pilcrow's Avatar

pilcrow

@pilcrowonpaper.com

I like building stuff https://pilcrowonpaper.com

1,527
Followers
19
Following
367
Posts
30.10.2024
Joined
Posts Following

Latest posts by pilcrow @pilcrowonpaper.com

Passkeys with no user verification provide more or less the same security as email OTP right?

05.03.2026 10:31 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Yeah it's not great but I don't think the premise is that bad either and this is infinitely better than forcing applications or OSes to do age verification by using AI or collecting IDs

04.03.2026 09:43 πŸ‘ 5 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

The whole point of the legislation seems to be:
1. Allow parents to have more control over their children's online activity
2. Force applications to respect parents' decisions and do basic age checks
3. Make enforcing COPPA etc easier

04.03.2026 09:43 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image Post image

I can't tell if "applications" include websites tho. The text seems to treat "software applications" and "websites" differently but idk

We might see a new web API or HTTP header?

04.03.2026 09:43 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

The bigger issue is that apps have to request for the age bracket info even if they don't have a use for it. It also seems to apply to ALL devs/apps

I wonder if the signal will be included in env vars or something like that so it's technically requested by all software by default

04.03.2026 09:43 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

The California law to require "age verification" in OS doesn't really seem to be about age verification. It just mandates OSs to allow parents to create accounts for children and for apps to use the age info of accounts

04.03.2026 09:43 πŸ‘ 4 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

I get to like 80 wpm comfortably and 100 if I try hard enough. Not efficient but it works

The big downside is that this only really works on MacBooks lol

02.03.2026 16:34 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Behold my terrible keyboard finger position

blue: thumb
green: index
yellow: middle
red: ring
pink: pinky

02.03.2026 16:34 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

β€ͺI’m finding Go’s standard library to be very helpful because it supports a lot of public key formats on top of the signing algorithms but creating a parser for them is still doable‬

β€ͺHandling attestation statements is probably a different story tho‬

02.03.2026 06:17 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Back to WebAuthn after a year and I’m fully convinced you don’t need a library for it

Well except for the crypto stuff

02.03.2026 06:10 πŸ‘ 8 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Implementing this in Go right now but my allergies are killing me

02.03.2026 06:01 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Passkeys not working on Nintendo.com in Firefox | 1Password Community If I create a passkey from my PC and save it to 1Password, I'm not able to use that passkey to login on any of my devices which have 1Password installed, not...

Looks like the bug has existed for over a year!a
www.1password.community/discussions/...

26.02.2026 15:33 πŸ‘ 5 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Passkeys are broken on the Nintendo Account's website because there's a bug in their base64url decoding lol

Do you see the issue?

26.02.2026 15:33 πŸ‘ 5 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

Eh I think it's fine for passkeys to be opt-in ("Do you want create passkey?") until Apple and Google figures out how to explain them to normies

25.02.2026 12:18 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I don't hate passwords but it's not super user friendly once you have complex password requirements. It's great for those who use a password manager but these people already use (or can use) passkeys

Adding back-up passwords might not hurt but again more complexity

25.02.2026 10:56 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

One possible issue I guess is that passkeys are significantly stronger than email OTP so some users might prefer to have the option to add a second factor (passkey or security key) with email OTP or outright disable it

Adds complexity but imo worth it for security sensitive appp

25.02.2026 10:56 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Email OTP is the best option for the regular user

Passkeys are the best option for more tech literate users

Provide both and you got a login system that's better than most apps

25.02.2026 10:56 πŸ‘ 24 πŸ” 1 πŸ’¬ 3 πŸ“Œ 2

The web as a whole ignore bilingual users

25.02.2026 10:51 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Doesn't work unfortunately, especially for programming stuff

The only solution I've found is to literally add "in English" to the search

25.02.2026 10:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I need to create a browser extension that appends "in english" to all google searches because I'm fucking tired of getting japanese results for everything

25.02.2026 07:12 πŸ‘ 5 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

How can I say no to a 20% discount?

24.02.2026 08:06 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

I couldn’t resist

It’s sooo good. It’s so much better than my Sundara. Super clean and surprisingly wide sound. Great build quality too

24.02.2026 08:06 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Nah just made some wrong analysis

23.02.2026 14:25 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Had a feeling something was wrong and found some glaring issues after a few days. Super glad I didn't rush it out

Very proud of this one :)

23.02.2026 14:11 πŸ‘ 5 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I'm seeing wildly inconsistent performance (2x) between different Hetzner instances of the same type

I believe the bottleneck is the memory bandwidth

23.02.2026 13:19 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Trying to map the names of Japanese and US cuts of meat is a whole another issue as well. Finding a good thickness too. Why are the steaks either 1 cm or 10 cm??

23.02.2026 12:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I did learn recently that Japan does have native breeds of cows that's less marbled but they only accounts for like 1% of the total population. Really expensive too

23.02.2026 12:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Finding a good cut of steak feels impossible in Japan. You can only find cheap stuff from Australia or really expensive wagyu that's 90% fat. I haven't seen US Prime in 4 years. Where's my dry aged or A2 wagyu?

23.02.2026 12:44 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I fucking hate LINE and PayPay sooooo much

Both of them have every single thing I hate about Japanese UI/UX design distilled into them

19.02.2026 11:00 πŸ‘ 4 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Didn't try the high-end hifimans but I didn't find their other headphones with a similar shape to be super comfortable

19.02.2026 08:13 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0