Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
robotdan
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
1.
▲
by
robotdan
5y ago
This is a good point. Keeping it simple is always a good engineering choice. I think one of the reasons JWTs come up so often is that if you are going to use OAuth2/OpenID Connect - ideally the Authorization Code grant, then tokens bec
2.
▲
by
robotdan
6y ago
He he... enjoy. Hopefully this doesn't trigger any nightmares. https://twitter.com/bpontarelli/status/1099067076138827776?s...
3.
▲
by
robotdan
6y ago
This thread makes me feel better with struggling to implement this. I'm not the only one.
4.
▲
by
robotdan
6y ago
To add to this... not trying to hide anything on purpose. :-) https://github.com/robotdan https://www.linkedin.com/in/robotdan/
5.
▲
by
robotdan
6y ago
Thanks for the mention. We already do see quite a few Auth0 converts. I expect to gain a lot of new customers as a result of this merger in the coming months. No complaints here.
6.
▲
by
robotdan
6y ago
>> and integrated over time > I'm reading too much into this sentence fragment and it fills me with fear. Lol!
7.
▲
by
robotdan
6y ago
> + Redhat seems quite invested in it, so it has corporate backing. This could also be a bad thing, depending on your view of Redhat and which direction they take the product. Yes, true. :-) We'll see if IBM feels the same way. htt
8.
▲
by
robotdan
6y ago
Nailed it.
9.
▲
by
robotdan
6y ago
I think @tremon is just getting at that auth must be considered critical, and thus you should maintain some level of skill and competency to ensure you don't get blindsided. Perhaps the distinction is just because something isn't
10.
▲
by
robotdan
6y ago
I don't know that I'd even refer to this at outsourcing. If you can run it on premise, it is just "not building it yourself".
11.
▲
by
robotdan
6y ago
Yes, this is an excellent choice as long as all of yours apps live in the Ruby world.
12.
▲
by
robotdan
6y ago
I hope IBM/Red Hat have more sense than this, but time will tell. It may not make sense for them to maintain Keycloak with all of IBMs identity solutions.
13.
▲
by
robotdan
6y ago
FusionAuth has some k8s, helm, docker and openshift examples as well. https://github.com/FusionAuth/fusionauth-containers FusionAuth is not open source, so if that is a hard requirement, you'll have to skip it.
14.
▲
by
robotdan
7y ago
Keycloak is a good option, but if you're not a Java development it may feel a bit cumbersome to setup. There are a bunch of good options out there - and all of them are likely better than trying to go it alone!
15.
▲
by
robotdan
7y ago
Dang that is quite a list. Thanks for sharing. Makes me think twice about my current solutions.
16.
▲
The fastest way to migrate from Auth0
(github.com)
18 points
by
robotdan
7y ago
|
1 comments
17.
▲
IAM AMA: OAuth, OpenID Connect, SAML, JWTs, etc.
(zoom.us)
6 points
by
robotdan
7y ago
|
1 comments
18.
▲
by
robotdan
7y ago
The last time I had to type in my Netflix password into my Roku using a d-pad I nearly chucked the remote at my TV. Not sure why everyone doesn't use this type of device authentication.
19.
▲
by
robotdan
7y ago
This may be of use, this is the Authorization Code Grant, but many others are documented as well. https://fusionauth.io/articles/logins/webapp/oauth-authoriza... https://fusionauth.io/articles
20.
▲
by
robotdan
7y ago
+1 for FusionAuth. FusionAuth has some example k8s and helm configurations available as well. Full disclosure I work for FusionAuth. We support all of these configurations.
21.
▲
Deploy a zip bundle on macOS using Homebrew
(fusionauth.io)
2 points
by
robotdan
7y ago
|
0 comments
22.
▲
by
robotdan
7y ago
Nice writeup. Brew is fantastic on macOS, do you have something similar on Windows?
23.
▲
Hey Twitter, 2007 called. They want their OAuth v1 tokens back
(fusionauth.io)
5 points
by
robotdan
7y ago
|
1 comments
24.
▲
A Practical Example of Reactive Hashing
(fusionauth.io)
3 points
by
robotdan
8y ago
|
0 comments
25.
▲
by
robotdan
8y ago
I'd like to see some of these ideas get off the ground. Ben mentions his email and Twitter handle in the post if anyone is interested in helping or contributing in some fashion to an open source library to implement some form of this s
26.
▲
Reactive Hashing Explained
(blog.benpri.me)
3 points
by
robotdan
8y ago
|
1 comments
27.
▲
by
robotdan
8y ago
Like Got Milk? I see what you did there. :-)
28.
▲
by
robotdan
8y ago
Why? I have yet to find concrete reasons how this makes a hash more vulnerable. Lots of people like to dismiss it, but without any reason. Seems weak.
29.
▲
by
robotdan
8y ago
Do you know of anyone that has used this strategy in production?
30.
▲
by
robotdan
8y ago
How much less suck are we talking about? Kind of sucks in most languages.
More ›