Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
omgitstom
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
omgitstom
4y ago
I'm unsure why the distinction matters that was brought up in the post. It really comes down to what do you need to support, and how much weight you can swing. Are you a small time supplier, and want a major retailer to integrate with
2.
▲
by
omgitstom
7y ago
My dad passed away with dementia in 2019, spent a lot of time in nursing homes and also making decisions about the care of my father. I actually got to see this first hand with his caregivers in his facility. The requests to put him on di
3.
▲
by
omgitstom
7y ago
Being in the authentication/authorization space for a while, this couldn't be truer. If OAuth 2.0 was a compelling differentiator from your API standpoint, they are doing it wrong.
4.
▲
by
omgitstom
9y ago
I love how Ajit keeps saying 'it does not happen' where traffic is limited or blocked. It was limited, we saw this by Comcast with Netflix back in 2014. This is what we are getting ready to get back into. I do not want to have a
5.
▲
by
omgitstom
10y ago
TL;DR Twitter gave the police information about the phone number which registered the account that sent the seizure-triggering gif AT&T gave the police information that is was a Tracfone prepaid account with an associated toll record th
6.
▲
by
omgitstom
10y ago
Bad is relative, it is bad compared to other more secure methods. But if you can't guarantee that your users have a smartphone, SMS is still a needed option.
7.
▲
by
omgitstom
10y ago
They support 2FA through SMS / TOTP / U2F. Yes, if most of their customers use GA / etc it is free, but that isn't their only option... If they implemented a provider, they will also charge for TOTP authentications.
8.
▲
by
omgitstom
10y ago
I'm sure Dropbox is going to get a lot of flak for this. 2FA based on the provider that they use may not have been cheap. Authy is $0.09 an auth, if you integrate with Twilio, you get SMS charges that vary on price based on country &
9.
▲
by
omgitstom
10y ago
Here you go: https://cl.ly/3q3d293k2N3X
10.
▲
by
omgitstom
10y ago
Head of Product @ Stormpath It doesn't really matter where you start, as long as you can relate to the product and its customers. I've seen great PM from every beginning. My beginning was a normal comp sci background -> dev -&
11.
▲
by
omgitstom
10y ago
Auction information is here: https://github.com/theshadowbrokers/EQGRP-AUCTION
12.
▲
by
omgitstom
10y ago
This question is a little vague. My assumption is you mean a REST API. This is a must watch and encapsulates good design and theory: https://www.youtube.com/watch?v=hdSrT4yjS1g Good API design, if you are trying to learn f
13.
▲
by
omgitstom
10y ago
"The U.S. Marshals Service (USMS) offers property for sale to the public which has been forfeited under laws enforced or administered by the United States Department of Justice, its investigative agencies (Drug Enforcement Administrati
14.
▲
by
omgitstom
10y ago
"Sleeping animals are incredibly vulnerable to attacks, with no obvious benefit to make up for it — at best, they waste precious hours that could be used finding food or seducing a mate; at worst, they could get eaten." It seems p
15.
▲
by
omgitstom
10y ago
Acquisitions are complicated in tax law. There was a good write-up about this in Forbes about a year ago that your question reminded me of: http://www.forbes.com/sites/anthonynitti/2015/10/05/tax-ge
16.
▲
by
omgitstom
10y ago
It isn't about the vesting periods, it is about the exercise period. Vesting periods are fine in most cases. The exercise period is usually 90 days, if you leave a company. What happens a lot is there is no liquidation event for years
17.
▲
by
omgitstom
10y ago
All of these points are sound. There are some benefits of using a JWT over a session identifier, though. And I think that most of these were covered in the comments of your first post. We have an implementation of JWTs @ Stormpath for Toke
18.
▲
Stop using JWT for sessions, part 2: Why your solution doesn't work
(cryto.net)
3 points
by
omgitstom
10y ago
|
1 comments
19.
▲
by
omgitstom
10y ago
Always happy to get feedback. Again, this article was written back in 2014, and will be updated. In regards to your advice about id_tokens and access_tokens. Usually, what I've seen in most attacks is that if a malicious user can get
20.
▲
by
omgitstom
10y ago
Definitely not pedantic! Believe it or not, JOSE was still a draft when this blog post was released into the wild.
21.
▲
by
omgitstom
10y ago
Thanks, Evan. these are all good points, I'm surprised to see this on HN since it is an old article I wrote. In regards to the replay attacks, if you are using JWTs in a 3 party setup, and they are validating JWTs locally (not sending
22.
▲
by
omgitstom
10y ago
Every company will want a PM that understands their vertical. This isn't as simple as researching, a PM should never interview without using the product and using as many of the competitors products as possible. Every company wants a
23.
▲
by
omgitstom
10y ago
What has happened with web storage since 2015-09-09 that makes their recommendations out of date?
24.
▲
by
omgitstom
10y ago
As a developer, I feel like I have more control over mitigating CSRF then XSS. But where I have more issues is that OWASP clearly advises not to use web storage for identities: + A single Cross Site Scripting can be used to steal all the da
25.
▲
by
omgitstom
11y ago
I think if you really wanted to think outside of box for this, quantum entangled particles is your best bet for instantaneous low energy communication
26.
▲
by
omgitstom
11y ago
To add to this, the author brought up another interesting point, the organization you belong to should not own the identity. This will allow the identity to be associated with 0..* organization and the data associated with your identity ca
27.
▲
by
omgitstom
11y ago
Side effects of Sprycel: http://www.drugs.com/sfx/sprycel-side-effects.html
28.
▲
by
omgitstom
11y ago
Metal filings can wreck havoc on your lungs / eyes - please use safety precautions if you are attempting this at home
29.
▲
by
omgitstom
11y ago
Does anyone know how many foxes they started with for the experiment?
30.
▲
by
omgitstom
11y ago
I spend some time with API Gateway this weekend. Since I work at a company that has a product that helps customers with authentication and authorization for APIs, I am always curious where everyone else is skating. Your section about authen
More ›