HNHacker News
TopNewBestAskShowJobs

skion

34 karma · joined April 9, 2013

Tech lead @ WatchMouse
submissionscomments
skion··on Show HN: We made a WordPress plug-in to replace Clef
Yes, you can filter by email address or email domain. It's one of the things we get for free by using WordPress Social Login.
skion··on Show HN: We made a WordPress plug-in to replace Clef
Hi HN,

We received a number of requests from (ex-)Clef users asking if we would perhaps build an authentication plug-in for WordPress, now that Clef is sunsetting.

This is our first version: We opted to use a proven extension as a base, and collect feedback. Then use that to develop a stand-alone plug-in in the future.

Tell us what you think!

- Pieter

skion··on SecureLogin Authentication Protocol 1.0
There are probably several angles on this. One is to let our Authentiq ID mobile app support and sign in to SecureLogin sites. Another to let websites that use Authentiq automatically support sign-ins with SecureLogin. These look feasible at first sight.

A third, replacing our current auth flow with SecureLogin indeed isn't likely to work for reasons you mention.

skion··on SecureLogin Authentication Protocol 1.0
Yes! As a site admin in today's world, you should indeed not want to store passwords. Or even personal data for that matter.

I applaud this initiative since it lists exactly the reasons why we started Authentiq: Decentralization, usability, privacy, safety for end users (which is very different from merely offering security features that most people don't use).

Authentiq is similar in goals and architecture, yet with a more comprehensive feature set, since we aim to support existing standards (like OIDC) as the integration point for developers, and offer a more complete mobile identity to end users so that the site owner doesn't need to store those details either.

That said, I'm very keen to see if we can add support for the OP's authentication protocol soon. Check us out here if interested: https://www.authentiq.com/

skion··on Chalice: Python Serverless Microframework for AWS
Or any server side store, maybe DynamoDB.
skion··on Dutch government says no to backdoors, grants $540k to OpenSSL
You probably mean €500 thousand, not million.
skion··on 5 out of 7 .io nameservers appear to be down
This is indeed a typical configuration for authoritative name servers.
skion··on One Less Password
"Passwords might be useful for someone who works on a public computer at the library."

Key loggers anyone?

skion··on TweetNaCl.js
You guys are right of course; I was looking at the C version.
skion··on TweetNaCl.js
For one the fact that (the author of NaCL) Daniel Bernstein is backing it.
skion··on Ask HN: How can I sustainably run a website without charging a fee?
> And always unbundle DNS contract from hosting contract, so you can switch fast, in case your hosting provider sucks.

With Hetzner that is indeed a necessity. They sell cheap iron, but don't expect any support from them and be prepared to move out quickly.

skion··on Self-Destructing Cookies
So, what other extensions can we ditch now?

I really like the UX of SDC; are Disconnect or DoNotTrackMe just clutter, or adding value still?

skion··on Pervasive Monitoring Is an Attack
Curious if Analytics and Real User Monitoring (RUM) companies feel addressed by this memo. And whether the IETF intended that or not.
skion··on Your REST API should come with a client
Agree with this, even if just done in one reference language. It is much easier for the community to port an existing binding to other languages, than to implement a new client from scratch.

Two notes:

2) No need to mask requests with a HEAD; a GET can also return a 304 directly.

6) De-duplication of calls: Any method except POST should be idempotent already, hence also a retry-on-error is trivial in those cases.

skion··on Linux 3.14 out
I think that would then be the first time that Ubuntu LTS is piggybacking on an LTS kernel. With 3.12 already 6 months old that seems unlikely to me given Ubuntu's usual attempts to support modern hardware.
skion··on Linux 3.14 out
Not according to http://www.phoronix.com/scan.php?page=news_item&px=MTY0NTc

No risks for an LTS release I guess.

skion··on Firefox 27 Released
I just fixed that by setting:

  security.tls.version.max = 3
  security.tls.version.min = 1
  security.ssl3.rsa_fips_des_ede3_sha = false
in about:config, after which it also said "Probably good" for FF26.
skion··on Telegram - secure, free messaging
"As a result, Telegram is the fastest and most secure messaging system in the world."

That's a very bold and yet to be proven statement. Probably any crypto expert would know better than to say that.

This paragraph exactly pin points the problem with being a cryptographic nobody.

PS. I do like their icon designer.

skion··on Piercing Through WhatsApp’s Encryption
I love how exactly this mistake is covered in detail in the first week of Dan Boneh's crypto course:

  https://class.coursera.org/crypto-008/class
The Russians made the same mistake in WWII, but Whatsapp shows the relevance today.
skion··on Show HN: goworker – a faster, Resque-compatible background worker
And so the age starts where we rewrite in Go for performance all cool things Ruby, Python...
skion··on The Great Language Game: How many languages can you distinguish between?
It'd be great if the multiple choices appeared a few seconds late, giving some time to let your senses guide you.
skion··on Create a font from your own handwriting
For me that would result in the ugliest font ever.
skion··on Cool water vapor effect in HTML5 Canvas
Gah! It does look cooler in a geeky way now. Nice!
skion··on European roaming charges will end in 2014
This proves again that Neelie gets it.
skion··on Two.js
Awesome, I can see the reincarnation of animated banner ads...