HN user

skion

34 karma

Tech lead @ WatchMouse

Posts3
Comments25
View on HN

Hi HN,

We received a number of requests from (ex-)Clef users asking if we would perhaps build an authentication plug-in for WordPress, now that Clef is sunsetting.

This is our first version: We opted to use a proven extension as a base, and collect feedback. Then use that to develop a stand-alone plug-in in the future.

Tell us what you think!

- Pieter

There are probably several angles on this. One is to let our Authentiq ID mobile app support and sign in to SecureLogin sites. Another to let websites that use Authentiq automatically support sign-ins with SecureLogin. These look feasible at first sight.

A third, replacing our current auth flow with SecureLogin indeed isn't likely to work for reasons you mention.

Yes! As a site admin in today's world, you should indeed not want to store passwords. Or even personal data for that matter.

I applaud this initiative since it lists exactly the reasons why we started Authentiq: Decentralization, usability, privacy, safety for end users (which is very different from merely offering security features that most people don't use).

Authentiq is similar in goals and architecture, yet with a more comprehensive feature set, since we aim to support existing standards (like OIDC) as the integration point for developers, and offer a more complete mobile identity to end users so that the site owner doesn't need to store those details either.

That said, I'm very keen to see if we can add support for the OP's authentication protocol soon. Check us out here if interested: https://www.authentiq.com/

One Less Password 12 years ago

"Passwords might be useful for someone who works on a public computer at the library."

Key loggers anyone?

TweetNaCl.js 12 years ago

For one the fact that (the author of NaCL) Daniel Bernstein is backing it.

So, what other extensions can we ditch now?

I really like the UX of SDC; are Disconnect or DoNotTrackMe just clutter, or adding value still?

Agree with this, even if just done in one reference language. It is much easier for the community to port an existing binding to other languages, than to implement a new client from scratch.

Two notes:

2) No need to mask requests with a HEAD; a GET can also return a 304 directly.

6) De-duplication of calls: Any method except POST should be idempotent already, hence also a retry-on-error is trivial in those cases.

Linux 3.14 out 12 years ago

I think that would then be the first time that Ubuntu LTS is piggybacking on an LTS kernel. With 3.12 already 6 months old that seems unlikely to me given Ubuntu's usual attempts to support modern hardware.

Firefox 27 Released 12 years ago

I just fixed that by setting:

  security.tls.version.max = 3
  security.tls.version.min = 1
  security.ssl3.rsa_fips_des_ede3_sha = false
in about:config, after which it also said "Probably good" for FF26.

"As a result, Telegram is the fastest and most secure messaging system in the world."

That's a very bold and yet to be proven statement. Probably any crypto expert would know better than to say that.

This paragraph exactly pin points the problem with being a cryptographic nobody.

PS. I do like their icon designer.

I love how exactly this mistake is covered in detail in the first week of Dan Boneh's crypto course:

  https://class.coursera.org/crypto-008/class
The Russians made the same mistake in WWII, but Whatsapp shows the relevance today.
Two.js 13 years ago

Awesome, I can see the reincarnation of animated banner ads...