<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: pwlb</title><link>https://news.ycombinator.com/user?id=pwlb</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 06 Apr 2026 02:08:01 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=pwlb" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by pwlb in "German implementation of eIDAS will require an Apple/Google account to function"]]></title><description><![CDATA[
<p>The documentation actually reveals why this will most likely not work, given you are on expert on mobile security</p>
]]></description><pubDate>Sun, 05 Apr 2026 18:53:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=47652631</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=47652631</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47652631</guid></item><item><title><![CDATA[New comment by pwlb in "German implementation of eIDAS will require an Apple/Google account to function"]]></title><description><![CDATA[
<p>The documentation clearly outlines that there are multiple signals being analysed. Relying on play integrity alone is definitely not sufficient as you state.</p>
]]></description><pubDate>Sun, 05 Apr 2026 18:48:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=47652585</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=47652585</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47652585</guid></item><item><title><![CDATA[New comment by pwlb in "German implementation of eIDAS will require an Apple/Google account to function"]]></title><description><![CDATA[
<p>EIDAS 2 motivation is implicitly that eID failed in eIDAS 1. It simply either didn't take off or didn't work at all</p>
]]></description><pubDate>Sun, 05 Apr 2026 18:42:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=47652533</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=47652533</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47652533</guid></item><item><title><![CDATA[New comment by pwlb in "German implementation of eIDAS will require an Apple/Google account to function"]]></title><description><![CDATA[
<p>This is necessary because the wallets contain an identity proofing functionality called PID(Person Identification Data). Showing these credentials basically approves you are you. There are high requirements for identity proofing that even pre-date wallets and that makes sense, because the potentially blast radius of identity theft is huge. Historically, these have been secured in smartcards, like eID cards or passports and are not shifting to the smartphone. Verifying the security posture of your device and app is therefore crucial.</p>
]]></description><pubDate>Sun, 05 Apr 2026 10:38:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=47648032</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=47648032</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47648032</guid></item><item><title><![CDATA[New comment by pwlb in "German implementation of eIDAS will require an Apple/Google account to function"]]></title><description><![CDATA[
<p>Banks actually have high fraud rates today because of weak security mechanisms. If attackers steal your money, the bank will reimburse you. If attackers steal your identity, you are really screwed. Security requirements for banking and identity are simply different.</p>
]]></description><pubDate>Sun, 05 Apr 2026 10:20:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=47647924</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=47647924</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47647924</guid></item><item><title><![CDATA[New comment by pwlb in "German implementation of eIDAS will require an Apple/Google account to function"]]></title><description><![CDATA[
<p>Preventing credential duplication is a requirement to achieve high level of assurance. One of its purpose is to limit the potential damage that can be done by attacks. If credentials are bound to hardware-bound keys, attackers will always need access to this key store to make any miss-use. If you don't prevent duplication, attackers may extract credentials and miss-use them at a 1000 places simultaneously.</p>
]]></description><pubDate>Sun, 05 Apr 2026 10:17:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=47647905</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=47647905</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47647905</guid></item><item><title><![CDATA[New comment by pwlb in "An illustrated guide to OAuth"]]></title><description><![CDATA[
<p>This is due to many parts of the system being spread across multiple IETF RFCs, which happens as OAuth was improved and made more secure over time. Efforts are underway by combining all important parts into OAuth 2.1, otherwise have a look at FAPI 2.0 security profile for high assuance use cases.</p>
]]></description><pubDate>Mon, 25 Aug 2025 16:35:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=45015705</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=45015705</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45015705</guid></item><item><title><![CDATA[New comment by pwlb in "Ten years of JSON Web Token and preparing for the future"]]></title><description><![CDATA[
<p>You may have a look at this (still a Draft): <a href="https://datatracker.ietf.org/doc/draft-ietf-oauth-status-list/" rel="nofollow">https://datatracker.ietf.org/doc/draft-ietf-oauth-status-lis...</a></p>
]]></description><pubDate>Mon, 26 May 2025 07:35:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=44094946</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=44094946</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44094946</guid></item><item><title><![CDATA[New comment by pwlb in "A planned EU regulation about website certificates is causing concern"]]></title><description><![CDATA[
<p>Where exactly do people move if they only chose between Firefox and Chrome, there is not enough competition in the browser market</p>
]]></description><pubDate>Mon, 28 Feb 2022 16:26:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=30501652</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=30501652</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30501652</guid></item><item><title><![CDATA[New comment by pwlb in "Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'"]]></title><description><![CDATA[
<p>First,which DID methods will be successful is a question of time, additional your wallet app could support multiple of these DID methods.
