23 karma · joined June 12, 2018
I want my decoders to essentially do 2 things:
1. Transform received data into a data structure that is best suited for my app. This might involve converting lists to objects, objects to sets, parse dates etc.
2. Only succeed on valid data
This way, my application never has to deal with bad data. Also, I get to design the data structures I use, not the APIs I use. By only validating and not transforming, you are pushing more advanced validation further away from where the data was received (since you'll need to transform the data at some point anyway).
As for libraries, I want composable parsers. For TS I'd probably use: https://github.com/paperhive/fefe/
https://lexi-lambda.github.io/blog/2019/11/05/parse-don-t-va...
I really like Elms way of Json decoding for this.
If you're interested, you can probably get an invite from @supermario on the elm slack, or on: https://lamdera.app/
Disclaimer: I'm not affiliated with the project, but I've met Mario in person and he's a cool dude with great ideas ;)
That's not true, it just uses the new way to ask for permissions. E.g. when you want to scan a QR code it requires the camera permission. But it only asks at that moment, not upfront as older android apps used to do
In terms of technology it's of course completely different.
> Not everyone has a million devices.
I don't think that's fair. With 3 devices you're perfectly ok. Or even with only 2, if you also use a "key box" (gives you one "device" more at the cost of having to remember a password).
I don't wanna push you, just wanna give you some things to think about. As long as you use strong and unique passwords everywhere you're good.
Also, it's not a big problem if one of your devices dies, as long as you paired enough devices you won't lose any passwords.
The only exception is at the start when there are no passwords stored yet.
In short, a new device doesn't have the same power as the others from the start, first new keys have to be generated which can only happen if you are able to unlock your passwords.
So just don't setup both the Firefox and Chrome extension and you're golden.
So don't do it.
That's true. I suppose it's a trade off between protection against lost vs. smaller attack surface.
> Since there's no master key, one has to only compromise the OS to get at everything
That's wrong, compromising one device doesn't give an attacker anything useful. Only if two or more devices have been compromised can passwords be decrypted. But in any case, I think if your device is compromised you might be in bigger troubles anyway. E.g. if an attacker controls your device, ransomeware might be easier and more lucrative to them than going after more devices to hunt for passwords.
That's why it's a very good idea to pair as many devices as you can, e.g. an old phone, your work PC, etc.
This way you're pretty save from any loss.
In general, if you save your passwords with security level N (meaning you need N devices to unlock), if you lose all but N-1 devices, you lose access. You can also add a "key box", which gives you one more "device", but requires you to remember a password.
This is my first time posting something to HN, so please be kind.
I wanted to show what I’ve been working on for the last 6 months:
NoKey, a password manager without a master password. Instead, you can unlock your passwords by confirming from another device. E.g. if you need a password on your PC, you only have to confirm this on your phone. No need to remember any passwords!
The vast majority of the code is written in Elm and it’s fully open source.
There is a browser extension for Chrome and Firefox and an Android app. The application is only useful with at least two devices, so to really test it out, you’ll have to install it on two devices. There is no iOS version and the web app doesn’t work on Safari either (it's missing some stuff from the Web Crypto API), sorry!
Any feedback or questions are greatly appreciated!