frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Opaque, Interoperable Passkey Records (and a Go API)

https://words.filippo.io/passkey-record/
39•gnabgib•9h ago

Comments

cadamsdotcom•6h ago
Ok so we are achieving interoperability by turning passkeys into strings.

You know what it's called when you store a secret string in your password manager?

A password.

gnabgib•6h ago
> You know what it's called when you store a secret string in your password manager?

You keep changing your comment, but on the off chance you're still throwing shade.. Filippo probably wrote your password manager (or the code it runs, or the code your docker/kube system runs), and the decoder on the other end.

miloignis•6h ago
That's his point - he's demonstrating a proposed standard that would make storing passkeys server-side almost as easy as passwords.
fastest963•4h ago
The user still needs to provide proof that they own the passkey in order to login. It's not like someone could hack the website, steal the "string" and use it to login.
deathanatos•6h ago
From the linked spec,

> The authenticator data is a CBOR structure defined in the WebAuthn Level 3 specification, is returned by the getAuthenticatorData() method of the AuthenticatorAttestationResponse

From TFA,

> The payload is the authenticator data, a CTAP2 CBOR encoding of most of the credential record fields that is already specified by WebAuthn

Both link to the same section of the WebAuthn spec, §6.1 Authenticator Data[1]. Unless I'm missing something, that section is describing a custom binary format, not a CBOR encoding of data. (Though n.b. that one of the items contained by the outer custom binary format is CBOR, but the 37(ish) byte array itself is not CBOR.)

(…and it's stuff like that that just makes all of WebAuthn so impenetrable.)

[1]: https://www.w3.org/TR/webauthn-3/#sctn-authenticator-data

masklinn•2h ago
The article does not say it’s storing the authenticator data (in the format the webauthn spec specifies), it says it’s storing (most of) the fields in cbor. So it’s using the webauthn reference for logical purposes (the names and types of fields) not physical (the encoding).
dwaite•9m ago
I was unclear on that as well. WebAuthn uses an extended form of the U2F format, such that if you don't use any of the new features or extensions the two are binary compatible with compatible signatures.

So the U2F bits like authenticator data are in a bespoke format using section lengths, while the newer features and extensions are CBOR.

One could translate the bespoke bits to CBOR, but care would be needed if you want to round-trip back to the bespoke format (e.g. so that attestations could be verified in the future off of the registration record.) Since CBOR isn't really as usable as say JSON as being an abstract object access API, and since CBOR is going to take up more space, I don't think this would really provide value over leaving it in the WebAuthn format for tooling to work on directly.

Vixen 0.3 – fork of ratpoison (winman) goes back in time to resolve old bugs

https://codeberg.org/spidervixn/vixen
1•icmpkitty•2m ago•1 comments

The 'Screwfly Solution' Solution: Bi-Sexuality

https://gwern.net/screwfly
1•barry-cotter•4m ago•0 comments

Show HN: A BIOS-style terminal for observing a deterministic persistent world

https://speykye.github.io/persistent-world-observer-terminal/
1•Speykey•6m ago•1 comments

Judge halts Paramount's $111B purchase of Warner Bros. in win for US states

https://arstechnica.com/tech-policy/2026/07/judge-halts-paramounts-111b-purchase-of-warner-bros-i...
3•rbanffy•7m ago•0 comments

Did China just beat Intel?

https://twitter.com/SemiAnalysis_/status/2079251630608842814
3•xnhbx•11m ago•0 comments

Stacker – Deploy multi-container Docker stacks with one CLI command

https://github.com/trydirect/stacker
1•trydirect•13m ago•0 comments

AI-Assisted Vulkan Development

https://docs.vulkan.org/tutorial/latest/AI_Assisted_Vulkan/introduction.html
1•pjmlp•14m ago•0 comments

Configuration Complexity Clock (2012)

http://mikehadlow.blogspot.com/2012/05/configuration-complexity-clock.html
1•dwrodri•15m ago•0 comments

Figma Console MCP

https://github.com/southleft/figma-console-mcp
1•handfuloflight•16m ago•0 comments

Show HN: QuiverKit – 62 developer tools that run offline

https://quiverkit.dev
2•ensardev•16m ago•0 comments

Ask HN: I am building a app to deep search bookmarks from browser, X etc.

2•shafkathullah•20m ago•1 comments

Were you watching the World Cup or playing chess?

https://mastodon.online/@lichess/116952699800947773
1•plaguna•23m ago•0 comments

Agent solves problem in JavaScript but fails in TypeScript

https://twitter.com/dillon_mulroy/status/2079400950280663126
2•tosh•23m ago•0 comments

Show HN: Qscreen – tmux-like session manager for Windows PowerShell

https://github.com/dualface/qscreen
1•dualface•24m ago•0 comments

Set Cover Problem

https://en.wikipedia.org/wiki/Set_cover_problem
1•tosh•27m ago•0 comments

European Password Manager Shares [..] With State-Certified Russian Firm

https://www.occrp.org/en/investigation/european-password-manager-shares-origins-and-updates-with-...
3•defly•31m ago•1 comments

Ask HN: What are opinions on browser password manager vs. standalone?

2•omnifischer•31m ago•1 comments

Memory Safety's Hardest Problem

https://matklad.github.io/2026/07/20/memory-safety-hardest-problem.html
2•ingve•32m ago•0 comments

Ask HN: Claude Code or Codex?

4•czeizel•33m ago•4 comments

Palantir in Europe: 40 documented customer relationships across 14 countries

https://ciphercue.com/blog/palantir-in-europe-governments-companies-2026
2•adulion•34m ago•0 comments

KDE for Enterprise Needs a Strong PIM Infrastructure

https://ervin.ipsquad.net/blog/2026/07/21/kde-for-entreprise-needs-a-strong-pim-infrastructure/
4•hebus•35m ago•0 comments

DeepSWE – Best Benchmark for Evaluating AI Coding Agents?

https://www.i-programmer.info/news/105-artificial-intelligence/19016-deepswe-best-benchmark-for-e...
2•aquastorm•38m ago•1 comments

What if they are all wrong? (2020)

https://igorpak.wordpress.com/2020/12/10/what-if-they-are-all-wrong/
1•kkoncevicius•38m ago•0 comments

Armored Cars, Now on the American Road

https://www.nytimes.com/2026/07/20/style/armored-cars-bulletproof-american-drivers.html
2•reaperducer•39m ago•0 comments

Building Anthropic [video]

https://www.youtube.com/watch?v=om2lIWXLLN4
1•tosh•40m ago•0 comments

Windows 11 OpenSSH agent to WSL2

https://addshore.com/2023/07/windows-11-openssh-agent-to-wsl2/
2•ankitg12•42m ago•0 comments

CodeSizer: Why is that binary so big?

https://github.com/Wren6991/CodeSizer
1•birdculture•43m ago•0 comments

Ransomware attack on fairlife (company owned by Coca Cola)

https://www.sec.gov/Archives/edgar/data/21344/000162828026048466/ko-20260716.htm
1•wolfi1•43m ago•0 comments

Daily Urban Systems: where people live and where they work (the Netherlands)

https://regio.toekom.st/
2•overboil•45m ago•0 comments

Controlling user access in ScalarDB Cluster by using OIDC-based JWT tokens

https://medium.com/scalar-engineering/controlling-user-access-in-scalardb-cluster-by-using-oidc-b...
1•josh-scalar•45m ago•0 comments