Tim Cappalli's Avatar

Tim Cappalli

@timcappalli.me

πŸ” #passkeys πŸͺͺ verifiable digital credentials πŸ’ bruins ⚾️ sox πŸš† urban mobility πŸ‰ cars ruin cities

1,138
Followers
304
Following
1,239
Posts
27.04.2023
Joined
Posts Following

Latest posts by Tim Cappalli @timcappalli.me

Post image

hahahha forgot about the crappy Apple keyboard lawsuit.

09.03.2026 18:11 πŸ‘ 11 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

A walk on the first 60Β° day in Boston is always life changing.

Temporary relief from existential dread and depression.

09.03.2026 17:40 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Charles River Esplanade: 2026 USA TODAY 10BEST Readers' Choice Awards The Charles River Esplanade in downtown Boston features a 64-acre park and a series of running trails along the waterfront. The riverfront is also home to a community boat launch, a small cafe that's ...

Vote for the Charles River Esplanade for Best Riverwalk!

#boston

10best.usatoday.com/awards/charl...

09.03.2026 16:17 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
U.S. Tomahawk Hit Naval Base Beside Iranian School, Video Shows The evidence contradicts President Trump’s claim that Iran was responsible for a strike at the school that killed 175 people, most of them children.

Breaking News: New video adds to evidence that a U.S. missile likely hit an Iranian school where 175 people, many of them children, were reportedly killed.

09.03.2026 02:40 πŸ‘ 2560 πŸ” 1150 πŸ’¬ 169 πŸ“Œ 150
Post image

hellloooooo spring! #boston

08.03.2026 23:04 πŸ‘ 102 πŸ” 10 πŸ’¬ 0 πŸ“Œ 0

Zachaaaaa 🧒🧒🧒

08.03.2026 23:03 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Yeah, it's a challenge. I don't typically promote 1Password for... reasons, but I do think they do a good job at storing federated accounts in the vault to help address this.

07.03.2026 17:23 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

it's another big reason why I recommend folks not use consumer federation and instead use passkeys (the other reason being privacy).

07.03.2026 17:19 πŸ‘ 4 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

Not expected. You're supposed to use the pairwise sub claim in the token to link to the user account, not the email (or phone) identifier.

But unfortunately many implementations don't follow the spec.

There's been some high profile account takeovers because of this.

07.03.2026 17:18 πŸ‘ 8 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

DHS nominee Markwayne Mullin is one of the most active stock-traders in the Senate β€” and violated the STOCK Act against insider trading as recently as last August.

He currently holds stock in L3Harris, which has millions in contracts with ICE and FEMA.

The grift continues.

06.03.2026 19:45 πŸ‘ 16358 πŸ” 7377 πŸ’¬ 530 πŸ“Œ 384

wtf @massgovernor.bsky.social

05.03.2026 14:48 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Term limits would literally change everything. I wish more people would see that.

05.03.2026 14:07 πŸ‘ 2 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

The lack of a biometric sensor on the base level MacBook Neo is really unfortunate.

It's going to add a lot of fragmentation to many experiences, especially since macOS does not have a device PIN concept.

04.03.2026 18:25 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

the cross-device flow is an exception case when you don't have a passkey on your local device.

03.03.2026 03:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

that's not actually what makes a credential phishing resistant. Signing over the origin provided phishing protection. Passkeys always provide this, regardless of whether they're stored on security keys or a software credential manager.

03.03.2026 03:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

If someone asks for avocado or your menu says avocado, and you use guacamole, you should lose your restaurant license immediately.

This is worse than someone asking for Diet Coke and you give them Diet Pepsi.

01.03.2026 16:07 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

synced passkeys in the consumer ecosystem are not attested.

01.03.2026 13:37 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Please, please, please stop using passkeys for encrypting user data Passkeys are the future of authentication, but using them for data encryption is a disaster waiting to happen. Overloading these credentials creates a dangerous blast radius that can lead to the irrev...

Please, please, please stop using #passkeys to encrypt user data. Please πŸ™πŸ»

blog.timcappalli.me/p/passkeys-p...

27.02.2026 16:22 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

β€œThe Court is not aware of another occasion in the history of the United States in which a federal court has had to threaten contempt β€” again and again and again β€” to force the United States government to comply with court orders,”

27.02.2026 12:32 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

The headline should be clearer: the US government is threatening to destroy a company that won’t capitulate to its illegal demands.

27.02.2026 11:11 πŸ‘ 26 πŸ” 4 πŸ’¬ 1 πŸ“Œ 0

Looks like Google Wallet already has support for Aliro πŸŽ‰

27.02.2026 11:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

hahhah these clowns have zero brain cells

27.02.2026 03:21 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

imo the threat posed by CBS News and CNN getting absorbed by pro-regime billionaires isn't that they're going to produce right-wing slop that convinces people to be right-wing, it's the dismantling of newsrooms capable of doing investigative reporting on the administration. Fewer eyes on the street.

27.02.2026 00:40 πŸ‘ 7208 πŸ” 1746 πŸ’¬ 144 πŸ“Œ 102
Post image

really #Spotify?

26.02.2026 20:52 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

When a trans person’s ID doesn’t match their appearance, every interaction where they have to show that ID becomes a potential outing. A traffic stop. A job orientation. A TSA checkpoint. You hand someone your license and suddenly they’re looking at you differently, or asking questions, or worse.

26.02.2026 14:34 πŸ‘ 822 πŸ” 145 πŸ’¬ 2 πŸ“Œ 5
Preview
What is a passkey? The easy explanation - and how they beat passwords Yes, the technology behind passkeys can be confusing. Here's a simple guide to help you ditch passwords today.

TLDR: Passkey good. #security

What is a passkey? The easy explanation - and how they beat passwords www.zdnet.com/article/what...

25.02.2026 19:26 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

It turns out Russ Vought knows how to get to the Capitol after all...

He should stop hiding and come testify before the Budget Committee about Trump's cost-of-living crisis.

25.02.2026 02:41 πŸ‘ 411 πŸ” 91 πŸ’¬ 3 πŸ“Œ 1
Preview
Justice Department withheld and removed some Epstein files related to Trump An NPR investigation finds the public database of Epstein files is missing dozens of pages related to sexual abuse accusations against President Trump.

An NPR investigation finds the public database of Epstein files is missing dozens of pages related to sexual abuse accusations against President Trump. n.pr/4qTItsU

24.02.2026 10:11 πŸ‘ 10200 πŸ” 5127 πŸ’¬ 335 πŸ“Œ 629