HNHacker News
TopNewBestAskShowJobs

anderspitman

1 karma · joined September 26, 2023

I've moved over to https://news.ycombinator.com/user?id=apitman
submissionscomments
anderspitman··on Why even let users set their own passwords?
> Or the third to to illustrate the argument in another context.

This is still case 1.

I actually agree with you that some people with bad security habits will never change their behavior, but do you really feel that someone using passwords in a notebook because that's what they're comfortable with is in the same class of behavior as someone addicted to nicotine?

Feel free to have the last word here. 1 on 1 HN threads more than 3 deep rarely result in productive conversation. Cheers

anderspitman··on Why even let users set their own passwords?
> For one thing, I now have to be logged in on my mail on the device I am using, and that means if the device is unsafe, I am exposing far more of a risk that way

What's preventing you from getting the email code from another device?

anderspitman··on Why even let users set their own passwords?
I agree social SSO is the gold standard in terms of UX, but it's also a privacy disaster. What we really need is for someone to make a Let's Encrypt for login. A nonprofit that provides SSO in a privacy respecting manner.
anderspitman··on Why even let users set their own passwords?
This made me chuckle, and it honestly might be true.
anderspitman··on Why even let users set their own passwords?
Other than the chance the email is delayed, and the generally subpar UX, what are your concerns with emailed codes? This is an honest question, as this is the primary login method I settled on for all my services after spending a good chunk of time thinking about this.
anderspitman··on Why even let users set their own passwords?
I find there are generally two reasons people use analogies. The first is to make a concept easier to understand. The second is to subtly change what is being argued in order to make their position seem stronger. I did the second for years without realizing what I was doing, and still fall into the trap.
anderspitman··on Why even let users set their own passwords?
This is interesting. I'm not sure how I feel about it from the perspective of the user understanding what they're consenting to, but it's secure and the flow is simple.

I don't support passwords on any of my services. Emailed magic links and SSO are the encouraged methods, even with all the tradeoffs. I've considered allowing users to generate tokens similar to OP, but some percentage of them will be emailed around and pasted into phishing sites etc.

But something like this could work as an option, especially if it could integrate with a couple popular password managers as well. Not sure if that's even possible.

anderspitman··on Why even let users set their own passwords?
I read OP's mention of third party cookies as an example of browsers supposedly moving in a more privacy focused direction, not as being related to authentication.
anderspitman··on Why even let users set their own passwords?
Is the cost of getting phished really lower than the cost of learning a password manager for your dad?
anderspitman··on Web Environment Integrity API Proposal
> you have to fork the entire web

That's exactly what we need to do. More specifically, we need to decouple the app web from the document web. Most of the value of the web to society lies in text, images, and video, in that order. We need a version of the web refocused around basic content with a spec simple enough for a small team to implement a browser for. A subset of HTML/CSS is probably the only way to succeed, since sites would need to work with current browsers. I think a few HTML tags + flexbox + fonts + colors would get you pretty far.

anderspitman··on Ask HN: What hardware are you running for your home server?
My recommendation would be using an old laptop you have laying around, or picking up a used Lenovo T series laptop for 300-400USD on ebay. Try to find a CPU with 10000+ score on cpubenchmark.net, and 16GB+ memory. Plug in whatever storage you want with USB.
anderspitman··on Firejail: Light, featureful and zero-dependency security sandbox for Linux
The aforementioned user namespaces and accompanying complexity come into play here, and you're going to take a performance hit using FUSE for fs and slirp for networking. I'm not saying these are bad tools, just that we need something simpler without sacrificing performance.
anderspitman··on Self-hosted photo and video backups directly from your mobile phone
> Because nobody outside of HN is going to install software on an old phone or laptop. But they'll buy a $30 Box.

How do you figure?

