Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
woloski
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
woloski
7y ago
things should be back to normal. Are you still seeing an issue?
2.
▲
by
woloski
9y ago
It is great to see that the industry is moving from webhooks to Functions. We've seen this model succeed at Auth0 with our Rules feature [1] implemented 3 years ago. Recently productized this experience with Auth0 Extend [2]. It suppor
3.
▲
Parallelizing and auto-scaling bcrypt
(auth0.engineering)
1 points
by
woloski
10y ago
|
0 comments
4.
▲
by
woloski
11y ago
The article is talking about webtask.io, the underlying engine for sandboxed code execution used by Auth0 for allowing customers to extend the platform with arbitrary nodejs code. In such system there is a need to acccess real time logs (th
5.
▲
by
woloski
11y ago
Also looking for Technical Product Marketing Manager
6.
▲
by
woloski
11y ago
hi sean, it's a hidden program :). We started this year with the first two interns and there is not much there on the site yet. If you are interested, jobs+interns@auth0.com Type of things you do as an intern (apart from eating Asado a
7.
▲
by
woloski
11y ago
Auth0 https://auth0.com - Remote | Seattle, USA | Buenos Aires, AR Auth0 makes identity simple for developers. Our subscriber base consists of more than 24,000 developers at over 20,000 enterprises across more than 150 countries
8.
▲
Blacklisting JSON Web Tokens
(auth0.com)
9 points
by
woloski
12y ago
|
0 comments
9.
▲
by
woloski
12y ago
Yep, you got it right. Re: holding the keys, response below. The encryption keys are on the server. We encourage you to deploy your own sharelock instance. We made that super easy with Herok. There is no storage, just a node app. And then y
10.
▲
by
woloski
12y ago
Read my response above.
11.
▲
by
woloski
12y ago
The encryption keys are on the server. We encourage you to deploy your own sharelock instance. We made that super easy with Heroku for instance ( https://dashboard.heroku.com/new?template=https%3A%2F%2Fgith... ). There is no
12.
▲
Sharelock – Securely share data
(sharelock.io)
87 points
by
woloski
12y ago
|
34 comments
13.
▲
Slackin
(rauchg.com)
15 points
by
woloski
12y ago
|
0 comments
14.
▲
4 things we want from products
(sendgrid.com)
4 points
by
woloski
12y ago
|
0 comments
15.
▲
by
woloski
12y ago
To start with, OAuth is an authoriation protocol and JWT is a token format (a signed and/or encrypted piece of data). So they are orthogonal. The OAuth protocol doesn't specify which token format to use. Normally people have been
16.
▲
by
woloski
12y ago
Thanks for spreading the word Adam! We (Auth0) are heavy promoters of the usage of JWT. Here are some articles about using JWT instead of cookies on single page apps with APIs, and its pros/cons. https://auth0.com/blog&
17.
▲
Homakov on Covert Redirect OAuth exploit
(homakov.blogspot.com.ar)
3 points
by
woloski
12y ago
|
1 comments
18.
▲
by
woloski
12y ago
We wrote a blog post that shows how you can authenticate your users and get temporary security credentials from AWS based on the user tokens to avoid putting your keys on the client (both JavaScript apps in the browser or native apps). This
19.
▲
REPL to any browser in the cloud
(github.com)
82 points
by
woloski
13y ago
|
11 comments
20.
▲
by
woloski
13y ago
Yes, I don't think there is a one-size-fits-all answer. It will depend on your use cases. You can always start small using JWT and move to database backed tokens when you get a better idea of your architecture, use cases and authorizat
21.
▲
by
woloski
13y ago
For images that are protected you can use this approach http://blog.auth0.com/2014/01/27/ten-things-you-should-know-...
22.
▲
by
woloski
13y ago
Yes, that's correct.
23.
▲
by
woloski
13y ago
Hey, Matias founder of Auth0 ( https://www.auth0.com ) here (we wrote the original article). re: cookies vs xss. Expanding on sil3ntmac comment, based on my experience, it's easier to protect against XSS than protecting again
24.
▲
by
woloski
14y ago
I am curious, what were the drivers for this pricing instead of plain fixed price?
25.
▲
by
woloski
15y ago
Yes, the link is there, maybe buried in all the text. Did you find the homepage too bloated? I added the open source bit in the initial statement "MarkdownR is an open source project that provides collaborative realtime markdown editor buil
26.
▲
by
woloski
15y ago
Glad you like it. Thanks for the bug, it's still work in progress. https://github.com/southworksinc/markdownR/issues/13
27.
▲
Google Docs for Markdown: MarkdownR (node.js on Windows Azure)
(markdownr.cloudapp.net)
1 points
by
woloski
15y ago
|
4 comments