HNHacker News
TopNewBestAskShowJobs

timothy-quinn

160 karma · joined April 8, 2015

Co-founder of Congruent Labs --- Author at: https://blog.congruentlabs.co/ --- PM for YubiKey MFA: https://enterprise.signata.net --- PM for YubiKey Cryptocurrency: https://signata.net --- PM for: https://screwnotes.com --- [ my public key: https://keybase.io/timothyquinn; my proof: https://keybase.io/timothyquinn/sigs/BSbGlvz_jyn9wc0z9XVfjpKYR0tcKGm62pWHWwejxKQ ]
submissionscomments
timothy-quinn··on Stop using RSA (2019)
This is how most critical articles of crypto end. They criticise the algorithm or system, and then don't offer much in the way of solutions.

They _do_ suggest using ECC, but in practice ECC support is super sporadic, and a lot of products charge extra for it.

timothy-quinn··on Algebraic Effects for React Developers
The value of hooks became apparent to me after working with a very large react-redux application. It was so large and the forms had so many elements that the capture of data, testing, and subsequent state management in redux was enormous.

It wasn't overly complicated from a technical perspective, but when there were forms with say 50-100 different inputs and dozens of state transitions, it was a mentally taxing experience every time to try to maintain the data model and state machine in my head when debugging or introducing changes.

For me the introduction of hooks was amazing as it's allowed us to strip most of the redux state management in favour of managing state with hooks inside of functional components. We still use redux for global application state, but there are also hooks for interacting with that redux state too.

We effectively went from class-based components in react-redux with say 500 LOC in each class, 500 LOC in each action file, 500 LOC in each reducer file, all the way down to about 700 LOC in each functional component file.

I do agree though that debugging sucks. It's incrementally getting better, but it's got a long way to go.

timothy-quinn··on PayPal to allow cryptocurrency buying, selling and shopping on its network
Thanks to this I've found building a product in the cryptocurrency market has been the most challenging for applying typical online marketing strategies - I've exhausted most avenues of advertisement - basically the only tools left are the more expensive sponsorship arrangements as every advertising platform will instantly reject your content.

I can appreciate why the pendulum swung hard against ads - it's incredibly hard to differentiate between real and fake ICOs, and we're seeing that again with the defi craze at the moment. It's just made it so much more expensive as an emerging company to try to sell services in this market even when you _aren't_ trying to sell a coin.

timothy-quinn··on Using PIV Cards for Every Business
Support for PIV cards on Linux/Mac is kind of sporadic, and very much DIY. In most cases authentication gets kind of tricky because you need to set up everything yourself on the workstation.

For web-based certificate authentication, if you follow instructions for setting up CACs, then you're usually good (but you have to just ignore the US Military specific stuff): https://militarycac.com/macnotes.htm

Yubico also provide some instructions for each platform: https://developers.yubico.com/PIV/Guides/Smart_card-only_aut...

https://developers.yubico.com/PIV/Guides/SSH_with_PIV_and_PK...

In the end though a centrally managed authentication solution isn't really easy a quick and easy set up for *nix or Mac, unlike Windows with Active Directory. Perhaps in the future something better will come along.

And the same applies with iOS and Android - I've seen some pretty hacky products where they'll interface with smart card readers onto phones do things like authentication to websites or email encryption, but in the end you had to use the vendor's browsers/mail clients instead because only they could handle the integration with the PIV cards. YubiKeys can now connect to phones too, but you've gotta have the right combination of YubiKey and phone to get that connectivity going - and you're still limited to what the apps on the phone actually support.

timothy-quinn··on Tired of note-taking apps
I think we all end up on our own journey of trying to find the note taking style that works best for us, and the variety of styles (git, onenote, evernote, pen & paper, notes app, etc.) has lent to a variety of applications being built to cater for each.

I've got my own slightly different style of note taking that works really well for me, but only when I start to work on multiple projects simultaneously and I need a way to track tasks across them all. When I fall back to one or two projects, then my note taking needs disappear. I joined the fray anyway and turned it into a web app so I could at least have something that _I_ want: https://screwnotes.com

timothy-quinn··on Pwned Passwords, Version 6
Exactly - but the reactions I saw when he first released Pwned Passwords was "this is a malicious tool, don't give your password to anyone". Even if you're hitting the API from your own service, you need the entire password first to submit the partial hash to the API.

We who understand what's going on know it's perfectly fine, but it's hard to get that message across. Just like the first time you try to explain what a hash is to a non-technical person.

timothy-quinn··on Pwned Passwords, Version 6
I've always found HIBP in this funny conflicting situation - on hand you should never provide your email or password to a 3rd party service because it's probably malicious, but on the other hand in HIBP's case it's very evidently not malicious, so it's totally fine. But it's evident only if you follow Troy for a while to see what he's doing.

I think it's a good study in game theory at the least.

timothy-quinn··on Australian Government and businesses hit by state-based cyber attack, PM says
The Aus Government has a good guide called the "Essential Eight" for reducing risk. It's a good starting point for businesses, and is pretty much universal advice, not just applicable to government departments: https://www.cyber.gov.au/publications/essential-eight-explai...

