HNHacker News
TopNewBestAskShowJobs

PranavBerry

38 karma · joined August 8, 2019

submissionscomments
PranavBerry··on Ask HN: Who wants to be hired? (February 2022)
Location: India

Remote: Yes

Willing to relocate: No (can work remotely according to another time zone)

Technologies:

Python (FastAPI, Flask, Django)

JavaScript/TypeScript (React, React Native, Node.js)

Machine Learning (Numpy, Scikit-Learn, Pandas, Keras)

PostgreSQL/MySQL

Docker

Résumé/CV: https://www.linkedin.com/in/pranav-berry-00809719b/

Email: berrypranav@gmail.com

I'm also ok with an internship role before discussing further.

PranavBerry··on Ask HN: Who wants to be hired? (January 2022)
Remote: Yes

Willing to relocate: No (but can work remotely according to another time zone)

Technologies:

JavaScript/TypeScript (React, React Native, Node.js)

Python (FastAPI, Flask, Django)

Machine Learning (Numpy, Scikit-Learn, Pandas, Keras)

PostgreSQL/MySQL

Docker

Résumé/CV: https://www.linkedin.com/in/pranav-berry-00809719b/

Email: berrypranav@gmail.com

PranavBerry··on Ask HN: Who wants to be hired? (December 2021)
Location: India

Remote: Yes

Willing to relocate: No (but can work remotely according to another time zone)

Technologies:

JavaScript/TypeScript (React, React Native, Node.js)

Python (FastAPI, Flask, Django)

Machine Learning (Numpy, Scikit-Learn, Pandas, Keras)

PostgreSQL/MySQL

Docker

Résumé/CV: https://www.linkedin.com/in/pranav-berry-00809719b/

Email: berrypranav@gmail.com

I'm also ok with an internship role or working on something as a sample before discussing further.

PranavBerry··on Why is using SMS bad for 2FA?
>If I'm a common person with one phone

I had not thought about that but I think I can add push notifications if this is a problem. So on your phone you just tap the login with my authenticator button and approve the push notification in my authenticator app.

>how do I get my account back?

You can optionally add a recovery email.

PranavBerry··on Why is using SMS bad for 2FA?
> plug my Yubikey into as many laptops as I would like.

What if you don't own a physical key?

> I have to trust you to not leak my 2FA. Authy does this already and so I don’t use Authy

This is optional. You can choose not to have a recovery email. Just curious though, what do you do if your Yubikey gets stolen/damaged/lost?

PranavBerry··on Why is using SMS bad for 2FA?
>Is your service going to be audited by independent third parties that vendors choose?

Yes I am planning to do that.

>How do people verify that your application is the legitimate version? How does the bank know if someone has tampered with your application?

I will use SafetyNet to check that the device is not rooted/jailbroken and that the signature is being made from my app.

PranavBerry··on Why is using SMS bad for 2FA?
> FIDO Alliance is doing with WebAuthn

Yes I looked into it, but it looks like WebAuthn does not support multiple devices (let me know if I am wrong).

What if I want to login from two different devices? I don't think that is possible with WebAuthn, but using my authenticator you can login to multiple devices. You will also be able to add a recovery email address to my authenticator to recover your accounts if you phone gets damaged/lost.

PranavBerry··on Why is using SMS bad for 2FA?
>intercepting traffic or spoofing a site can copy/tamper/replace the QR code

Will this be a problem with HTTPS?

When you open a page, a request will be made to my server to generate a unique login attempt, the id of this unique login attempt will be shown in the QR code. When you scan it and enter your phone's pin, my authenticator generates a signature of the login attempt id, your username on that website and the current time. My server verifies the signature and logs you in if everything is ok.

Have you logged in to the Discord/Reddit/Whatsapp websites by scanning the QR code shown there from their mobile app? My concept is the same but using my authenticator app, websites which do not have a native app can also offer a QR code login.

PranavBerry··on Why is using SMS bad for 2FA?
>As for QR codes, those can be copied The QR code are unique for every login attempt. After you scan the QR code and enter your phone's pin, my authenticator will send a request to my server. If everything is ok you will be logged in. Sorry I did not get what you mean by this? Do you mean that someone could copy and use the same QR again?

>I will never use digital face/touch ID for anything I do not save any biometrics on my server. They are stored locally on your phone, my app just uses the native system used to unlock your phone. That being said, you can just use your phone's pin if you don't like to use biomterics.

PranavBerry··on Why is using SMS bad for 2FA?
> SMS based 2fa has many other problems

What are these problems? It will be great if you can list some of them, I'd like to read more in detail.

PranavBerry··on What do you think of Scan QR to Login as a Service?
Got it, but there will still be a network effect.

You will just have to download it once and can add and manage accounts on a lot of websites.

PranavBerry··on What do you think of Scan QR to Login as a Service?
>have a Msft Authenticator and a Google one I think you can just add all accounts to one authenticator.

>make it work with one of these These authenticators, have no support for QR codes so this would not be possible.

PranavBerry··on What do you think of Scan QR to Login as a Service?
>agree with password-less.

Does my idea sounds like something you would use? Will you download a authenticator app to avoid using user/pass?

PranavBerry··on How do you handle 2FA?
>the website display the QR code and the phone scan it I'm exploring that right now, thx a lot.

>I'm probably missing the point of your idea.

It was mainly a way to do 2FA with a phone but no SMS/internet on phone. However it looks like TOPTs solve this probelem.

PranavBerry··on How do you handle 2FA?
> TOTP and similar already solve the "phone is present but offline" issue.

Thanks a lot, this invalidates my idea and I will not work further on it.

PranavBerry··on How do you handle 2FA?
> How will a website be able to scan my phone's screen?

Using your webcam. However from the comments it seems that there are a lot of devices without a webcam so my idea will not work.

PranavBerry··on How do you handle 2FA?
If the phone not having a internet/network coverage was a problem, my idea could be useful. It also makes the phone a kind of hardware token, a user can login only if he has his phone.

However from the responses it looks like this is not an issue and I'll probably not work further on this idea.

PranavBerry··on How do you handle 2FA?
> If the user needs to be loggedin somewhere, they must be online

I will be using JWTs, with asymmetric signatures. An internet connection will only be needed while adding the device for 2FA. The JWT will be generated from the private key already on the phone so internet is not necessary.