They _do_ suggest using ECC, but in practice ECC support is super sporadic, and a lot of products charge extra for it.
160 karma · joined April 8, 2015
They _do_ suggest using ECC, but in practice ECC support is super sporadic, and a lot of products charge extra for it.
It wasn't overly complicated from a technical perspective, but when there were forms with say 50-100 different inputs and dozens of state transitions, it was a mentally taxing experience every time to try to maintain the data model and state machine in my head when debugging or introducing changes.
For me the introduction of hooks was amazing as it's allowed us to strip most of the redux state management in favour of managing state with hooks inside of functional components. We still use redux for global application state, but there are also hooks for interacting with that redux state too.
We effectively went from class-based components in react-redux with say 500 LOC in each class, 500 LOC in each action file, 500 LOC in each reducer file, all the way down to about 700 LOC in each functional component file.
I do agree though that debugging sucks. It's incrementally getting better, but it's got a long way to go.
I can appreciate why the pendulum swung hard against ads - it's incredibly hard to differentiate between real and fake ICOs, and we're seeing that again with the defi craze at the moment. It's just made it so much more expensive as an emerging company to try to sell services in this market even when you _aren't_ trying to sell a coin.
For web-based certificate authentication, if you follow instructions for setting up CACs, then you're usually good (but you have to just ignore the US Military specific stuff): https://militarycac.com/macnotes.htm
Yubico also provide some instructions for each platform: https://developers.yubico.com/PIV/Guides/Smart_card-only_aut...
https://developers.yubico.com/PIV/Guides/SSH_with_PIV_and_PK...
In the end though a centrally managed authentication solution isn't really easy a quick and easy set up for *nix or Mac, unlike Windows with Active Directory. Perhaps in the future something better will come along.
And the same applies with iOS and Android - I've seen some pretty hacky products where they'll interface with smart card readers onto phones do things like authentication to websites or email encryption, but in the end you had to use the vendor's browsers/mail clients instead because only they could handle the integration with the PIV cards. YubiKeys can now connect to phones too, but you've gotta have the right combination of YubiKey and phone to get that connectivity going - and you're still limited to what the apps on the phone actually support.
I've got my own slightly different style of note taking that works really well for me, but only when I start to work on multiple projects simultaneously and I need a way to track tasks across them all. When I fall back to one or two projects, then my note taking needs disappear. I joined the fray anyway and turned it into a web app so I could at least have something that _I_ want: https://screwnotes.com
We who understand what's going on know it's perfectly fine, but it's hard to get that message across. Just like the first time you try to explain what a hash is to a non-technical person.
I think it's a good study in game theory at the least.
My take on the E8: https://blog.congruentlabs.co/essential-eight-essentially/
That said though once I know which marketing tools are effective, there's nothing more that GA does that CloudFlare couldn't just tell me anyway (i.e. am I getting more or less traffic) and I'll probably drop it as it's one less dashboard to look at - like you said that conversion to subscriber _is_ the ultimate metric for success.
Microsoft also provide pretty cheap deals for startups if they want some basic infrastructure for the office (excluding the hardware of course), so it's not entirely out of the equation on the licencing side either.
Really small teams typically will find U2F auth easiest to work with in the beginning, and then after hitting like 20 users they'll bump into problems like a large enough number of connected systems that they need to manage 2FA for.
I'll have to add it in to the article :)
Are you heavily SaaS based for the tools you use in your startup, or do you have some on-prem infrastructure? That'll kind of dictate which path you should go down for provisioning the keys to your users. Our product will be perfect if you're using AD & a Microsoft CA internally (or are willing to set one up), as you could then just set up 3 YubiKeys for each employee, all loaded with certificates for authentication.
And, should one be stolen or an employee leaves, just revoke the certificates on it to kill the access immediately.
Any path you go down should really still only take a bit of time upfront and almost nothing longer term, unless your team grows fast.
You can also hit me up at tim@congruentlabs.co and I can give you more advice if you don't want to mention specifics publicly.
If your business is seeking "higher" assurance (yes, assurance levels are very subjective) then certificate-based MFA can meet the needs better. Or, if your business is working with sensitive data/systems, phones may be banned from the office (e.g. military, intelligence, banks, etc.).
And usually it's twice what they charge, because you need a backup device to handle losing the first one.
I'd like to see a competitor come out with a combo PIV card & FIDO device. At least from the enterprise perspective it would cover 99.9% of MFA situations. And the majority of my personal uses of YubiKeys.
brew install pam-u2f
mkdir -p ~/.config/Yubico/
pamu2fcfg > ~/.config/Yubico/u2f_keys
<Press the U2f device>
cat ~/.config/Yubico/u2f_keys # should output <your username>:<really long hash>
In /etc/pam.d/screensaver
Add to the top:
auth sufficient pam_u2f.so
In /etc/pam.d/authorization
Add to the top:
auth sufficient pam_u2f.soThere are products like Silverfort (https://www.silverfort.com/) that can handle agentless auth, and might be able to do that kind of MFA inside an RDP session. But, products like this usually require some 3rd device (i.e. your phone) to perform the MFA action, which is kind of not really just a simple WebAuthn logon...
Firebase for hosting/serverless funcs.
G Suite for collaboration.
Bitbucket for Repos (they had better enterprise-y tools for free, not sure if Github now is at parity).
Notion for task lists and product specs.
Stripe for payments.
Twilio for SMS.
Cloudflare for caching/DNS.
And, now that COVID-19 has pushed a lot of businesses to remote work, there's a greater need for MFA-enablement for these remote access solutions, and quickly.
Our blog has an announcement post too, which may help you understand how our product works too: https://blog.congruentlabs.co/introducing-signata-enterprise...
Feel free to ask me any questions here or on our blog post.
The one I gravitate towards now is MUI - it's got the easiest drop in to an existing project, and the most predictability.
Semantic seems to be stuck in a weird place where the main project is barely maintained and a fork (Formantic) is superior, but there's no React version for the fork so you have to make your own React components if you want their new features.
I liked Ant but the integration into existing apps took far more effort than I would've liked. In the end with Ant I gave up and made a fresh project and shifted my existing codebase across.
The only thing I wish MUI had that Semantic was superior in was forms - Semantic has a far better built-in form component, including error/warning/success & loading states out of the box.
The app itself is something tightly coupled to having an account to operate (so no data is lost), but I might try adding in an interactive demo on the landing page so you get that feel of how it works straight away.
Just adding the URL here so it becomes a hyperlink to be clickable at least.
This project was an interesting experiment in building on Firebase. Currently the whole app is almost entirely client-side, with access to data controlled by firestore rules. The Stripe Checkout service handles subscriptions, and successful payments flow down to the user through a hook trigger from stripe followed by a bunch of firestore onChange event listeners.
This may change if users want particular features, but for now I'm amazed at how simple (from the perspective of my codebase) it was to string all of these components together.
For me personally I found getting any software development job I could, even though they're really dull large enterprise forms-over-data jobs, gave me a massive boost in development ability and experience, especially because I was thinking about dev for 8+ hours straight every day.
Will the Choice 1 job make you work less hours? If so that frees up more time to work on dev projects on the side, and you could use that to your advantage.
There's more detail about the release here: https://medium.com/@congruent_tim/signata-release-candidate-...
I really do want them to work fully though so I can extend my product to mobile too. I know a lot of people now that have gotten rid of their computers and just use their phones for everything.