Hey… if you weren't aware, the HN guidelines now include: > Don't post generated comments or AI-edited comments. HN is for conversation between humans.
HN user
dyml
I also used Kagi, but decided to cancel my subscription last year when it was revealed they pay Yandex for their search, which is a Russian company that ultimately fuels the Russian war on Ukraine.
Once Kagi stops transferring money to Russia, I’d be happy re-subscribe.
I work at bitwarden and I can confirm this. While technically you have the data, any other app need to support our json format (which they totally can, our code is open source) - but CXP (the standard) is happening this year so we’re planning on using it.
I worked on this standard and we’re all excited that it’s rolling out to most of not all password managers and platforms.
We're enabling it by default, you can opt-out.
I just want to point out that the title is wrong. 2FA is on by default, but not mandatory. Dang, can we change the title?
I work at Bitwarden and I have that same pet peeve! Let's see if I can get a PR up without causing a UX stir :)
Very unfortunate and caused me to cancel my subscription immediately. Any alternatives that people can recommend to someone who throughly enjoyed Kagi?
I really hope they reconsider their arrangement.
Please don’t use WebAuthn on every page load.
Two reasons: the protocol is not designed to do this - and the UI/UX is not designed to support this. There are better ways.
2) it will likely not work. There are virtual/software authenticatators (available in dev tools) that could generate a valid response without a human.
Use a password manager, like Bitwarden
Send an email to me at aaberg@bitwarden.com and I’ll look into it!
Good feedback, thanks! will bring it up when I’m back at work
Very soon
You can use any passkey provider app. I work at Bitwarden and we’re building mobile passkeys for android right now. We can do the e2e sync, but if you want you can always self host Bitwarden server and just use our clients app.
You make a valid point about “non-resident” WebAuthn 2FA being great 2FA. However, passkeys are also great, and they depend on your context…. Most people are in the passkey context.
For people who are not knee-deep I think we can explain it a bit better, why passkeys replaces passwords:
With non-resident (2FA keys) you need to identify your account first. Since you don’t want to have account enumeration, this means doing a primary authentication, e.g. passwords.
With passkeys, the website can just ask your browser) to sign in with any of the accounts it has passkeys for; which result in a one click sign in.
While hardware backed Security Keys for 2FA is great 2FA, there’s a tangible cost, both in UX and $ that leaves many users left out (not everyone can afford $20 for a security key)
Source: I work at Bitwarden building our Passkey API for developers. We support both 2FA and passkeys, both in the API service and in our password manager. Feel free to ask my anything related.
Hey, I work at Bitwarden and since you mentioned us I feel obliged to respond.
I lead our work on passkey portability, which I work on daily.
Give me and my colleagues a couple more weeks to get the code up and running (standard/cross-industry collaboration takes calendar time).
I’m sorry that our initial work is not happening fully in the open *yet*, but we’re all pushing for it and it will be, hopefully sooner than later.
The best place to argue this “in the open” is by raising issues in the w3c/webauthn repo, or meetings, which is open.
I like this! Thanks for building it. What’s the biggest differences between PagerDuty?
I want to echo your last question, are all dependencies bad?
Thanks for sharing this. As a web dev, rather than game dev, I like that what I’ve used in web dev more and more is usable in web dev (es6, imports, rollups) etc.
To me, it has previously felt clunky to use older (and more mature, sure!) toolkits when building a one-day game just for fun.
Would really have enjoyed this for Windows.
I watched the entire video and I absolutely loved it. Great work, good explanation and very elegantly and beautifully done.
What features will this unlock for you?
This is great! It has always been a peeve that they have been so coarse grained.
Thank you to the team members that made this happen.
I don’t agree with this statement. Im happy to see the innovation that have come out from GitHub in the last years.
What im really missing and hoping for is an even more open and extensible community platform. Discussions is a good start, it would love to more innovation there.
I don’t agree with your criticism.
On my iPhone indoors I could clearly see both the “workflow animation” and color variations in the examples further down.
Looks like a cool application.
It’s incredibly exciting to follow your work and the teams!
Thank you!
Can you expand on this? I’ve always found powershell hard to do right.
Good feedback. Will do.
I’ve asked everyone and they googled around, found the GitHub project and from there the API service. I haven’t been able to convert that knowledge into a strategy.
Yes