HNHacker News
TopNewBestAskShowJobs

mastahyeti

534 karma · joined February 28, 2012

submissionscomments
mastahyeti··on Soft U2F: A software-based U2F authenticator for macOS
Which device are you using? With U2F, the browser doesn't send the name of the site to the authenticator.
mastahyeti··on Soft U2F: A software-based U2F authenticator for macOS
From my testing of several hardware U2F implementations, the test-of-user-presence (touching the button) unlocks the device for an amount of time. During this time multiple authentication/registration will succeed without further user interaction. Even without this behavior though, hardware tokens don't indicate which site your authenticating with. Malware could just make an authentication request right as some user action triggers a legitimate authentication request.
mastahyeti··on Soft U2F: A software-based U2F authenticator for macOS
I've only tested on Sierra, so I'm not terribly surprised that this doesn't work. Would you mind opening an issue so I can help debug? https://github.com/github/SoftU2F/issues/new
mastahyeti··on Soft U2F: A software-based U2F authenticator for macOS
It is :-)
mastahyeti··on Soft U2F: A software-based U2F authenticator for macOS
You still have to configure TOTP (SMS or App) 2FA before you can add a U2F device. That might change in the future.
mastahyeti··on Soft U2F: A software-based U2F authenticator for macOS
My understanding is that the FF softtoken was intended to be temporary while they worked on their HID support. That might not be the case any longer though.
mastahyeti··on Soft U2F: A software-based U2F authenticator for macOS
I think the greatest practical threat to TOTP is phishing. U2F, regardless of where keys are stored, binds a keypair to an origin. Only authentication requests from `github.com` can use the `github.com` keys. For my money, any U2F implementation is a win over any TOTP.
mastahyeti··on GPG signature verification
There is a known bug where leading whitespace can cause the key to not be parsed. Also, check that you're only trying to upload a single key, and not your entire keyring.
mastahyeti··on GPG signature verification
It shouldn't be necessary to push a new signed commit for old ones to start showing the "verified" badge. We do cache some of our templates though, so it may take a while for some pages to be updated.
mastahyeti··on GPG signature verification
GitHub Desktop doesn't support commit/tag signing at this point. Sorry.
mastahyeti··on Subresource Integrity
It's only included for browsers that support it. That's Chrome>45 and Firefox>43.
mastahyeti··on Subresource Integrity
This isn't a concern with our implementation because a hash of the asset bundle is also included in the URL. This is a pretty common cache-busting technique for static assets and lets you send more aggressive cache directives to the browser.
mastahyeti··on Subresource Integrity
Thanks. I updated the post and opened a PR to fix the README on sprockets-rails. https://github.com/rails/sprockets-rails/pull/273
mastahyeti··on Two-factor Authentication
We just added support for India. Try again.
mastahyeti··on Two-factor Authentication
There is a setting for a fallback number on https://github.com/settings/two_factor_authentication/config...
mastahyeti··on Two-factor Authentication
TOTP is standardized. http://tools.ietf.org/html/rfc6238
mastahyeti··on Introducing GitHub Sudo Mode
This is a separate issue. We just added the Private Token feature on the /settings/applications page. This is essentially a password, so we wanted to make sure that it required password confirmation. This will be behind sudo mode later today hopefully.
mastahyeti··on Introducing GitHub Sudo Mode
Adding a new email address is now behind "Sudo Mode"...
mastahyeti··on Introducing GitHub Sudo Mode
We use Rails CookieStore. The cookie does change when you enter sudo mode, so a session would have to be compromised while you are in sudo mode.
mastahyeti··on Introducing GitHub Sudo Mode
Just shipped it a couple minutes ago. Previously, we only had password confirmations for adding Public Keys.
mastahyeti··on Nosniff header support coming to Chrome and Firefox
It would, but it would create other problems also. If I were to link to a raw.github.com URL on HN, it would be disallowed because the Referer header would be "incorrect".
mastahyeti··on Never again be thwarted by restrictive “guest” wifi (e.g. on buses or airplanes)
Alternative this is much more sneaky: run an obfuscated tunnel. Most firewalls will allow egress DNS for example, so tunnel your TCP over DNS. This will also allow you to sneak out of pay-for wifi setups like at the airport. http://analogbit.com/software/tcp-over-dns
mastahyeti··on Never again be thwarted by restrictive “guest” wifi (e.g. on buses or airplanes)
`ssh -D 1337 me@mysite.me` <-- Does dynamic port forwarding (SOCKS proxy)...