Readit News logoReadit News
politelemon commented on Credentials for Linux: Bringing Passkeys to the Linux Desktop   alfioemanuele.io/talks/20... · Posted by u/alfie42
digiown · 2 days ago
Passkey/webauthn is a cool tech, and I'd really like to use it everywhere, but I find the anti-user attitudes of the spec authors concerning. The spec contains provisions about "user verification" (the software must force user interaction) and not allowing the user to access the plaintext keys. It appears that the spec authors do not consider the keys to be owned by the user at all.

KeepassXC implements passkey support, but they do not implement these anti-user features. As a result, they are being threatened with being banned via attestation:

https://github.com/keepassxreboot/keepassxc/issues/10406

https://github.com/keepassxreboot/keepassxc/issues/10407

Screw these "You'll own nothing and be happy" people. I'll own all my keys no matter what. The software I run on my device should never betray me to signal things like "this passkey is allowed to be backed up!".

politelemon · 2 days ago
> It appears that the spec authors do not consider the keys to be owned by the user at all.

This was my impression, and it explains why the original announcement involved companies that would benefit the most from keeping their users on a leash.

Loading parent story...

Loading comment...

politelemon commented on Intel Recently Shelved Numerous Open-Source Projects   phoronix.com/news/Intel-O... · Posted by u/pjmlp
politelemon · 2 days ago
It comes as no surprise that polite guard turned out to be a lemon.
politelemon commented on OpenClaw is changing my life   reorx.com/blog/openclaw-i... · Posted by u/novoreorx
politelemon · 2 days ago
> Thank you, AGI—for me, it’s already here.

Poe's law strikes... I can't tell if this is satire.

politelemon commented on Software factories and the agentic moment   factory.strongdm.ai/... · Posted by u/mellosouls
politelemon · 3 days ago
> we transitioned from boolean definitions of success ("the test suite is green") to a probabilistic and empirical one. We use the term satisfaction to quantify this validation: of all the observed trajectories through all the scenarios, what fraction of them likely satisfy the user?

Oh, to have the luxury of redefining success and handwaving away hard learned lessons in the software industry.

Loading parent story...

Loading comment...

Loading parent story...

Loading comment...

Loading parent story...

Loading comment...

Loading parent story...

Loading comment...

Loading parent story...

Loading comment...

u/politelemon

KarmaCake day10926July 15, 2017View Original