Hacker Newsnew | past | comments | ask | show | jobs | submit | dm's commentslogin


What flows have you found not to use security keys?


All of them.



Twitter thread by the President of the Signal Foundation: https://twitter.com/mer__edith/status/1693740215112782223



It does mean all registrations, renewals and changes to ~250 TLDs are out of action though.


None of those are done via Whois. If what you say is true, then it must mean that they have taken down more than their Whois service, and have suspended EPP access as well.


You're right of course that Whois isn't involved in those things. Other comments indicate it's scheduled maintenance, which means EPP is down and most registrars have status updates out indicating changes to these TLDs are unavailable.


Which is not that uncommon. Registries undergo maintenance all the time. The only thing that is really impacted is the ability to register new domains and use them immediately.


Edit: Turned out to be scheduled maintenance, which is now complete.

--

Also the case for .IO and .AC as well as most TLDs managed by Identity Digital (Donuts).

List at https://identity.digital/our-domains/


Perhaps most notably, this includes .info domains.


Curious how this will work in practise. The passkey has to be stored somewhere. Logically, that's in 1Password itself, which would mean you can _only_ login if you have access to a device that's already signed in. Or, in iCloud Keychain, which is what the video seems to show, which would shift the trust model to my Apple ID. What happens if I get locked out of that?

And what happens if biometrics are unavailable on my device (like, after first boot)? Does 1Password then fall back to my macOS login password?

Their blog post is unclear on details, but it feels like there are multiple trade-offs to this where some might want to stick to the current Master Password + Secret Key model.


>The passkey has to be stored somewhere. Logically, that's in 1Password itself,

A Passkey is a WebAuthn-compliant[0] form of authentication which relies on biometric authentication combined with a key pair.[1] iCloud supports the ability to create passkeys, and allows users of Apple devices to use them to sign in by TouchID/FaceID. Another means to get a passkey is to purchase a physical WebAuthn-compliant hardware device, such as a Yubikey or a Google Titan Security Key.

[0]: https://webauthn.guide/

[1]: https://support.apple.com/guide/mac-help/aside/glos0930f77c/...


It's kind of ironic that their main IPv4 addresses are x.x.x.0, while their "ZERO" filtering version uses x.x.x.9.


If you're happy not having a home-grown open source solution, New Relic is essentially free if you don't have many servers and turn off extended metrics. If you start adding in more integrations, it's gonna cost you, but for basic monitoring and nice graphs hosted externally from your systems itself, it works nicely.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: