HN user

raron

230 karma
Posts0
Comments128
View on HN
No posts found.

That could work, but then the service needs to implement complex non standardized authentication mechanism outside of Passkeys. You will have 14 different services with 15 different options. I don't think that's really user-friendly.

Also it could be vulnerable to MFA fatigue attack, if people would constantly get new "confirm this login" popups, they would press anything to make it go away.

So you would need something that is explicitly initialized from a trusted session, then you need something to connect the trusted session to the new login. If you want that to be user friendly you need some short codes and can't rely on QR code / Bluetooth, or two-way interaction. And that brings up the phishing / MitM attacks again.

It is not feasible to remove password login or some other recovery login method.

Then passkeys doesn't provide any real value if you have other less secure recovery option.

Let's say I have a bank account, going to the branch and doing an in person ID check is a valid recovery option, but nobody would want to do that just to log in from a new device.

It isn’t useless, point is you don’t get to type in your password on a device that has passkey generated already, or get phished on a fake web address for example.

That's solved by letting the browser to remember the passwords.

Passkeys are meant to be protected by either PIN or biometrics, however they are also meant to be revocable on the web, at least they are for services i’ve been using with passkeys.

PIN and biometrics doesn't have any inherent security. They rely on some hardware (or software separated from main system) feature, and even those can have vulnerabilities.

You generate another passkey is your answer. How do you do that? The exact same way you do today.

How can I do that, if Passkeys are the only option to log in?

If I can just use a password to log into a website without Passkeys, then Passkey is useless and doesn't add any security benefit.

Why would you need to delete invalid passkeys? You wouldn't.

I sell my old (and no longer updated) phone or PC and don't want someone to get access to my account by getting access to the secret keys.

An non-revocable authentication mechanism is just stupid.

I don't think that would work either.

Let's say I have a new account and a single Passkey in the TPM of PC1. I want to log in from PC2, too. How can I do that? (I know there is some trickery with Bluetooth, but I haven't seen anything supporting it, and desktop PCs usually doesn't have Bluetooth connectivity.)

AFAIK some browsers can do some magic to use a Passkey from your smartphone on a PC, but you need to log in to the same browser-sync account from both device (which brings back us to the same issue).

Also the whole thing becomes a mess when you change devices. You need to log into all the services you have ever used to delete the Passkeys from devices you no longer have, and you need to add a new passkey from a new device you bought to all the services you use.

The enforcement of GDPR is more or less nonexistent for big companies. Even if they get fined, that is just cost of business for them.

In the text nothing prevents the manufacturer to stream the vide of your face to their servers all over the world and do the image processing there. It would even comply with GDPR if everybody pinky promised they not using that data for anything else.

I think that depends on how do you define PII.

I suspect the ZKP proof or token is practically unique and related to you, so I could be personal data if you use the definition from GDPR.

With ZKP the entity and the original verifier shouldn't be able to match your identity to the ZKP proof or token, but the app on your phone of course can do that.

The app probably will be made some government contractor and there is no technical measure that would prevent them to just share all that data with whoever they want.

if I wanted to buy a device with a new type of connector, I should have been able to

You are. Nothing prevents the manufacturers to support other better charging solutions than USB-C. In fact many notebooks has their proprietary connectors and some smartphones use custom signaling over custom USB cable to provide better experience while complying with the regulation and support USB-C charging, too.

The difference is more a financial or legal thing, than a technical one.

From an users' perspective paying with digital Euro would work more-or-less the same as you pay today with card, bank transfer or something based on QR codes. But it will have very different guarantees and trusts behind the scene.

Today you don't really think about keeping your money in a bank and paying with card as a different thing than having physical cash, because banks and payment services have very strict regulations and insurance schemes. Banks rarely goes bankrupt and even if they do, most of the people are not affected, because they get back their money from deposit insurance.

Banks can create money from thin air (without the approval of the central bank) and lend it to you (and destroy when you pay your loan back), they can not do that with Digital Euro.

Everybody would be able to convert all their Digital Euro to banknotes at the same time, but that would bankrupt any commercial bank.

Banks can deny your request to open an account or provide payment services to you (e.g. what happened with the ICC judge), you can own Digital Euro without having a bank account.

Banks pay interest for using your money (and the risk you take), this could even be negative that means some people even willing to loose money if they can have Euro instead of their original currency. Banks wouldn't be able to use your Digital Euro, you wouldn't get any interest on it.

Digital Euro (the same way as physical cash), is a legal tender, money in bank and card payments are not.

The value of Digital Euro doesn't depend on your bank, the numbers on your bank account could worth nothing if your bank goes bankrupt, central banks can not go bankrupt.

Digital Euro (for a limited amount) could be exchanged directly between two peers like physical cash (offline, without connection to internet or any bank).

It gets interesting when the two system interacts. Friends visiting the US told me that at the POS terminal they had to choose credit card despite paying with a Visa/Mastercard debit card issued by an European bank.

By the way, here banks even have daily bank / wire transfer limit that can be changed only by a personal visit to a branch, so even if your online banking credentials are stolen, the attacker can not empty your account.

Not really. Euro cash today is paper / plastic banknotes and metal coins. Your account in the bank is not really cash you own, it is more like the banks liability towards you.

If your bank fail, you loose the money you held in the bank (except the insured amount). If you have some cash, that's independent from any private company, and it must be accepted everywhere. Digital Euro should have the advantages of cash and the comfort of electronic payments, too.

That's interesting argument. Here it is usual to have a daily limit on debit cards. You can not spend more money than that, so a thief can not drain your account. Also many banks give you multiple accounts (you can transfer between them instantly). The debit card is connected to only one of them, so if you keep part of your money on the other account, that couldn't be touched even if the card payment limit has technical issues.

Probably it depends on what part of the world you are and on what is your goal, what you want to optimize for.

In many countries there are usual systematic weather events where all renewable production goes to basically nothing for few days or even 2 weeks. You can not solve that by improving renewable sources, there isn't enough raw energy they could capture.

Storage for that long is currently impossible and even if it would be, it would be prohibitively expensive. So what you can do, build gas or coal plants. Building those, having people on call all the time, and the opportunity cost is probably many times more expensive than the building cost of renewables themselves.

And you still need to buy and store fossil fuels, you are still dependent on geopolitical issues, and you still produce a lot of CO2.

If your goal is environment protection or reducing climate change, then nuclear is probably better. If your goal is to reduce energy cost then probably renewables + short term battery storage + gas backup is the winner if you use an appropriate electricity pricing model.

Nuclear seems to be the old, known, stable thing, while renewables are the new and shiny thing that solves everything cheaply (and that sounds like it has huge catch). When you are building such critical infrastructure as the electrical grid, then staying safe and choosing the known, but expensive solution might seems to be the right choice for many people.

The point of SynthID is to make generated images identifiable, in an attempt to prevent 1984-esque situations where you can't believe your eyes and ears.

You can still use traditional methods to manipulate images, too, so I don't think a "does not contain SynthID watermark" means you can trust that image more. In the other hand, encoding a lot of personal and other information in the watermark (136 bit is a lot) that can not be easily removed and most of the people are unaware of it seems really an 1984-like dystopia.

A payment should be a bank transfer. Anything more complicated is just something that is to be exploited by middle-men.

I disagree with that. Payments (especially online and contactless ones) should have some form of buyer protection, chargeback and a way to handle fraudulent transaction, lost / stolen cards, etc.

Wero is just another private company trying get their cut of payment fees. You can do the same thing with SEPA Instant Payment (or some member states outside of the Eurozone have their own similar thing).

I don't see why Wero should exists, their business model seems like "trying to get money for the same service you can get for free".