Show newer

@tasket also in general it's just more "standard", but I guess password managers are getting integrated at the operating system level now to so they're just as standard 🤷

@tasket I think one thing that is different from password managers in this scenario is that you can use your key instead of an email+password combo and could potentially reuse credentials more easily. also has an obvious path for hardware keys

@smitten@snowdin.town yeah! it's a pretty similar concept. I think one thing that's different is that this happens at a lower level and as a lot more standardized then password managers.

I think right now even with pass keys applications end up having a billion different ways of actually inputting credentials where as this has one unified way that lets you easily reuse public keys between sites.

they could have been synchronized between devices just as easily I think

@smitten@snowdin.town Mind rephrasing that? Having a bit of trouble parsing what you mean.

one thing that this thing is sorely missing though is a gps and a cellular modem. I still wish I could use map software to navigate around and I also wish I had more pile internet connection and access to my text messages without having to have a separate device for it

Show thread

using my smartphone feel so incredibly limiting after using my steam deck on the go. I think the main thing is that it's so much harder to customize and to use keyboard shortcuts that having to find the push and swipe all the time. especially now that I have my speech to text set up to a point where it's more useful. like, I had speech to text on my android at one point it's such a huge pain in the ass to make any customization to it. whereas on my deck I can just edit my python script

@mauve Omg, seriously. Back in 2016, when browsers started pulling support for generating client certs, I basically spent a year creating a new cross-domain authn system for the Solid Project (it relied solely on client certs before that).

But I still think about the kind of awesome world we could have had, had the vendors supported client certs properly. Just boggles the mind.

like the one where your identity is your mobile phone number right? making metadata really trivially attributable??? the one where you can't make an account using only a desktop computer? "doesn't suck"??

Show thread

We've been punching above our weight at @ddosecrets: we're a small transparency team with a shoestring budget, but hosting over 100 TiB of documents, operating search engines for some of those datasets, and fielding data requests from journalists and researchers, all costs money. If you can donate today, or share our fundraiser, your support right now means the world to us.

donorbox.org/keeping-ddosecret

Seriously, why the hell are we still using username/password when browsers have supported requesting client certificates for years now.

Literally just learned today that it's an API that's supported in all the major browsers already. Maybe because it's at the TLS/Server-side layer instead of inside client-side JS or the HTTP layer?

Only downside is now I need to add this functionality to Agregore. :P

@ninabreznik @fission They are targeting the web platform which only supports connecting people via servers (with some caveats).

💵 $1,000,000,000,000 💵

If only we could spend a TRILLION dollars every year to fight global heating and promote climate justice. But where would we get that kind of money??

Oh...

Governments Spent Record $1 Trillion Last Year Subsidizing Fossil Fuels

bloomberg.com/news/articles/20

#AntiCapitalism #FossilFuels #ClimateCrisis #ClimateJustice

Show older
Mauvestodon

Escape ship from centralized social media run by Mauve.