Second, DID  and the corresponding keys are supposed to be owned by the user or managed by a platform, any indivdual can make the choice whteher he wants convience of managed keys or full privacy under his own control
Third, you can have a seperate DID for every service and they issue you an login credential for that particular service.</p>
]]></description><pubDate>Thu, 30 Sep 2021 12:36:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=28705588</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=28705588</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28705588</guid></item><item><title><![CDATA[New comment by pwlb in "Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'"]]></title><description><![CDATA[
<p>Not necessarily is DID connected to publishing something on a blockchain. First: DID does not make any statements to the underlying infrastructure, this can be a completely decentralized public, permissionless blockchain but also public, permissoned ledger(also decentral but a little less) or the did Methods using a central server as referenced in the w3c mozilla response.
DID for example solves/enables some aspects of the 10 principles of SSI, e.g. portability</p>
]]></description><pubDate>Wed, 29 Sep 2021 12:52:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=28692931</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=28692931</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28692931</guid></item><item><title><![CDATA[New comment by pwlb in "Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'"]]></title><description><![CDATA[
<p>not yet, but identity giants like okta and ping are already looking at SSI very carefully. digital identity will be key in the next years</p>
]]></description><pubDate>Wed, 29 Sep 2021 12:37:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=28692805</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=28692805</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28692805</guid></item><item><title><![CDATA[New comment by pwlb in "Response to 'Call for Review: Decentralized Identifiers (DIDs) v1.0'"]]></title><description><![CDATA[
<p>Self-Sovereign Identity and DIDs are a very fast moving train. People argue that in the early internet days there was a similar competition between new protocols(compare with DID methods) before we arrive in our todays HTTP(S)-only world. Similarly DID methods will probably consolidate to a handful within few years and DID Core is only a first step to get a minimal common denominator.
Also its questionable if Microsoft&Google and the others are fearing a rapidly evolving ecosystem that they can not jump on as fast and therefore remain sceptic in any case</p>
]]></description><pubDate>Wed, 29 Sep 2021 09:28:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=28691762</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=28691762</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28691762</guid></item><item><title><![CDATA[New comment by pwlb in "Only 6 of the 50 largest companies are in Europe. LVMH is highest at #18"]]></title><description><![CDATA[
<p>That sounds like a view from last century. FAANG multinational, sovereign companys and they are interested in money and are not interested in  losing their userbase. moreover a lot of these companys have offices in europe as well, so part of these solutions are developed in europe as well. having the HQ in one country is only one aspect of a company</p>
]]></description><pubDate>Mon, 14 Jun 2021 22:43:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=27509276</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=27509276</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27509276</guid></item><item><title><![CDATA[New comment by pwlb in "Cryptography and how to deal with man-in-the-middle attacks in JavaScript"]]></title><description><![CDATA[
<p>Core mechanisms to prevent Man-in-the-Middle are missing in the article: PublicKey/certificate-Pinning or PKIs. Cryptography is best left to the experts, most of todays javascript developers are probably missing the knowledge to implement or use it in a correct way</p>
]]></description><pubDate>Thu, 29 Apr 2021 13:04:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=26980637</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=26980637</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=26980637</guid></item><item><title><![CDATA[New comment by pwlb in "The reason Okta spent $6.5B on Auth0"]]></title><description><![CDATA[
<p>Self-Sovereign Identity might  replace major parts of the federated identity market within 5 years i expect. even Okta CEO admitted that self-sovereign identity will be the future. the major problem is that the decentralized nature of SSI, will remove the most part and profit of 3rd party tools, as it is easier and cheaper to have direct relations between services and users</p>
]]></description><pubDate>Fri, 05 Mar 2021 21:21:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=26362275</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=26362275</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=26362275</guid></item><item><title><![CDATA[New comment by pwlb in "Czech gunmaker CZG buys Colt in cash and stock deal"]]></title><description><![CDATA[
<p>Is there any country in history that prevented its downfall because its civilians are armed to the teeth?</p>
]]></description><pubDate>Fri, 12 Feb 2021 17:13:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=26115917</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=26115917</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=26115917</guid></item><item><title><![CDATA[New comment by pwlb in "I made Deskreen, open source app to make any device a second screen for computer"]]></title><description><![CDATA[
<p>Anybody who wants to this with Linux: scrcpy
uses adb(turn on usb debug) und works like a charm</p>
]]></description><pubDate>Mon, 18 Jan 2021 22:30:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=25827481</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=25827481</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=25827481</guid></item><item><title><![CDATA[New comment by pwlb in "Show HN: See the Price of Stocks in BTC"]]></title><description><![CDATA[
<p>comparing all the stocks, seeing that only tesla is in a stable curve near the end, leads me to the following conclusion: Both Tesla and Bitcoin are heavily overpriced!</p>
]]></description><pubDate>Tue, 12 Jan 2021 11:09:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=25745267</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=25745267</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=25745267</guid></item><item><title><![CDATA[New comment by pwlb in "Poll: Switching from WhatsApp"]]></title><description><![CDATA[
<p>encryption is only and-to-end, and searching on your device is easily doable</p>
]]></description><pubDate>Thu, 07 Jan 2021 17:17:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=25673907</link><dc:creator>pwlb</dc:creator><comments>https://news.ycombinator.com/item?id=25673907</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=25673907</guid></item></channel></rss>