerprint reader on my Thinkpad X1 Carbon (gen 7) can work as a FIDO device. I just re-tested it on https://webauthn.io/ with Firefox in Windows 10. I'm guessing other fingerprint readers will too. You need to know that it will be considered a "Platform" device rather than a "Cross platform" device, which is what YubiKeys are considered.
Related but not answering your question: I haven't found any major website that support Platform FIDO devices. I'm guessing they only want 2FA devices which can roam between computers. I think that's unfortunate. Perhaps a good policy would be to allow Platform devices to be used after a Cross Platform device has been registered first. But there are few websites that support multiple FIDO keys to begin with.
How nice would it be to log into websites with your builtin fingerprint reader? The client side stuff seems ready to go.
Hey Matthias! I know this is off topic for the thread but thanks for jhead! I used it for years in order to sync up the exif times from friend's cameras when we traveled together. I was pleasantly surprised to see your name when looking at the man page.
Love your channel. All the best with your new little one!
It's also to protect the world from the wearer. Not the other way around. Droplets aren't hurled as far when wearing a mask.
"My mask protects you. Your mask protects me."
"The reason the stock market is hard to predict is because it is a prediction."
https://futureoflife.org/2017/07/31/podcast-art-predicting-a...
Years ago, I was sitting next to John Conway and another older Professor in a small computer lab in Fine Hall (Princeton's math building) while waiting to meet my advisor. What I remember most about listening in on their conversation was how much fun it seemed they were having. Especially Conway. It was like he was engrossed in a really fun game and was trying to come up with new ways of thinking about the rules. I think you can see that in his work too.
The pure joy he took in his work is something I admired.
1. What happens in the middle, between a lock-down bringing down the infected numbers and vaccine.
I've read a few things from epidemiologists, but there seems to be little discussion in the wider media.
https://medium.com/@tomaspueyo/coronavirus-the-hammer-and-th...
2. What's going on with the PCR reagent shortage? Where are they produced? Why is it hard to make it quickly? etc.
Correction: the innergie does not use GaN
I've been looking at the innergie chargers. They use GaN.
I've been looking at this once since its so small.
Moreover, if a physically undetected clone is managed, it will be detected soon through the spec. The WebAuthn spec includes monitoring an always increasing counter for each key/site pair. One of the clones will start to fail.
So really there's no point in cloning. Straight up theft is the bigger concern.
I remember them being useful when my phone was resting on my desk at work. This was before always on notifications were as prolific and advanced as they are today.
I could wave my hand to check the time. Or see what was causing the most recent notification chime. It sounds really simple but not having to pick up the phone meant reducing distraction.
The Moto X's gestures couldn't be much more than a hand wave due to the simplicity of the sensor. But even so, they kept me from picking up my phone quite a bit.
I had a Moto X which had IR touch-less gestures. I remember them being surprisingly useful and I missed them when I retired the phone.
I'm optimistic to see what these radar based sensors can add.
Anything by John Carmack. (DOOM's open source release, for example)
Slight generalization of the first two: many emacs keybindings work in bash.
I like this hierarchical approach. Thanks.
You can also add PINs to Yubikeys to mitigate the local threat.
How do you manage keeping all the keys "synced" in terms of which services they are registered with.
I keep keys in separate locations for safety, but that makes adding all keys to a new account a big pain.
This hasn't been a big problem yet because there are so few services that support the keys, but I wonder how people would manage it if it became widespread.
In the end they said the checks are done locally—by downloading dozen-gigabyte leak archives like the exploit.in, I guess?
I would guess they are doing the checks with a technique called k-anonymity. It doesn't require sending the password, nor does it send too much data to the client. Troy Hunt offers a service using this technique.
For anyone who finds this stuff fascinating, There's a great book, "through the language glass" by Guy Deutscher. I really enjoyed it.
To be fair to Intel, you wouldn't be in the red if you took dividends into account. The adjusted pre-crash price is ~$44 relative to today's $54. Still, a pretty bad return for 20 years.
At highway speeds, the sound of a modern cars (ICE or otherwise) is mostly tire noise. Electric cars are much quieter at slower speeds, when tire noise is minimal.
LastPass has this too I think. But something seems off to me storing my 2FA with the service that manages my first factor.
YubiKeys can store and access OTP secrets. I put the secret in both Google Authenticator and my YubiKeys as backup.