My take on the E8: https://blog.congruentlabs.co/essential-eight-essentially/

timothy-quinn··on Lightweight Alternatives to Google Analytics
So far GA is answering two important questions for me - which marketing strategies are actually working (because it's hard to tell when you've got multiple going at once), and also making sure my marketing is actually hitting the geo-regions I need it to.

That said though once I know which marketing tools are effective, there's nothing more that GA does that CloudFlare couldn't just tell me anyway (i.e. am I getting more or less traffic) and I'll probably drop it as it's one less dashboard to look at - like you said that conversion to subscriber _is_ the ultimate metric for success.

timothy-quinn··on Getting the most out of YubiKeys for your business
Yeah that's why I added the "if" - But I have seen a lot of very small teams running AD (or Azure AD if they've chosen the Microsoft path), but they tend to just be paranoid about security or running in countries with poor internet connections.

Microsoft also provide pretty cheap deals for startups if they want some basic infrastructure for the office (excluding the hardware of course), so it's not entirely out of the equation on the licencing side either.

Really small teams typically will find U2F auth easiest to work with in the beginning, and then after hitting like 20 users they'll bump into problems like a large enough number of connected systems that they need to manage 2FA for.

timothy-quinn··on Getting the most out of YubiKeys for your business
Oh yeah good point, I always forget about the OATH part of the YubiKeys - unfortunately it's like the OTP feature in that I haven't had enterprise customers asking me about it at all (they're all hyped about U2F), so I start to forget its there.

I'll have to add it in to the article :)

timothy-quinn··on Getting the most out of YubiKeys for your business
Hi! I'm actually the product manager for the product mentioned in that article: https://enterprise.signata.net.

Are you heavily SaaS based for the tools you use in your startup, or do you have some on-prem infrastructure? That'll kind of dictate which path you should go down for provisioning the keys to your users. Our product will be perfect if you're using AD & a Microsoft CA internally (or are willing to set one up), as you could then just set up 3 YubiKeys for each employee, all loaded with certificates for authentication.

And, should one be stolen or an employee leaves, just revoke the certificates on it to kill the access immediately.

Any path you go down should really still only take a bit of time upfront and almost nothing longer term, unless your team grows fast.

You can also hit me up at tim@congruentlabs.co and I can give you more advice if you don't want to mention specifics publicly.

timothy-quinn··on Getting the most out of YubiKeys for your business
It depends on the context really - I love the push-driven MFA products, but they specifically require you as a user to be carrying a phone with you at all times, and are usually considered "low" assurance of the user's identity.

If your business is seeking "higher" assurance (yes, assurance levels are very subjective) then certificate-based MFA can meet the needs better. Or, if your business is working with sensitive data/systems, phones may be banned from the office (e.g. military, intelligence, banks, etc.).

timothy-quinn··on Getting the most out of YubiKeys for your business
Yeah Nitrokeys are probably the closest device, but cost even more https://www.nitrokey.com/

And usually it's twice what they charge, because you need a backup device to handle losing the first one.

I'd like to see a competitor come out with a combo PIV card & FIDO device. At least from the enterprise perspective it would cover 99.9% of MFA situations. And the majority of my personal uses of YubiKeys.

timothy-quinn··on Getting the most out of YubiKeys for your business
Luckily I wrote down the steps I took. Based on this, but the original seems to be gone now: https://nicluo.com/projects/secure-your-mac-with-yubico-u2f-...

  brew install pam-u2f
  mkdir -p ~/.config/Yubico/
  pamu2fcfg > ~/.config/Yubico/u2f_keys
  <Press the U2f device>
  cat ~/.config/Yubico/u2f_keys # should output <your username>:<really long hash>

  In /etc/pam.d/screensaver 
  Add to the top:
  auth       sufficient     pam_u2f.so

  In /etc/pam.d/authorization
  Add to the top:
  auth       sufficient     pam_u2f.so
timothy-quinn··on Getting the most out of YubiKeys for your business
I've personally never seen it work that way - usually because RDP doesn't pass through direct USB devices, only their abstracted forms (e.g. smartcards don't get passed through, only the "Smart Card" device registered in the OS, and only if you enable that to be passed through in an mstsc session.

There are products like Silverfort (https://www.silverfort.com/) that can handle agentless auth, and might be able to do that kind of MFA inside an RDP session. But, products like this usually require some 3rd device (i.e. your phone) to perform the MFA action, which is kind of not really just a simple WebAuthn logon...

timothy-quinn··on Getting the most out of YubiKeys for your business
Does anyone use YubiKeys on OSX for business use? I've tried integrating them on my personal mac before, but the U2F PAM experience was pretty clunky, and caused weird messages from services like Keychain that (I guess) couldn't decrypt without normal credentials being provided at logon.
timothy-quinn··on Postbank to replace 12M bank cards after employees steal 'master key'
Probably a backup. It makes sense to have an offline backup in cleartext (for DR), as long as you have the appropriate storage and security controls in place to protect it.
timothy-quinn··on Ask HN: What are your go to SaaS products for startups/MVPs?
Mailchimp & Sendgrid for mail (I like MC for campaigns, but SG for API call driven messages).

