Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
aaronpk
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
aaronpk
1y ago
It refers to the property of FedCM that means nothing about your account is revealed to the website until you click the "Continue As" button. In other words, alternatives to this that use third-party cookies enable tracking you be
2.
▲
by
aaronpk
1y ago
I wrote a much more narrative version of what this is useful for here: https://aaronparecki.com/2025/05/12/27/enterprise-ready-mcp It isn't exclusive to MCP, it applies to any regular OAuth connecti
3.
▲
by
aaronpk
2y ago
"nothing inherently bad" other than: (a list of things that are specifically bad implementations) In my demos the OAuth flow completes so fast you can't even tell it happened, you don't even see the address bar change to
4.
▲
by
aaronpk
3y ago
I have chosen to interpret your response as sarcasm
5.
▲
by
aaronpk
3y ago
Exactly. Even in a relatively dense location, I have a new automation that runs when my cameras detect a person, both blaring a siren outside as well as notifying me in the house. Now about half a dozen times, it has stopped someone from ge
6.
▲
by
aaronpk
3y ago
sorry my sarcasm didn't make it through the computer screen
7.
▲
by
aaronpk
3y ago
what if data collection as a hobby is the end goal
8.
▲
by
aaronpk
3y ago
Discord is just fancy IRC
9.
▲
by
aaronpk
3y ago
oh hi. Yes I moved to Libera a while back and am still there regularly.
10.
▲
by
aaronpk
5y ago
No it was just a bad take
11.
▲
by
aaronpk
5y ago
Check out the actual spec, there's nothing in IndieAuth that relies on third parties. The whole point is so you can authenticate as your own domain to other things. There are some helper services that let you authenticate via Twitter&#
12.
▲
by
aaronpk
5y ago
ActivityPub by definition doesn't work with a static site. But check out this project which offloads the ActivityPub parts for any site assuming you can make a request there as part of your static site build process https://
13.
▲
by
aaronpk
6y ago
> edit: Also, why doesn't webmention.io display its own mentions to utilize the two-way communication it advertises? Seems like a no-brainer to show prospective users an example of it working in action This is a good idea, and if I
14.
▲
by
aaronpk
6y ago
The good news is everyone who receives webmentions can decide what it looks like themselves! In fact you'll see quite a lot of variation in how these are displayed on people's websites. Everything from a list of comments, to just
15.
▲
by
aaronpk
6y ago
HN does not as far as I know, but Lobsters does! https://github.com/lobsters/lobsters/pull/535
16.
▲
by
aaronpk
6y ago
Don't think of it as comments on blog posts, think of it as enabling entire conversation threads between websites instead of between twitter accounts.
17.
▲
by
aaronpk
6y ago
I'd happily accept a PR to the docs! I launched this service in... 2012
18.
▲
PKCE vs. Nonce: Equivalent or Not?
(danielfett.de)
1 points
by
aaronpk
6y ago
|
0 comments
19.
▲
by
aaronpk
6y ago
I'm having a different (but likely related) problem, which is that my SMTP stopped working today. I have a legacy Google Apps account on a custom domain, and have had two-factor auth configured for years. Today my SMTP credentials stop
20.
▲
by
aaronpk
7y ago
No, you're confusing things again. Your example includes two separate OAuth/OIDC flows. Dropbox as the client to Google, and the camera app as a client to Dropbox.
21.
▲
by
aaronpk
7y ago
For those of you wondering how this is different from OpenID Connect: https://indieweb.org/How_is_IndieAuth_different_from_OpenID_...
22.
▲
What the Heck Is Sign in with Apple?
(developer.okta.com)
4 points
by
aaronpk
7y ago
|
1 comments
23.
▲
Is the OAuth 2.0 Implicit Flow Dead?
(developer.okta.com)
2 points
by
aaronpk
7y ago
|
0 comments
24.
▲
by
aaronpk
8y ago
No picture you see is exactly what came out of the camera. As the author points out at the end of the article, if your camera outputs a jpg image, then it's already made its own decisions of how to manipulate the raw data.
25.
▲
A Journey to the Underworld That Is RDF
(petermolnar.net)
3 points
by
aaronpk
8y ago
|
1 comments
26.
▲
If It Ain't TypeScript It Ain't Sexy
(developer.okta.com)
50 points
by
aaronpk
8y ago
|
45 comments
27.
▲
by
aaronpk
8y ago
I can't believe this post is making the rounds again six years later. Reply All did a great podcast about a similar issue, it's worth a listen! https://www.gimletmedia.com/reply-all/104-case-phantom-calle...
28.
▲
Okta’s PassProtect checks your passwords with ‘Have I Been Pwned’
(techcrunch.com)
4 points
by
aaronpk
8y ago
|
0 comments
29.
▲
by
aaronpk
8y ago
Here's a table showing the "old" lost technologies with the new ones that have been replacing them https://indieweb.org/lost_infrastructure
30.
▲
WebAuthn: A Developer's Guide to What's on the Horizon
(developer.okta.com)
6 points
by
aaronpk
8y ago
|
0 comments
More ›