I'm curious how fixing these sorts of events gets funded. I imagine the expense is massive. Is it insurance? Is the allocated amount anywhere near proportional to the money being lost to being stuck? Who eventually bears the cost?
I've used Anki (spaced repetition app) with some success. I haven't been particularly dedicated. However, I know it's something that many people use and get results.
The fingerprint reader on my Thinkpad X1 Carbon (gen 7) can work as a FIDO device. I just re-tested it on https://webauthn.io/ with Firefox in Windows 10. I'm guessing other fingerprint readers will too. You need to know that it will be considered a "Platform" device rather than a "Cross platform" device, which is what YubiKeys are considered.
Related but not answering your question: I haven't found any major website that support Platform FIDO devices. I'm guessing they only want 2FA devices which can roam between computers. I think that's unfortunate. Perhaps a good policy would be to allow Platform devices to be used after a Cross Platform device has been registered first. But there are few websites that support multiple FIDO keys to begin with.
How nice would it be to log into websites with your builtin fingerprint reader? The client side stuff seems ready to go.
Hey Matthias! I know this is off topic for the thread but thanks for jhead! I used it for years in order to sync up the exif times from friend's cameras when we traveled together. I was pleasantly surprised to see your name when looking at the man page.
Love your channel. All the best with your new little one!
Years ago, I was sitting next to John Conway and another older Professor in a small computer lab in Fine Hall (Princeton's math building) while waiting to meet my advisor. What I remember most about listening in on their conversation was how much fun it seemed they were having. Especially Conway. It was like he was engrossed in a really fun game and was trying to come up with new ways of thinking about the rules. I think you can see that in his work too.
The pure joy he took in his work is something I admired.
Moreover, if a physically undetected clone is managed, it will be detected soon through the spec. The WebAuthn spec includes monitoring an always increasing counter for each key/site pair. One of the clones will start to fail.
So really there's no point in cloning. Straight up theft is the bigger concern.
I remember them being useful when my phone was resting on my desk at work. This was before always on notifications were as prolific and advanced as they are today.
I could wave my hand to check the time. Or see what was causing the most recent notification chime. It sounds really simple but not having to pick up the phone meant reducing distraction.
The Moto X's gestures couldn't be much more than a hand wave due to the simplicity of the sensor. But even so, they kept me from picking up my phone quite a bit.