Also you may be interested in checking out https://kubesail.com/homepage and https://privaterouter.com/

anderspitman··on Self-hosted photo and video backups directly from your mobile phone
That's fair. Personally I'd like to see (and am working on) more solutions that make it realistic for everyone to run their own single user instances. Selfhosting shouldn't be any more difficult less secure than running an app on your phone.
anderspitman··on Self-hosted photo and video backups directly from your mobile phone
With the caveat that your VPS provider can access all your data should they choose to.
anderspitman··on Self-hosted photo and video backups directly from your mobile phone
Is there anyone in your family that you really want to have access to all your photos? Not even referring to just NSFW stuff. If your answer is "as the admin I'm the only one that can access everything" then consider the question from your family's POV. Not trying to discount your point only pointing out that single user and e2ee implementations have some value.
anderspitman··on Self-hosted photo and video backups directly from your mobile phone
Why does it need to be a new separate physical device, instead of just software installed on an old phone or laptop?
anderspitman··on Container Training
I used to feel like docker wasn't worth the complexity but I've come around. It strikes a pretty dang good balance. Is kubernetes worth learning if you don't use microservices at work?
anderspitman··on Purchase and manage domains directly through Bluesky
While there's some truth to this, it's more of an incidental problem with DNS than an intrinsic one. There's nothing preventing registrars from simplifying their UX to target average customers, including multi-year registrations and ample warning systems.
anderspitman··on Purchase and manage domains directly through Bluesky
See here: https://blueskyweb.xyz/blog/4-28-2023-domain-handle-tutorial
anderspitman··on Purchase and manage domains directly through Bluesky
I agree this might confuse users initially, but we need to normalize owning and using domains. We also need to make it much easier and this is an important step.
anderspitman··on Ask HN: Could you share your personal blog here?
https://apitman.com

Main claim to fame is that you can read my blog with curl:

curl https://apitman.com/txt/feed

Or netcat:

nc apitman.com 2052 <<< /txt/feed

anderspitman··on Purchase and manage domains directly through Bluesky
Lot of negative comments here but IMO this is huge. The best way to keep anything commercial good in the long term is competition, and the only way to have competition with web services is if users can go somewhere else, which requires a portable identity/username and open protocols. Bluesky is currently the only platform offering both in a convenient package. Even Mastodon doesn't make it this easy[0].

[0]: https://github.com/mastodon/mastodon/issues/2668

anderspitman··on Google and HTTP (2018)
Your browser is probably blocking it for not using HTTPS /s

https://web.archive.org/web/20230704151648/http://this.how/g...

anderspitman··on Google and HTTP (2018)
While I do think this is an important conversation to have, and part of an even more important conversation about how much control Google/Chrome has over the web, I grudgingly disagree. I think signed data is table stakes for any communication over the internet, and encryption in most cases.

Let's Encrypt/ACME make encryption accessible enough in theory. That said, we're not there yet. Domain names still need to be easier to buy and use, and more software should use ACME by default (like Caddy does).

anderspitman··on Bill C-18: Google to remove news links in Canada over online news law
The web may never be better than it was about 5 years ago, and that makes me very sad
anderspitman··on Fast machines, slow machines
Ok this is awesome
anderspitman··on Why use OpenID Connect instead of plain OAuth2?
I think it mostly just evolved that way. OAuth started on the web and if you're using a browser anyway you might as well take advantage of HTML/JS rendering for the UI and cookies for secure storage.
anderspitman··on Why use OpenID Connect instead of plain OAuth2?
I would be very interested to see an implementation that doesn't. And I'm not being sarcastic. Even the device flow has you open a browser on another device.
anderspitman··on Why use OpenID Connect instead of plain OAuth2?
I do think it's pretty amazing that a basic modern authorization system essential has a hard dependency on a 20+ million lines of code web browser, even for native apps. And mostly just because we need a central location to store auth cookies. I'd love to see a stripped-down "auth browser" that has no job other than rendering basic style-free forms (maybe even declared in JSON) and storing cookies. Problem is you have to get the big boys to stop requiring JavaScript for their auth flows.

That said, after doing a decent amount of implementing OAuth2/OpenID Connect, the core profiles are actually pretty reasonable and about what you would want to do if you were starting from scratch. The trick is making sense of all the optional stuff. There have been some efforts[0] to improve that.

The part I've never been able to figure out is why does OAuth2 use tokens at all, rather than generating a key pair and sending the public key with the initial auth request, then signing subsequent requests?

[0]: https://fusionauth.io/articles/oauth/differences-between-oau...

← PreviousPage 2 of 34Next →