Hacker Newsnew | past | comments | ask | show | jobs | submit | Shank's commentslogin

I've been testing with Xcode 27.1 on the Duo simulator and I was pleasantly surprised that nearly everything worked well, untouched. The main thing I need a real device for is knowing which buttons are easier or harder to press on the right edge, but using modern UIKit this was not that difficult. That, and taking advantage of the left/right inner display content areas.

I store my passkeys in KeePassXC and I have absolutely no feeling of being walled into any garden, personally.

but what do passkeys offer in terms of security, when stored in password managers, compared to having a (password manager) generated password and a totp?

I believe that by allowing password managers to store passkeys, the whole purpose of "device based security" got lost..


They are 100% immune to credentials phishing. You literally cannot authenticate to an impersonator site based on cryptographic guarantees.

And yes, I know the happy path of password managers uses host-based autofill which does add some friction to phishing attempts, but given the prevalence of unexpected but legitimate urls with weird alternate subdomains/SSO/redirects in modern login flows, you have to manually autofill/add an exception often enough that it's possible to let your guard down once at the wrong time.


Yes. I use hardware based passkeys and absolutely love them. I think it was a giant mistake having them 'software' based. It some ways it kind of defeats the entire purpose...

Wait until websites start demanding device-bound/attested passkeys. Big tech just needs to get enough adoption to make this change.

Nobody is going to do this because Apple’s devices don’t support this for the Passwords app out of the box, by design.

As much as I hate to admit it (because I love passkeys UX), but I do think that device-bound/attested passkeys are going to happen in the future :(

UPD: oh, heck, attested passkeys are actually already in the protocol. Why can't we just have nice things?


Fujitsu is such a large company that it is unlikely that there is any overlap between these two groups.

> Can easily pay $15 to essentially go around the corner.

Would it not be better to simply walk if the distance is essentially around the corner?


I love walking - checking distance tracking on my phone, I walked over 20km in a day a couple of weeks ago. But when it's hot in Singapore, the distances I don't want to walk can become crazy-short at times.

I'm hesitating to judge someone taking a ride-share around the corner. Among many other reasons, I can imagine scenarios where someone would think it worth paying to not arrive a sweaty mess.


Have you considered using a pedometer watch or a fitness tracker that doesn't rely on phone data?

Would that change the distance they walk?

I walk 99% of the time. By around the corner, I mean a 10 - 20 min walk (5 min drive in good traffic), which will easily get you drenched in sweat depending on the weather. If I'm headed to a dinner or gathering that requires a bit of dressing up (shirt and trousers), walking isn't really an option.

In 32C high humidity where is about to rain?

I’ve been travelling to singapore for the last 15 years, my gut view is cabs are far more expensive today than they were 10 years ago even after adjusting for inflation. Maybe it’s just incorrect memories - rates don’t seem to have increased that much.


Rains a lot and often around 30°C. Walking is not always an option if you need to be presentable wherever you're going.

Ever tried walking around the corner when it's 35C (95F) and 90% humidity?

Humidity is usually between 60% to 70%. Where do you get your 90% figure from?

My next trip to singapore is the end of next week. I’m staying a mile from the office, Apple predicts it’s 89% at 0730 but will drop to 75% during the day, and back upto 80% after dinner.

Yes, relative humidity goes up during the night. My numbers were for the day.

Yes? All the time in South Florida.

Famously Americans walk everywhere.

It's called a lower bound.

How much would a nation state pay for a complete copy of OpenAI’s github repositories? I doubt there are many full chains laying around like this.

It’s the structure that really gives this one away. If you were writing a blog post about introducing limits you wouldn’t explain what HTTP 429 is or what the behavior would be like. It’s a rate limit.

I've experimented with things like this, e.g., the Narrative Clip. I think the concept is quite novel and interesting, but the privacy implications are just far too gross for anything outside of an experiment. Of all companies, I find it appalling that it's Apple implementing this one.

I don't even know how this is supposed to work e.g., in states with call recording legislation, let alone any new legislation. It feels utterly appalling that every Apple watch could theoretically be recording all surroundings now.


I’m really disappointed that Apple removed the one-toggle option to turn off Apple Intelligence / Siri AI features in the last beta. Writing tools magically reappearing after I had it off is not a great experience.

You find a way to turn it off ? I completely disabled Siri immediately but a lot that stuff still shows up

> You can use AI computer control to do this stuff now, right?

Speaking as someone who had to do a lot of immigration work to move to Japan, I can think of no work I would want to have a close eye on than immigration paperwork. One error is all it takes for a clerical rejection or similar. I had a professional lawyer working on mine and still cross checked every detail, and found errors!


> Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting.

It sure seems like the evidence doesn't point to scraping to me.


Have I been pwned reports 99% of email addresses from chess.com leak were already in their database. Rather strong indicator that the Hacker scraped an API with a list of email addresses.

https://infosec.exchange/@haveibeenpwned/117263977537458510


I'm assuming they're basing this on the no-passwords part.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: