14,768 karma · joined June 27, 2008
Author of Password Authentication for Web and Mobile Apps (https://dchest.com/authbook/)
Based in Montenegro.
Email: dmitry@codingrobots.com
X: @dchest Bsky: dchest.com Mastodon: mastodon.social/@dchest
Website/blog: https://dchest.com
GitHub:
https://github.com/dchest
https://github.com/coding-robots
(CC-BY) All my comments on HN are licensed under Creative Commons Attribution 3.0 license.
Agree with your other points, the whole passkey story is undeveloped and unclear yet.
After entering your username, you select an option to use your other device to sign in and scan a QR code with it.
No, they can be synched. There are different types of passkeys, synched and device-bound (for YubiKeys, etc.)
Hope this clears up the confusion (haha).
macOS virtual memory works well on swapping in and out stuff to SSD.
Probably should just use llama.cpp server/ollama and not waste a gig of memory on Electron, but I like GUIs.
(Also, ChatGPT usually uses emdashes without spaces.)
https://fossil-scm.org if you don't care about git.
Huh?
I could never imagine Apple employees doing it like this. I knew they had to have discussions about the scare screen, but come on! This is pure evil.
https://www.reddit.com/r/crypto/comments/7imejm/monthly_cryp...
I've tried to take a stab at this problem, but was not sure if it worked at all:
https://gist.github.com/dchest/50d52015939a5772497815dcd33a7...
It's a modified BuzHash with the following changes:
- Substitution table is pseudorandomly permuted (NB: like Borg).
- Initial 32-bit state is derived from key.
- Window size slightly varies depending on key (by ~1/4).
- Digest is scrambled with a 32-bit block cipher.
I also proposed adding (unspecified) padding before encrypting chunks to further complicate discovering their plaintext lengths. Glad to see I was on the right track :)
But you're correct - they don't mess with it, they slightly and mostly invisibly improve it, and someone who learned it in 80s could use it without problems today.
https://www.youtube.com/watch?v=uqehwCWKVVw
https://www.bloomberg.com/ux/2017/11/10/relaunching-launchpa...
https://www.bloomberg.com/company/stories/how-bloomberg-term...
https://www.bloomberg.com/company/stories/designing-the-term...
https://github.com/microsoft/go/blob/microsoft/main/patches/...
Upstream Go tricks Windows into enabling long path support by setting an undocumented flag in the PEB. The Microsoft Go fork can't use undocumented APIs, so this commit removes the hack.
So, even if they fork something, they have to strictly follow this guideline and remove undocumented API usage. I wonder if this only applies to Windows APIs though.
macOS Sonoma 14.6.1 on M1 = 0
iOS 17.6.1 = -0
WTF.
What was important during the times when we didn't know how to generate random numbers on computers, perhaps shouldn't be as important today?
Otherwise, you'd want longer outputs.