Sign in

Arian van Putten

@arianvp.me
482 followers 93 following 160 posts

Working on banking infra at @mercury@twitter.com prev: @feeldco@twitter.com, @wire@twitter.com Opinions are my own and do not reflect that of my (past) employer(s)

PostsRepliesMedia
Arian van Putten @arianvp.me · 28/09/2026
Are you gonna be at ASG? I’m landing 2 October in the morning
100
Arian van Putten @arianvp.me · 31/07/2026
I’m actually very tired of all the Americans having takings in Ceuta. Both on left and right (or whatever you call your weird ideologies over there) the takes are so off with so little respect of history that I can only conclude you’re all brainwashed to the max.
020
Arian van Putten @arianvp.me · 30/07/2026
Would be Nice to add examples for both the app usecase and the different cctld usecase though . So that it’s clear for people how to do them
example.de
3erlei - Malerei
010
Arian van Putten @arianvp.me · 30/07/2026
Ah yeh gotcha. Especially as on the mobile Origin you can even serve some extra challenges like AppAttest or SafetyNet to get an attestation about the appid. Okay I’m convinced. Forcing the choice to one origin makes sense
110
Arian van Putten @arianvp.me · 30/07/2026
Rpid* not app id. iOS autocomplete screwing me
000
Arian van Putten @arianvp.me · 30/07/2026
So on the client side multiple origins map to one rpid and on the server side one rpid maps to multiple origins. It seems very tight to me? The client will always contact the rp for the origin list so potential for abuse seems nil
100
Arian van Putten @arianvp.me · 30/07/2026
For iOS and android you need to explicitly allow list which origins are equivalent to your appid <Relying Party ID>/.well-known/apple-app-site-association Must list the app id origins that are allowed for the appid
200
Arian van Putten @arianvp.me · 30/07/2026
Would I instead instantiate for each origin separately? Instead of reusing the same object?
100
Arian van Putten @arianvp.me · 30/07/2026
So I think making Origin a single string is purposefully a misfeature for production webauthn deployments. Your post seems to suggest you made it a deliberate choice. Could you elaborate why?
100
Arian van Putten @arianvp.me · 30/07/2026
I chose OriginPolicy to work the same as the acme autocert package so that it’s familiar and reusable
100
Arian van Putten @arianvp.me · 30/07/2026
The related origins feature is useful if you want your amazon com passkey to work in amazon de for example
100
Arian van Putten @arianvp.me · 30/07/2026
One hardcoded Origin is not enough for proper passkey support and I suggest you take the OriginPolicy approach I have in the original approach. This is because 1) one RP can support multiple origins (all its subdomains can be valid origins) 2) related origins allow cross-domain webauthn
100
Arian van Putten @arianvp.me · 29/07/2026
I’ll take some time to read it in detail and give feedback:)
100
Arian van Putten @arianvp.me · 29/07/2026
This looks great! This proposal seems to replace what I started at github.com/golang/go/is...
github.com
proposal: crypto/webauthn: webauthn signature verification API · Issue #71095 · golang/go
Proposal Details Passkey Authentication is seeing wide-spread industry adoption for authenticating users on websites and is implemented through the https://w3c.github.io/webauthn specification. It ...
100
Arian van Putten @arianvp.me · 17/07/2025
Really really don't like that Zed downloads random binaries without my consent. They also most of the time don't work due to being dynamically linked.
120
Arian van Putten @arianvp.me · 11/07/2025
tfw you buy a chip on ebay for 1/4th the price and it turns out to be an engineering sample with an unlocked management engine
020
Arian van Putten @arianvp.me · 16/06/2025
I'm in SF from 21 jun onwards. If you want to meet up let me know!
000
Arian van Putten @arianvp.me · 16/06/2025
The problem with OIDC and SSO in general is that it only solves identifying the person but most clients all implement their own session management. This is is why I think an auth proxy is a way better strategy than configuring SSO on all your services as you have centralized session management
020
Reposted by Arian van Putten
Ricky Mondello @rmondello.com · 22/05/2025
“An update on improving passkey support in Linux” www.iinuwa.xyz/blog/linux-p...
iinuwa.xyz
Linux Passkeys Update
An update on improving passkey support in Linux
0114
Arian van Putten @arianvp.me · 26/05/2025
I guess I can talk about this now :D You should be able to sign in with Passkeys on mercury.com and the iOS app since today
Settings page showing an option to add a Passkey to your Mercury account
093
Arian van Putten @arianvp.me · 26/05/2025
The entshitification of GitHub is happening at record pace since they've replaced all their engineers with AI. The website literally is not usable anymore on slightly bad network connections. We need to abandon ship before we're all going down with it
110
Arian van Putten @arianvp.me · 22/05/2025
The useful insight was: Have you tried updating your BIOS
020
Arian van Putten @arianvp.me · 22/05/2025
Programmers uncovers inscriptions from an ancient civilization and they provide useful insights (User commenting on a thread that was created pre-AI boom)
151
Arian van Putten @arianvp.me · 15/05/2025
OpenSSF is actively harmful to the open source ecosystem. Death by bureaucracy whilst actual core library maintainers with enormous impact on our supply chain security are unemployed, unpaid, and burning out.
130
Arian van Putten @arianvp.me · 15/05/2025
More relevant than ever. > All the "best practices" like OpenSSF Scorecards are just an attempt by big tech companies to guilt trip OSS maintainers and make them work for free. gitlab.gnome.org/GNOME/libxml...
gitlab.gnome.org
Making sure you're not a bot!
121
Arian van Putten @arianvp.me · 13/05/2025
