Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
deepakprab
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
deepakprab
4y ago
Tracking and mapping where your sensitive data goes is challenging and manual approaches always fall short. This is a very unique unique approach to preventing sensitive data leakage.
2.
▲
by
deepakprab
4y ago
We (BoxyHQ) are an SSO and Directory Sync vendor like WorkOS and they are spot on with the details of the SAML vulnerabilities. We have guarded against these attacks so our customers don't have to but plenty of companies still roll out
3.
▲
by
deepakprab
4y ago
It's just riddled with vulnerabilities but most of them are now well known and mitigated. OpenID was meant to be the successor but popularity wise SAML is still the champion with enterprises. SCIM doesn't really have a successor a
4.
▲
by
deepakprab
4y ago
Great suggestion, SAML SSO should really become commodity and made available to all tiers. Enterprise tiers are clearly dictated RFP/Security Questionnaires, there's no bigger admin hassle than that.
5.
▲
by
deepakprab
4y ago
You could make SSO setup self-served. Happy to help you simplify your SSO implementation so you can make it available across all tiers, open-source on an Apache 2.0 license - https://github.com/boxyhq/jackson
6.
▲
by
deepakprab
4y ago
Indeed, one common interface for the sync that captures all the nuances of multiple identity providers implementing the SCIM protocol. Thanks IvoSolveoYCSS19.
7.
▲
by
deepakprab
4y ago
Plugging in my startup BoxyHQ here. This is the reason why we open sourced our SAML integration - https://github.com/boxyhq/jackson , it should be commodity.
8.
▲
by
deepakprab
4y ago
Plugging in my startup BoxyHQ here. This is the reason why we open sourced our SAML integration - https://github.com/boxyhq/jackson , it should be commodity.
9.
▲
by
deepakprab
4y ago
I'd love to join the conversation. My email is deepak at boxyhq.com
10.
▲
by
deepakprab
4y ago
Absolutely, we mention this excellent resource in the blog. Also https://www.enterprisegrade.io/ to take a self-assessment of your enterprise readiness.
11.
▲
Be enterprise-ready: reasons not to build enterprise features
(boxyhq.com)
43 points
by
deepakprab
4y ago
|
37 comments
12.
▲
by
deepakprab
4y ago
I agree, something like 80 SaaS apps on average per enterprise apparently. I like to call it Death by SaaS! ;)
13.
▲
by
deepakprab
4y ago
Which bits specifically? :)
14.
▲
by
deepakprab
4y ago
You have to look at it from the perspective of the Enterprise and you'll see that everything you list as risks is exactly what helps them mitigate their other critical risks: - Lets them centralise access, provisioning and de-provision
15.
▲
by
deepakprab
4y ago
Disclaimer: I am the co-founder of BoxyHQ, an open-source alternative to WorkOS. Historically SSO (especially SAML), Directory Sync, Audit logs, enhanced roles/permissions, etc. have always been something that only Enterprises needed.
16.
▲
by
deepakprab
4y ago
Thanks Eric, That is a great suggestion. SSO starter content is in the works including product integration guides. It is a nodejs service (or can be embedded as an npm). We are looking at potentially supporting other languages but for now o
17.
▲
by
deepakprab
4y ago
Hey everyone, we are Deepak and Sama, co-founders of BoxyHQ. We are posting our enterprise SSO project to seek feedback from the Reddit community. Over the past few months, the team has been working really hard on our SAML SSO project, our
18.
▲
Show HN: Open-source enterprise SSO – integrate SAML with a few lines of code
(github.com)
24 points
by
deepakprab
4y ago
|
4 comments
19.
▲
by
deepakprab
4y ago
Please do give SAML Jackson a try, we've married SAML with OAuth2.0 - https://github.com/boxyhq/jackson
20.
▲
by
deepakprab
4y ago
This is one of our motivations at BoxyHQ, to commoditize enterprise-readiness features. SAML SSO should be available on all plans without crazy markups on the pricing. Vendors should separate their core enterprise features from undifferenti
21.
▲
Show HN: Open-source testing tool for SAML SSO integrations (mocksaml.com)
4 points
by
deepakprab
4y ago
|
0 comments
22.
▲
by
deepakprab
4y ago
Amazing, thank you. I'll definitely reach out if I have any questions.
23.
▲
by
deepakprab
4y ago
Thanks mooreds, we are all working towards a common mission. Looking forward to expanding the market togather.
24.
▲
by
deepakprab
4y ago
Hi mooreds, would love to get access to a FusionAuth account where we could set up and test your SAML identity provider (would also help us build an instructions guide for FusionAuth customers). Could you make this happen?
25.
▲
by
deepakprab
4y ago
Ory seems like a modular Keycloak, they don't seem to support SAML as a Service Provider yet which is the one thing we do well.
26.
▲
by
deepakprab
4y ago
Thanks zwayhowder, that's a great summary!
27.
▲
by
deepakprab
4y ago
Great question, I would think Shibboleth might cover some of the topics you are looking for. I am not too experienced with the education sector, would love to chat further to get a better understanding.
28.
▲
by
deepakprab
4y ago
Would love to see both Auth0 and WorkOS go open-source as well! ;) Jokes aside, hi grinich. Would love to catch up sometime, my email is deepak@boxyhq.com
29.
▲
by
deepakprab
4y ago
Haha, love it. Hope no one was fed up! Do you recollect the other names?
30.
▲
by
deepakprab
4y ago
At a high level it lets you separate (and centralize) your PII data from your main infrastructure whilst providing configurable semantics on how the data should be encrypted underneath. Additionally you'd have granular control (and aud
More ›