Arian van Putten @arianvp.me · 28/09/2026Are you gonna be at ASG? I’m landing 2 October in the morning 100
Arian van Putten @arianvp.me · 31/07/2026I’m actually very tired of all the Americans having takings in Ceuta. Both on left and right (or whatever you call your weird ideologies over there) the takes are so off with so little respect of history that I can only conclude you’re all brainwashed to the max. 020
Arian van Putten @arianvp.me · 30/07/2026Would be Nice to add examples for both the app usecase and the different cctld usecase though . So that it’s clear for people how to do themexample.de3erlei - Malerei 010
Arian van Putten @arianvp.me · 30/07/2026Ah yeh gotcha. Especially as on the mobile Origin you can even serve some extra challenges like AppAttest or SafetyNet to get an attestation about the appid. Okay I’m convinced. Forcing the choice to one origin makes sense 110
Arian van Putten @arianvp.me · 30/07/2026So on the client side multiple origins map to one rpid and on the server side one rpid maps to multiple origins. It seems very tight to me? The client will always contact the rp for the origin list so potential for abuse seems nil 100
Arian van Putten @arianvp.me · 30/07/2026 For iOS and android you need to explicitly allow list which origins are equivalent to your appid <Relying Party ID>/.well-known/apple-app-site-association Must list the app id origins that are allowed for the appid 200
Arian van Putten @arianvp.me · 30/07/2026Would I instead instantiate for each origin separately? Instead of reusing the same object? 100
Arian van Putten @arianvp.me · 30/07/2026So I think making Origin a single string is purposefully a misfeature for production webauthn deployments. Your post seems to suggest you made it a deliberate choice. Could you elaborate why? 100
Arian van Putten @arianvp.me · 30/07/2026I chose OriginPolicy to work the same as the acme autocert package so that it’s familiar and reusable 100
Arian van Putten @arianvp.me · 30/07/2026The related origins feature is useful if you want your amazon com passkey to work in amazon de for example 100
Arian van Putten @arianvp.me · 30/07/2026One hardcoded Origin is not enough for proper passkey support and I suggest you take the OriginPolicy approach I have in the original approach. This is because 1) one RP can support multiple origins (all its subdomains can be valid origins) 2) related origins allow cross-domain webauthn 100
Arian van Putten @arianvp.me · 29/07/2026I’ll take some time to read it in detail and give feedback:) 100
Arian van Putten @arianvp.me · 29/07/2026This looks great! This proposal seems to replace what I started at github.com/golang/go/is...github.comproposal: crypto/webauthn: webauthn signature verification API · Issue #71095 · golang/goProposal Details Passkey Authentication is seeing wide-spread industry adoption for authenticating users on websites and is implemented through the https://w3c.github.io/webauthn specification. It ... 100
Arian van Putten @arianvp.me · 17/07/2025Really really don't like that Zed downloads random binaries without my consent. They also most of the time don't work due to being dynamically linked. 120
Arian van Putten @arianvp.me · 11/07/2025tfw you buy a chip on ebay for 1/4th the price and it turns out to be an engineering sample with an unlocked management engine 020
Arian van Putten @arianvp.me · 16/06/2025I'm in SF from 21 jun onwards. If you want to meet up let me know! 000
Arian van Putten @arianvp.me · 16/06/2025The problem with OIDC and SSO in general is that it only solves identifying the person but most clients all implement their own session management. This is is why I think an auth proxy is a way better strategy than configuring SSO on all your services as you have centralized session management 020
Reposted by Arian van PuttenRicky Mondello @rmondello.com · 22/05/2025“An update on improving passkey support in Linux” www.iinuwa.xyz/blog/linux-p...iinuwa.xyzLinux Passkeys UpdateAn update on improving passkey support in Linux 0114
Arian van Putten @arianvp.me · 26/05/2025I guess I can talk about this now :D You should be able to sign in with Passkeys on mercury.com and the iOS app since today 093
Arian van Putten @arianvp.me · 26/05/2025The entshitification of GitHub is happening at record pace since they've replaced all their engineers with AI. The website literally is not usable anymore on slightly bad network connections. We need to abandon ship before we're all going down with it 110
Arian van Putten @arianvp.me · 22/05/2025The useful insight was: Have you tried updating your BIOS 020
Arian van Putten @arianvp.me · 22/05/2025Programmers uncovers inscriptions from an ancient civilization and they provide useful insights (User commenting on a thread that was created pre-AI boom) 151
Arian van Putten @arianvp.me · 15/05/2025OpenSSF is actively harmful to the open source ecosystem. Death by bureaucracy whilst actual core library maintainers with enormous impact on our supply chain security are unemployed, unpaid, and burning out. 130
Arian van Putten @arianvp.me · 15/05/2025More relevant than ever. > All the "best practices" like OpenSSF Scorecards are just an attempt by big tech companies to guilt trip OSS maintainers and make them work for free. gitlab.gnome.org/GNOME/libxml...gitlab.gnome.orgMaking sure you're not a bot! 121
Arian van Putten @arianvp.me · 13/05/2025I also kept my Dutch bank account as that's connected to my PayPal and PayPal doesn't understand you can move between countries and keep your bank accounts in the original country. 000