I also kept my Dutch bank account as that's connected to my PayPal and PayPal doesn't understand you can move between countries and keep your bank accounts in the original country.
000
Arian van Putten @arianvp.me · 13/05/2025
It's a nightmare and it shows how Americanocentric all these big tech companies are. Moving between countries in the EU is common and I had to go through a shitload of hoops to get my Apple, Google account into a sane state. Paypal was a lost cause and I simply never told them I moved
100
Arian van Putten @arianvp.me · 13/05/2025
404
000
Arian van Putten @arianvp.me · 13/05/2025
No it was a second hand deal on eBay. I snatched it for 500 dollars!!
110
Arian van Putten @arianvp.me · 13/05/2025
I just might have bought an Ampere Altra Max M128-30. Oops
140
Arian van Putten @arianvp.me · 12/05/2025
> At least in part because disabling these third-party cookies breaks important Single-Sign On (SSO) flow What exactly breaks in OIDC and/or SAML with Same-Site=Lax? I keep seeing this cited in various places but I can't think of a way that it would break things
000
Arian van Putten @arianvp.me · 10/05/2025
The funny thing is it does work on GitHub.com/torvalds/linux but not on github.com/cloud-hypervisor/linux which tells me GitHub has special hacks in place just so that they can support this repo to not look embarrassing
github.com
GitHub - torvalds/linux: Linux kernel source tree
Linux kernel source tree. Contribute to torvalds/linux development by creating an account on GitHub.
050
Arian van Putten @arianvp.me · 10/05/2025
1. Linux Torvalds writes git to develop linux 2. GitHub starts business on top of git 3. GitHub gets acquired by trillion-dollar MicroSoft 4. GitHub enshitifies so much you can't even browse the linux kernel on GitHub anymore Seriously???? I'm so done man.
270
Arian van Putten @arianvp.me · 09/05/2025
Honestly we might want to move off GitHub
210
Arian van Putten @arianvp.me · 09/05/2025
This is kind of dense coming from MICROSOFT who fucked us over with their AI bullshit github.blog/changelog/20...
github.blog
Updated rate limits for unauthenticated requests - GitHub Changelog
To provide a secure and dependable experience on GitHub, we’re rolling out updates to rate limits for requests made without authentication. These changes will apply to operations like cloning reposito...
121
Arian van Putten @arianvp.me · 02/05/2025
3 year anniversary of "I cant' dismiss PRs that were already merged from my notification feed" github.com/orgs/communi... I currently have 5000 unread notifications because of this. I despise GitHub so much for not addressing any kind of UX concerns
github.com
Filter notifications by `status` · community · Discussion #15591
Hey there, daily I review my work notifications from GitHub, and a feature that would be interesting is filtering notifications(PRs and issues) by status. I mean open, closed, merged by status. It ...
130
Arian van Putten @arianvp.me · 29/04/2025
Am I holding it wrong? I would really like to avoid adding a dedicated "Sign In with security key" button to our UI as it would be very confusing. Is there really no way to have people use security keys using conditional mediation except for "Use Google Chrome" ?
000
Arian van Putten @arianvp.me · 23/04/2025
`build-and-uplo... (build /` failed!!! Okay is that build-and-upload (build / x86_64-linux, nixos_2411) or build-and-upload (build / aarch64-linux, nixos_2411) ? who knows! We just randomly cut off all useful info!!!
110
Arian van Putten @arianvp.me · 23/04/2025
Dear @github.com please for the love of... Fix the CSS for Github Actions when using matrix jobs and reusable worfklows How is this readable at all? And this is a trivial matrix. I'm not doing anything complicated
100
Arian van Putten @arianvp.me · 23/04/2025
Bicep tattoo with : My other ARM is a server
010
Arian van Putten @arianvp.me · 16/04/2025
If you wanna view the zoom status page you can use curl --header 'Host: status.zoom.us' reds.craveable.support
reds.craveable.support
Red Rooster Support Status - Page Inactive
000
Arian van Putten @arianvp.me · 16/04/2025
You mean .schreibtisch files? :D
110
Arian van Putten @arianvp.me · 15/04/2025
10x engineers from DOGE have reduced the amount of CVEs in government infrastructure by 1000%. This is an amazing accomplishment that could only have been achieved with the brilliance of Elon Musk
010
Arian van Putten @arianvp.me · 15/04/2025
Perhaps www.sovereign.tech ? (German government)
sovereign.tech
Home | Sovereign Tech Agency
Investing in the infrastructure of the 21st century
050
Arian van Putten @arianvp.me · 15/04/2025
No dice. When I press the little key icon there is only an option for "Passkey from Nearby Device" and no Security Key
100
Arian van Putten @arianvp.me · 15/04/2025
Firefox works too. Albeit with more clicks as they use Apple's AuthenticationServices more and we need to click through more modals to find the Security Key option.
000
Arian van Putten @arianvp.me · 15/04/2025
Same flow on Chrome. Note that it gives me the option to either use a QR code **or** use a security key.
100
Arian van Putten @arianvp.me · 15/04/2025
Both Chrome and Firefox **do** allow security keys in this scenario. I'm trying to ship Passkeys at mercury.com and UX research shows that a dedicated "Sign in with Passkeys" button is confusing to users but we also want to keep support for Yubikeys for power-users. Safari is the odd one out.
100
Arian van Putten @arianvp.me · 15/04/2025
Hey @rmondello.com when I only implement conditional mediation for passkeys on Safari; there doesn't seem to be a button for people to use their Security Keys . In Chrome they do give this option when pressing "Use nearby device". Is this expected? It feels like a bug.
200
Reposted by Arian van Putten
mcyoung 🏳️‍🌈 @mcy.gay · 14/04/2025
new blog. i am angry about target triples mcyoung.xyz/2025/04/14/t...
mcyoung.xyz
What the Hell Is a Target Triple? · mcyoung
159519