HN user

jackson1442

2,595 karma

Some days, I put on my software engineer hat.

Posts8
Comments834
View on HN

My main issue with these systems is that they tend to not be able to do anything beyond what I can do myself in whatever self-service portal is available. If I'm calling, it's because I need support beyond what the bot can probably provide, and it just becomes a matter of arguing with the robot to get to a human who can actually solve my problem.

ChatGPT Pro 2 years ago

A more convenient manual that frequently spouts falsehoods, sure.

My favorite part is when it includes parameters in its output that are not and have never been a part of the API I'm trying to get it to build against.

I've found that face/retina scans are usually bad UX, especially if you need to use a viewfinder or a statically positioned device. Apple's Face ID works well because it's on a mobile device and you don't have to align your face in a box.

I don't see how this is any more convenient than using a mobile wallet. In fact, it looks less convenient than using the actual card - even if you forget the card you can usually just key in the number at the terminal.

Washington doesn’t even officially offer a RealID. Instead they have the “Enhanced ID” which functions as a passport card but does not have the security features required on a RealID (though it does have some additional features like RFID).

I really hope the profile management system keeps tab containers working the same. It's incredibly useful to have different containers automatically generated for AWS console sessions.

It's up to the server whether it uses it in challenge-response or not. That's application-specific behaviour that's past the definition of passkeys themselves.

Do you have a source for this? After reading the W3 spec[0] this seems entirely antithetical to the Passkey model and additionally raises concerns about the integrity of hardware mfa devices.

[0] https://w3c.github.io/webauthn/

This is the same behavior as SMS if you have enabled “Messages backup.” If backup is not enabled you will not have a copy of iMessages stored in iCloud (though all compatible and configured devices will still receive messages).

This can be changed by opting in to the e2ee iCloud data service “Advanced Data Protection.”

I’m curious how this works with the new ID-scanning machines that no longer require a boarding pass. Maybe there’s some level of fuzzy-matching name/sex/dob?

I assume for TSA Precheck users there’s some lookup that can just grab your KTN from the database from your ID and look up tickets based on that.

While I would love to see a more open iphone NFC chip (primarily for identification/access control system integration), I shudder to think of bank implementations of contactless payments. Bank apps I’ve used have been “meh” at best, usually bad (and filled with ads!!) and don’t even support modern secure authentication (totp/webauthn). I’d like to see them fix their core technology before trying to figure out a way to sell me a loan using mobile payments.

It even has certain advantages, such as allowing one to unlock a banks doors outside regular hours to access the self-service area for things that are beyond regular ATMs, something that currently does not work with Google or Apple Pay.

Have you tried it? I’ve been able to open Chase bank ATM lobbies using the NFC Jimmy John’s loyalty card in my Apple Wallet (along with every brand of payment card I have in there). This “security” appears to be primarily to keep unbanked (read: homeless) people out.

Highly recommend doing this - also if you think your employer is reporting data to The Work Number (highly probably if they use ADP), ask them for information on your employee profile. Equifax has lied to me about the existence of my profile even though they did, in fact, have data on me. Only when my employer told me the identifiers for my profile did I find out that they had previous data on me and I was able to opt-out.

Name changes can be locked; I'm in an Enterprise Grid org and our display names/usernames are synced against our employee profile. We're also required to SSO every single time we launch the desktop app so once you're terminated you're definitely not getting back in (they deactivate accounts very quickly too, so mobile is likely not a major concern).

Basically the only thing you can change without filing a ticket is your picture and some mostly-irrelevant freetext fields.

I just applied for my passport, and am looking forward to worldly exploration.

Congrats! Travel is super important to gain perspective - culturally, politically, and socially.

As an added bonus, having a passport makes ID verification much less of a pain in the ass (typically you just need a passport rather than a state ID + other documents).

Do sites generally allow you to have passkeys and passwords set at the same time for the same account?

Typically, yes. You can do this today with Github and Google accounts (and certainly at least a few others). The password option might instead be a link in your email or something similar on other websites, but generally I’ve seen it recommended to have at least one other option to get into your account.