HN user

TheBicPen

102 karma
Posts0
Comments64
View on HN
No posts found.

Can these services not use the same fallback mechanism that already exists for non-passkey logins? i.e. an email with a 1-time code or similar. Yes that somewhat defeats the purpose of passkeys but that option is going to exist for a long time regardless of passkey adoption.

If you don't want to downgrade security, how about requiring confirmation from another session that is already logged in using a passkey? e.g. You try to log in on PC2. A prompt appears with something like "confirm this login from [PC1, etc.]". You log in on PC1 using your passkey. The service recognizes that the login id definitely you, or at least someone in possession of your physical device and login method for that device. Therefore, it then allows PC2 to register a new passkey. Kinda similar to how google confirms new logins by sending a notification to your phone.

throw out all the ones that don’t

encouraging as many other people as possible to also throw out their cheap cables

One of the main advantages of a single standardized plug is reducing e-waste. This just sounds irresponsible. Having a single tool that covers every possible use case is rarely a good solution.

I didn't have a way of running that code and only giving it access to a single USB device and nothing else.

To be honest I think that's the most compelling case for webUSB today. If desktop OSes had sandboxing tools (or more granular permissions in general) that are easily usable be everyday users, there would be no need to put webUSB in a browser sandbox. The cross-pltaform nature of it is nice, but that alone is not enough IMO. I think it would be interesting to see a Linux distribution where software that is not explicitly trusted (i.e. not installed by the system package manager) has no permissions by default. Interpreters make this more complicated but for binaries it could work.

you dont get that much karma if you are consistently posting bad takes.

I wonder how true that is. While this site doesn't have incentivize engagement-maximizing behaviour (posting ragebait) like some other sites do, I would imagine that simply posting more is the best way to accrue karma long-term.

MacBook Neo 5 months ago

Last month, Apple released an update for the iPhone 8 and iPhone X [1]. The iPhone 8 was released September 2017. I seriously doubt 9-year old Android phones, even flagship models, are still getting software updates.

How usable is an 8-year-old iPhone as a primary phone though? I agree that having 8 years of support is a good thing, but at that point the hardware is so degraded that it's not suitable for its original purpose anymore. At that point I'd rather have android just so I can root it and install Linux. Then again, with improvements to phones slowing down in recent years, this is becoming increasingly untrue.

Does any serious historian believe that fully defeating the Soviet Union after WWII would have been possible? Even with the advantage of nuclear weapons, I doubt the US would have made it very far.

At least NK's human rights abuses are contained within their borders. I hope future generations will look back on the many US invasions of foreign countries over the years and all the war crimes that took place during those invasions with the scrutiny they deserve.

While I agree with you, I find it hard to argue against the view that politicians are elected for the views they held during their campaign. They may change their mind after being elected, but their constituents that voted for them will not all change their mind simultaneously. To the ones that don't change their mind, it does appear to be a betrayal of their principles. A rational politician would not want to gain that kind of reputation out of pure self-interest.

I'd agree but we're beyond hopelessly idealistic. That sort of approach only helps your competition who will use it to build a closed product

That same argument can be applied to open-source (non-model) software, and is about as true there. It comes down to the business model. If anything, crating a closed-sourced copy of a piece of FOSS software is easier than an AI model since running a compiler doesn't cost millions of dollars.

It's a shame how many platforms are moving away from transparent moderation. I get that there are strong incentives to do so - a user that knows they're banned will immediately try to find a way to circumvent the ban. Shadowbanning delays that reaction if not stopping it outright. But damn does the concept feel dystopian. Like you're being ignored through seemingly no fault of your own. Surely that can't be healthy. And yet the platform is better off because the person isn't trying to circumvent the ban. And don't even get me started on replacing human interaction with AI for shadowbanned users.

WASM 3.0 Completed 10 months ago

Where does the 4 come from? I thought it was R+G+B+A, but you already have 3 colour channels in that calculation

Not paying with cash 11 months ago

The problem with leaving both dimes and quarters is that you'd need dimes for any price that's a multiple of 10c but not 50c. Getting rid of dimes would make it so that every price payable with cash is payable entirely in quarters.