Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
npoturnak
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
npoturnak
4y ago
Thank you for taking a look. Magic plays in a different market. There are primarily 2 markets for identity - consumer identity and enterprise identity. Consumer identity - you are developing a scheduling application. You need to log the use
2.
▲
by
npoturnak
4y ago
Ping Identity is heavily enterprise centric. Have on-premises and cloud offerings. Great for SAML Single Sign-On. Ping Identity does not do anything for infrastructure access. You have to have a separate product for that.
3.
▲
by
npoturnak
4y ago
Thanks for taking a look. Both are great platforms indeed. To my knowledge StrongDM is only connectivity, no passwordless authentication to downstream resources. We offer similar functionality to that of Teleport, but try to abstract comple
4.
▲
by
npoturnak
4y ago
Great perspective, thank you for sharing. I might agree with this statement in the context of consumer authentication - when I am accessing my personal apps, websites, etc. Especially e-commerce is sensitive to login friction. In my opinion
5.
▲
by
npoturnak
4y ago
Thank you for your question. We do not touch or manage biometric data. When you use our Passwordless MFA mobile application to login, you use Face ID to unlock the certificate in the hardware backed storage, and then that certificate is use
6.
▲
by
npoturnak
4y ago
Thank you for reading through the security paper. Please find relevant points that explains the product security. 1. We have been very diligent and do not expose any sensitive user related metadata in any public api that is unauthenticated.
7.
▲
by
npoturnak
4y ago
Thank you. Very valid points and feedback. We would not position our product to very large enterprises with thousands of users. Indeed, they will deploy best of breed products - separate SSO, separate password manager, separate VPN etc. The
8.
▲
by
npoturnak
4y ago
To my knowledge Cloud Flare is about connectivity and authorization. They outsource authentication to external identity provider (Okta, etc.) and do not actually log you into downstream resources. Cloud Flare can also do basic device postur
9.
▲
by
npoturnak
4y ago
Appreciate your feedback. We have been prioritizing security from day one. We are SOC2 compliant, have conducted white box penetration with Cure53 to validate designs and crypto, architected our platform with modern protocols such as FIDO2,
10.
▲
by
npoturnak
4y ago
Thank you for taking a look, appreciate feedback. In an ideal world we would like to be passwordless 100%. And we can already do that with SAML/OIDC apps, SSH, etc. For these flows passwords do not exist. However, the companies we work
11.
▲
Launch HN: Idemeum (YC S21) – Passwordless access to apps and infrastructure
108 points
by
npoturnak
4y ago
|
54 comments