Submission timeline
2007–2026One slot for every year since HN launched. Height is that year's peak points; orange marks a 100+ point or 50+ comment breakout. Select a bar to open its strongest thread.
First comments on top threads
HN comment orderI am unfortunately not bullish that this will pick up but there are strong arguments for this way to authenticate. - you would typically store the private key on a disk-encrypted app-whitelisted iphone, so that the computer you are browsing with, whether yours or a public machine, is never involved in the authentication. Effectively this achieves 2FA. And you don't care if the machine you browse with is compromised. - this does not rely on a third party, it is…
This looks like a much less polished version of Clef (https://getclef.com/). Clef is a really awesome app and they're already powering this type of integration for a few hundred websites. One of the founders is an HN regular, although I can't remember his username (Jesse, reply if you see this).
Gibson has been hawking this for years. Skipping over some details, the biggest issue with it is that it's phishable, so it fails to address the single biggest threat most users face. In the five years this has been "under development" (!!!), FIDO and WebAuthn have made serious progress, providing a broadly-supported standards-based approach with native browser support and which addresses a more comprehensive threat model, including phishing and local user verification.
ice idea, but if you need to mitigate some issue by making the code also a clickable link, why would anyone ever scan it? Since opening some scanning utility will take more effort than simply tapping or clicking the link?
The first top-level comment from each of the four biggest threads, in HN’s own order. Excerpts are shortened; open a comment for full context.
- Breakout years
- 2
- Total points
- 507
- Total comments
- 293
100+ points or 50+ comments
reference only — not used in Hall rules or ranking
reference only — not used in Hall rules or ranking