Firebase for hosting/serverless funcs.

G Suite for collaboration.

Bitbucket for Repos (they had better enterprise-y tools for free, not sure if Github now is at parity).

Notion for task lists and product specs.

Stripe for payments.

Twilio for SMS.

Cloudflare for caching/DNS.

timothy-quinn··on Show HN: Signata Enterprise – Provision YubiKeys with PKI Certificates
I work a lot with MFA products, and despite newer technologies such as FIDO/FIDO2 simplifying MFA for users, I still see there's a place for the classic smartcard-based authentication. It has far greater Enterprise support, works easily in non-Internet connected networks (which there are a _lot_ of), and the certificate use cases extend beyond just authenticating.

And, now that COVID-19 has pushed a lot of businesses to remote work, there's a greater need for MFA-enablement for these remote access solutions, and quickly.

Our blog has an announcement post too, which may help you understand how our product works too: https://blog.congruentlabs.co/introducing-signata-enterprise...

Feel free to ask me any questions here or on our blog post.

timothy-quinn··on Show HN: Signata Enterprise – Issue YubiKeys with Certificates for Enterprise
Hi HN - more information can be found about our new product in our announcement blog post: https://blog.congruentlabs.co/introducing-signata-enterprise...
timothy-quinn··on Ant Design 4.0
Maybe lion is something that meets your needs? https://github.com/ing-bank/lion
timothy-quinn··on Ant Design 4.0
I've tried Semantic, MUI, and Ant now for 3 separate projects.

The one I gravitate towards now is MUI - it's got the easiest drop in to an existing project, and the most predictability.

Semantic seems to be stuck in a weird place where the main project is barely maintained and a fork (Formantic) is superior, but there's no React version for the fork so you have to make your own React components if you want their new features.

I liked Ant but the integration into existing apps took far more effort than I would've liked. In the end with Ant I gave up and made a fresh project and shifted my existing codebase across.

The only thing I wish MUI had that Semantic was superior in was forms - Semantic has a far better built-in form component, including error/warning/success & loading states out of the box.

timothy-quinn··on My productivity app for the past 12 years has been a single .txt file
Hi, there have been some updates to it and the landing page does have a short explanation, but I agree - something a bit more interactive would probably be better.

The app itself is something tightly coupled to having an account to operate (so no data is lost), but I might try adding in an interactive demo on the landing page so you get that feel of how it works straight away.

timothy-quinn··on My productivity app for the past 12 years has been a single .txt file
That was the ethos behind the app I wrote, https://screwnotes.com - I just wanted a note taking tool that syncs everywhere and I there's only one way to add items. I don't want to wait for a product to load, or to have to make any mental decisions about organisation, due dates, or relationships between items.
timothy-quinn··on Show HN: Screw Notes, A Really Simple TODO List App
https://screwnotes.com

Just adding the URL here so it becomes a hyperlink to be clickable at least.

This project was an interesting experiment in building on Firebase. Currently the whole app is almost entirely client-side, with access to data controlled by firestore rules. The Stripe Checkout service handles subscriptions, and successful payments flow down to the user through a hook trigger from stripe followed by a bunch of firestore onChange event listeners.

This may change if users want particular features, but for now I'm amazed at how simple (from the perspective of my codebase) it was to string all of these components together.

timothy-quinn··on Ask HN: I'm making a big decision about my career all comments appreciated
Choice 1 - without a contract a handshake means nothing, and as you've said they'll let you apply for the jobs, but that still doesn't guarantee you'll be given them (especially if you become very useful in L2/L3 support).

For me personally I found getting any software development job I could, even though they're really dull large enterprise forms-over-data jobs, gave me a massive boost in development ability and experience, especially because I was thinking about dev for 8+ hours straight every day.

Will the Choice 1 job make you work less hours? If so that frees up more time to work on dev projects on the side, and you could use that to your advantage.

timothy-quinn··on Stop Calling It “Military-Grade Encryption”
OP here. What browser/OS do you use? Our blog is run on Ghost so we don't actually control the TLS cert used, but we can try to find the cause of why it's not trusted and fix it.
timothy-quinn··on Show HN: Signata RC2 – The Software Keys Update
We just pushed RC2 out to let you try our product straight away without YubiKeys: https://signata.net

There's more detail about the release here: https://medium.com/@congruent_tim/signata-release-candidate-...

timothy-quinn··on Yubico launches its dual USB-C and Lightning two-factor security key
It's hard to say until we see it in action. I'm optimistic, but with Apple's track record of hobbling integrations in annoying ways I'm still a little hesitant.

I really do want them to work fully though so I can extend my product to mobile too. I know a lot of people now that have gotten rid of their computers and just use their phones for everything.

Page 1 of 2Next →