HNHacker News
TopNewBestAskShowJobs

pandorobo

17 karma · joined August 7, 2025

submissionscomments
pandorobo··on AI Adoption Rate Trending Down for Large Companies
Does it mean the number of companies newly adopting AI is dropping? That could mean that its just saturated so of course it would drop? Unless I am reading this graph wrong and it's actually the same companies that are now no longer adopting AI?
pandorobo··on The beauty of a text only webpage
Color contrast is also important. Like actually putting a readable header on the page. ('^_^)
pandorobo··on Emailing a one-time code is worse than passwords
Clearly I didn't misread that. It's literally the very first bullet point?
pandorobo··on Emailing a one-time code is worse than passwords
The first bullet point mentions phone number.

- Enter an email address or phone number

Thats not just email, that's also SMS.

pandorobo··on Emailing a one-time code is worse than passwords
Thats simple a lie or you didn't read the article.

The very first bullet point states: Enter an email address or phone number

That insinuates email OR SMS.

It doesn't just mention email only.

pandorobo··on Emailing a one-time code is worse than passwords
Specifically they are referring to synced passkeys (passkeys generated by services like Google password manager/1Password/Apple and are linked to that account).

Because these passkeys are stored in the Cloud and synced to your providers account (i.e. Google/Apple/1Password etc), they can't support attestation. It leads to a scenario where Relying Parties (the apps consuming the passkey), cannot react to incidents in passkey providers.

For example: If tomorrow, 1Password was breached and all their cloud-stored passkeys were leaked, RP's have no way to identify and revoke the passkeys associated with that leak. Additionally, if a passkey provider turns out to be malicious, there is no way to block them.

pandorobo··on Emailing a one-time code is worse than passwords
Very short, badly written article. It can't even describe phishing correctly... At least label your threat model correctly.

While the premise is correct -- it's easy to complain but the author also provides zero recommendations on what is a better form of MFA.