Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
SaltNHash
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
AI security that assumes the attacker has root
(thenewstack.io)
1 points
by
SaltNHash
14d ago
|
0 comments
2.
▲
by
SaltNHash
5mo ago
Great material. Good onya for sharing!
3.
▲
by
SaltNHash
8mo ago
Tide team here. Our dev Sasha built this PoC in a few weekends, using our SDK. Her core idea: Remove the risk of compromised keys, and the overhead of managing them at scale, by never having a key to steal. Instead the SSH signing operation
4.
▲
Show HN: KeyleSSH – SSH auth where the private key never exists
(tide.org)
4 points
by
SaltNHash
8mo ago
|
1 comments
5.
▲
The god mode vulnerability that should kill "Trust Microsoft" forever
(tide.org)
50 points
by
SaltNHash
1y ago
|
31 comments
6.
▲
Show HN: Provably secure vibe coding is now a thing
(secureaf.lovable.app)
6 points
by
SaltNHash
1y ago
|
0 comments
7.
▲
by
SaltNHash
1y ago
Yes it does. It replaces it with a break glass quorum approved process.
8.
▲
by
SaltNHash
1y ago
Hi HN, Keycloak is a popular open‑source Identity & Access Management (IAM) server, but like most IAMs it lets any admin make instant, irreversible changes. In regulated or high-security setups that "god mode" is a nightmare.
9.
▲
Show HN: Open-source "God mode killer" IGA in Keycloak
(github.com)
4 points
by
SaltNHash
1y ago
|
3 comments
10.
▲
Ghost in the Network "User-as-key" architecture
(tide.org)
2 points
by
SaltNHash
1y ago
|
0 comments
11.
▲
Ants hold the key to cybersecurity's future
(infosecwriteups.com)
2 points
by
SaltNHash
2y ago
|
1 comments
12.
▲
It's cybersecurity's kryptonite: Why are you still holding it?
(infosecwriteups.com)
2 points
by
SaltNHash
2y ago
|
0 comments
13.
▲
by
SaltNHash
2y ago
Someone once asked how would you cope with lawful interception of corrupt law enforcement agencies, so allow me to explain TideCloak in that context: imagine a corrupt agency requests the identity information of a specific user of TideCloak
14.
▲
by
SaltNHash
2y ago
Regrettably, neither this particular post nor the github content has any chatgpt-inflated content. This is entirely all human-manure.
15.
▲
by
SaltNHash
2y ago
In the end, it boils down to trusting only what you can verify. Unlike any comparable system today, every cog in TideCloak's architecture is entirely verifiable to its administrators, operators and end-users – so there's no requir
16.
▲
by
SaltNHash
2y ago
License file now added to the Github, thanks! Currently, the Cybersecurity Fabric (decentralized network service) is in Beta, so we're only offering free "as-is" developer licenses. We anticipate that eventually, the service
17.
▲
Reimagining Cybersecurity for Platform Developers
(infosecwriteups.com)
7 points
by
SaltNHash
2y ago
|
0 comments
18.
▲
by
SaltNHash
2y ago
Tricky question, because the answer to this will evolve in time (as planned). First, thanks for pointing out the license issue on Github. We'll fix that right away. The Cybersecurity Fabric operates based on the Tide Protocol: our WIP
19.
▲
by
SaltNHash
2y ago
That point is pure gold! This is such a critical aspect that we hardly see addressed even in the leading platforms. This exact sentiment was the drive behind our SDKs primary premise: Assume a breach! Assume an error-prone junior dev. Assum
20.
▲
by
SaltNHash
2y ago
Not sure how to quantify "how much is new" as like all other breakthroughs are "built on the shoulders of giants". I'd find it almost impossible to answer that same question accurately if it was asked about somethin
21.
▲
by
SaltNHash
2y ago
Check how many analogies I managed to squeeze into this thought piece https://medium.com/bugbountywriteup/how-nature-holds-the-key...
22.
▲
by
SaltNHash
2y ago
So many great points raised here! Allow me to try and cover as much as possible. In a way, you can say TideCloak uses the Fabric as a key vault for (1) each user's authority (2) its own central authority. This way, even when TideCloak
23.
▲
by
SaltNHash
2y ago
You understand it perfectly. This is an example of an SPA that displays content based on authentication/roles – all client side. This was to demonstrate the simplest, most straightforward implementation in a few minutes. If you look cl
24.
▲
by
SaltNHash
2y ago
Absolutely true! And that’s only half of it. In schemes like this, how can you even tell the operators are following protocol? How do you know it's not a façade? At the edge of all those schemes, there's a point where you simply m
25.
▲
by
SaltNHash
2y ago
Analogy = Nailed! Can we use that one?
26.
▲
by
SaltNHash
2y ago
Thanks. The ideal end game is for the Cybersecurity Fabric to become a de-facto standard for best practice security inside the biggest platforms in the world (Entra, Okta, AWS, Google etc). So individuals can login with Tide (i.e. with thei
27.
▲
by
SaltNHash
2y ago
Cheers! The idea is that anyone can tap into the Fabric, but also participate in it (coming soon)
28.
▲
by
SaltNHash
2y ago
The multi-party-computation and zkps used to generate the keys, authenticate to them, encrypt / decrypt and sign with them are PQ resilient. The key presentation layer (i.e. the key standard we've currently deployed) are elliptic
29.
▲
by
SaltNHash
2y ago
Yep - there's already a working group in the Keycloak community aligning with various standards. In our case, the Cybersecurity Fabric is the component that handles ownership, secure portability and revocation.
30.
▲
Show HN: TideCloak – Decentralized IAM for security and user sovereignty
(github.com)
54 points
by
SaltNHash
2y ago
|
36 comments
More ›