Arian van Putten @arianvp.me · 13/05/2025It's a nightmare and it shows how Americanocentric all these big tech companies are. Moving between countries in the EU is common and I had to go through a shitload of hoops to get my Apple, Google account into a sane state. Paypal was a lost cause and I simply never told them I moved 100
Arian van Putten @arianvp.me · 13/05/2025No it was a second hand deal on eBay. I snatched it for 500 dollars!! 110
Arian van Putten @arianvp.me · 13/05/2025I just might have bought an Ampere Altra Max M128-30. Oops 140
Arian van Putten @arianvp.me · 12/05/2025> At least in part because disabling these third-party cookies breaks important Single-Sign On (SSO) flow What exactly breaks in OIDC and/or SAML with Same-Site=Lax? I keep seeing this cited in various places but I can't think of a way that it would break things 000
Arian van Putten @arianvp.me · 10/05/2025The funny thing is it does work on GitHub.com/torvalds/linux but not on github.com/cloud-hypervisor/linux which tells me GitHub has special hacks in place just so that they can support this repo to not look embarrassinggithub.comGitHub - torvalds/linux: Linux kernel source treeLinux kernel source tree. Contribute to torvalds/linux development by creating an account on GitHub. 050
Arian van Putten @arianvp.me · 10/05/20251. Linux Torvalds writes git to develop linux 2. GitHub starts business on top of git 3. GitHub gets acquired by trillion-dollar MicroSoft 4. GitHub enshitifies so much you can't even browse the linux kernel on GitHub anymore Seriously???? I'm so done man. 270
Arian van Putten @arianvp.me · 09/05/2025This is kind of dense coming from MICROSOFT who fucked us over with their AI bullshit github.blog/changelog/20...github.blogUpdated rate limits for unauthenticated requests - GitHub ChangelogTo provide a secure and dependable experience on GitHub, we’re rolling out updates to rate limits for requests made without authentication. These changes will apply to operations like cloning reposito... 121
Arian van Putten @arianvp.me · 02/05/20253 year anniversary of "I cant' dismiss PRs that were already merged from my notification feed" github.com/orgs/communi... I currently have 5000 unread notifications because of this. I despise GitHub so much for not addressing any kind of UX concernsgithub.comFilter notifications by `status` · community · Discussion #15591Hey there, daily I review my work notifications from GitHub, and a feature that would be interesting is filtering notifications(PRs and issues) by status. I mean open, closed, merged by status. It ... 130
Arian van Putten @arianvp.me · 29/04/2025Am I holding it wrong? I would really like to avoid adding a dedicated "Sign In with security key" button to our UI as it would be very confusing. Is there really no way to have people use security keys using conditional mediation except for "Use Google Chrome" ? 000
Arian van Putten @arianvp.me · 23/04/2025`build-and-uplo... (build /` failed!!! Okay is that build-and-upload (build / x86_64-linux, nixos_2411) or build-and-upload (build / aarch64-linux, nixos_2411) ? who knows! We just randomly cut off all useful info!!! 110
Arian van Putten @arianvp.me · 23/04/2025Dear @github.com please for the love of... Fix the CSS for Github Actions when using matrix jobs and reusable worfklows How is this readable at all? And this is a trivial matrix. I'm not doing anything complicated 100
Arian van Putten @arianvp.me · 16/04/2025If you wanna view the zoom status page you can use curl --header 'Host: status.zoom.us' reds.craveable.supportreds.craveable.supportRed Rooster Support Status - Page Inactive 000
Arian van Putten @arianvp.me · 15/04/202510x engineers from DOGE have reduced the amount of CVEs in government infrastructure by 1000%. This is an amazing accomplishment that could only have been achieved with the brilliance of Elon Musk 010
Arian van Putten @arianvp.me · 15/04/2025Perhaps www.sovereign.tech ? (German government)sovereign.techHome | Sovereign Tech AgencyInvesting in the infrastructure of the 21st century 050
Arian van Putten @arianvp.me · 15/04/2025No dice. When I press the little key icon there is only an option for "Passkey from Nearby Device" and no Security Key 100
Arian van Putten @arianvp.me · 15/04/2025Firefox works too. Albeit with more clicks as they use Apple's AuthenticationServices more and we need to click through more modals to find the Security Key option. 000
Arian van Putten @arianvp.me · 15/04/2025Same flow on Chrome. Note that it gives me the option to either use a QR code **or** use a security key. 100
Arian van Putten @arianvp.me · 15/04/2025Both Chrome and Firefox **do** allow security keys in this scenario. I'm trying to ship Passkeys at mercury.com and UX research shows that a dedicated "Sign in with Passkeys" button is confusing to users but we also want to keep support for Yubikeys for power-users. Safari is the odd one out. 100
Arian van Putten @arianvp.me · 15/04/2025Hey @rmondello.com when I only implement conditional mediation for passkeys on Safari; there doesn't seem to be a button for people to use their Security Keys . In Chrome they do give this option when pressing "Use nearby device". Is this expected? It feels like a bug. 200
Reposted by Arian van Puttenmcyoung 🏳️🌈 @mcy.gay · 14/04/2025new blog. i am angry about target triples mcyoung.xyz/2025/04/14/t...mcyoung.xyzWhat the Hell Is a Target Triple? · mcyoung 159519