60 karma · joined December 2, 2009
At that time, I inspected the registration request Google sent to Chrome and found it was passing a private option that Chrome recognized. According to what I found in web searches for it, the option created a legacy U2F key, and they needed to do that because there were existing Android devices that they could not upgrade and that would not support log-in with WebAuthn keys.
In comparison to those, Google’s support seems better. It worked, was transparent about what was going on, and gave me the option to create the key on either the device I was using or another one if I wanted. The one hitch was that when I already had a 2FA key on the same platform authenticator, it just said I already had a registered key on this device and didn’t do anything. I would have expected some sort of upgrade flow for people who previously registered their devices for 2FA, or at least to more directly tell me to delete the existing security key on the device (which is what I did, and which worked).
Kayak shows a "Set up passkey" button with no indication that I already have one or any apparent way to revoke the existing one. Very bad.
Shop Pay does clearly show what passkeys exist, and allows revocation and addition. However, when I try to add one on Chrome on macOS, it only lets me set up a Chrome passkey. (These don't sync between devices. It should have let me set up whatever kind I wanted.) Also, the list just indicates passkeys by what browser type last used them, like "Chrome on macOS." So according to the list I have two passkeys that are just described as "Chrome on macOS" and they are indistinguishable.
I can't imagine recommending anyone try this unless they are consciously an early adopter.
1. PayPal: I could not find an option to do it on either a phone or a web browser even after reading the linked instructions. Perhaps it thinks neither device is compatible (they are).
2. Microsoft: After eventually I found an option inside its settings to go "Passwordless" which sounds right, it instead tries to ram an app called Microsoft Authenticator down my throat. On passkeys.directory I check the instructions for insight and I see it says "All you’ll need is a device running Windows 11 and the Microsoft Edge browser." So much for cross-platform standards. If I had been using Windows 11, I assume I would have still needed my password to log in on my phone or anywhere else.
3. Kayak: Works fine, although the log in option is not as discoverable as it could be (I had to click to log in via email, and then click in the email field, and then an option appeared).
4. Shop Pay: Works fine, the only one about which I have no complaints.
I never worked through the details, and I'm not a category theory partisan, but I think that's what this is: https://ncatlab.org/nlab/show/fully%20formal%20ETCS
It worked fine for me when I was careful to stay within what it actually supported, bearing in mind it’s a fast and rough implementation not something for production use.
I think this article gives a better understanding of what’s actually happening: https://www.kilpatricktownsend.com/Blog/fintech/2020/8/Banki...
In brief, if you want to set up a fintech company now, you may need to comply with 50 states laws. That isn’t just being basically law-abiding, but involves serious compliance work. I started looking up licenses for Square as an example and got bored after the first few as state web sites are all different and inconvenient:
https://dbo.ca.gov/2018/04/02/square-inc/
https://www.dob.texas.gov/entity-search/entity-detail?bid=10...
http://www.dora.state.co.us/pls/real/BIDS_Search.Individual_...
Each of those, and also for all the other states, involved satisfying a state agency that Square was adequately solvent and would comply with a host of laws. You may notice that the first two have license numbers and the numbers are small. That says something about how easy it is to get the licenses. This is a meaningful part of these companies’ moats.
The OCC action that New York is challenging is to provide a federal alternative structure in which companies would get one federal license and receive nationwide permission to engage in a host of banking-like activities. They would still be able to get state licenses instead, if they wanted. This system (of picking between a state and federal regulator) is called dual chartering and has existed in the banking industry for a long time; it establishes a check on both state and federal regulators by allowing the regulated entity to switch to an alternative regulator.
If you do encounter an issue it will be more work to deal with, because you both have to figure out the underlying issue and then figure out how to fit that into the Nix way of doing things.
The biggest factor is handling downloaded pre-built binaries that assume various libraries will be in typical locations. Those generally require patchelf and then they work fine. I would only recommend NixOS for now for people who are willing to tinker a bit and learn how it works.
(I haven't tried everything, so I don't have firsthand knowledge that they all work equally smoothly.)
The TPM is a security feature--you don't have to use it. I have not used it on my laptop but I see from the documentation that it is different from some other trusted computing systems in that the end user controls the keys and what is loadable, not the vendor.
We're a marketplace that connects people with studios and gyms so they can take yoga, martial arts, or other classes near them. We have a solid working business model and are growing. We're hiring for backend, frontend, full-stack, and infrastructure roles.
I'm a technical lead in SF and happy to talk to anyone on either coast. Contact me at (my HN username)@classpass.com or apply directly at https://classpass.com/jobs/openings.
Some more information is available at http://www.cendi.gov/publications/04-8copyright.html#317.