Hacker Newsnew | past | comments | ask | show | jobs | submit | throw7's commentslogin

I have said before, I'm personally not interested using "Something I have"/"device bound" as an authentication factor. I'm also not interested in the sync "workarounds" that store keys in the cloud.

People have replied it's possible to extract the private key, but it's not clear to me that that's usable (maybe it is I don't know). It's certainly not in line with what passkey devs want people to do and not do, so I'm not interested in "fighting" against the "flow" so to speak.

I'm happy with TOTP, as I can manage and use the codes where I want, under my control.


It's a "feature" that you can't call google to help with getting "locked out":

"For your security, you can't call Google for help to sign into your account. We don’t work with any service that claims to provide account or password support. Do not give out your passwords or verification codes."

for the future: https://support.google.com/accounts/answer/7684753


"Something you have"/"device bound" is not what I want if I don't control it. In the case of passkeys, I don't have access to the private key, so I consider that not controllable by me.

I'm happy to be wrong if I am able to extract and import the private keys (it's what I do with TOTP now), but my understanding is designers of passkeys explicitly don't want users access to their own privkeys so they can tie them to physical objects. I get that, I don't want that.

So passkeys are not something I'll ever use or useful or convenient to me.


Bitwarden lets you extract and import passkeys. Apple, Google, Microsoft, and 1Password don't support that directly, but they do support a finicky app-to-app transfer system, where you install two password-manager apps on the same device, and you directly export your passkeys from one app to another. It's called the "Credential Exchange Protocol" (CXP).

Bitwarden's app can receive CXP passkeys, so you can install a passkey in Apple's password manager, CXP it to Bitwarden, and then export it to a file that you control.

Putting the file under your control does make it possible for someone to trick you into sending you that file, undermining some of the phishing protections of passkeys. It’s up to you to decide whether protecting yourself from being tricked into exporting your passkeys is worth sacrificing your ability to read them.


KeypassXC was threatened with blacklisting for deigning to let users access their private keys. Passkey Consortium lackeys will try and reassure you that you have control over your keys, but they are lying through their teeth.


If you're using a hardware device, you can't extract them, because that's the point.

If you're using a password manager to store your passkeys, there are protocols to move them between password managers.


okay but on apple devices (for instance) I believe the private keys are stored in the icloud keychain, otherwise there would be no passkey portability between your apple devices


The argument from the article is when things go wrong (as what happened w/ Taylor), the damage is widespread, whereas damage is contained locally.


NIV is what I grew up with and I kind of tired of it because of that... I have a soft spot for the KJV/NKJV.


Same, not a believer, I appreciate KJV for its artistic value and it being referenced in so much literature and cinema.


Am a believer, and appreciate the KJV for its language. However, it can be tricky, because words change over 400 years. So while there are many wonderfully translated passages that use very expressive language, you also have passages that are full of words that seem similar but actually are easy to confuse.

For example:

- "Prevent" in 1611 meant "go before, precede". Now it means "stop from happening". - "Suffer" in 1611 meant "allow to happen". Now it means "experience pain". - "Quick" in 1611 could mean "alive" (hence "the quick and the dead"). Now it exclusively means "fast".

And there are words that are completely archaic now - "anon", "bissam", etc. Or words that are just very rare - e.g., peradventure.

It's a wonderful read in many places if you want to revel in language, but modern translations are often better for understanding meaning. Not because they're "dumbed down" (as some claim) but rather because they reflect modern meanings and usage.


I get that, but KJV is referenced so much that I find it's worth just dealing with it and learning the 1600s differences along the way. Plus those differences are interesting in of themselves.


Almost no one is reading the 1611 version today though. Over 99% of the KJV bibles in existence today are the 1769 revision.


I respect your beliefs.

I once tried to stick to Green’s Literal Translation but it got dry fast. I actually enjoyed reading the preface and made me appreciate the work Jay Green Sr put in.


Good article. It's a sober look at where we are at.

We lost a lot of strong privacy rights we had with landlines when we shifted to cell phones.

We're actually slowly creeping into pre-crime territory. You could have AI searching for possible pre-crime candidates based on unknown identity in the area, disparate pattern to usually movements, etc.



The soft bigotry of low expectations.


"an employee simply forgot to remove it."

And? That's all? This is why no one wants the gov't. to run things.


So the subcontractor is "avoiding regulations" (which are what btw?) by being a "subcontractor" and NYC can do nothing about the "subcontractors" but get rid of "subcontractors"?


Part of the problem is that sometimes the subcontractors are small enough to play by different rules. Or they don't have the means to support the staff when things go sideways. Or sometimes they're independent drivers, in which case the drivers themselves are responsible for the vehicle and any accidents, etc.

The subcontractors can just fold as well, leaving drivers in the lurch.

However, Amazon gets to dictate everything else about the job. The subcontractors have no authority or autonomy, but are made responsible for the heavier costs of the process.

Amazon wants to have an employer-relationship when it comes to dictating terms, but a contractor-relationship when it comes time to giving benefits or resolving disputes.


"...the model may give different advice even when the underlying question is the same."

Isn't this the point of LLMs? If not it would be deterministic and that's not "new" and/or "exciting".


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: