3 ms·
The article provides a very light history and technically shallow description of OAuth and OIDC so it can advertise Okta. Essentially, "these two protocols are
by aclimatt 8y ago
The article provides a very light history and technically shallow description of OAuth and OIDC so it can advertise Okta. Essentially, "these two protocols are complicated, and you probably don't care, so you should buy Okta."
Except this is Hacker News, where caring is fundamental. I'll pass on the Okta advertisement.
- rdegges 8y agoI'm legitimately not trying to advertise for Okta here at all. This topic is near and dear to my heart because I've been working in this industry for many years now, and it is frustrating that there is a huge focus on building more OAuth/OIDC tools and encouraging developers to get directly involved in working with things like JWTs directly. There are so many ways to mess things up at foundational levels today, I just really want to see better tooling created in the open source communities (and in paid products) to abstract things like OAuth/OIDC so that developers don't need to constantly be fiddling around with these lower level protocols where the risk for messing up is extremely high.
- jessaustin 8y agoAdvertisements with their hearts in the right place are still advertisements. If your tool were open source (it may be? not clear from TFA...) no one would complain. Since it's commercial and TFA takes such an anti-hacker stance, the complaint above is not surprising. It's not difficult to imagine that TFA might be very effective in speaking to some of your customers. With the customers who hang out here, a different essay with a different emphasis (e.g. "this is how everyone gets OAuth wrong and here's how we do it right") might be more effective.
- Dowwie 8y agoI appreciate your blog posts. They're consistently interesting and useful. If you can do what you love and align that with your work, more power to you.
- paxys 8y agoOkta is not a replacement for either of those things, and I didn't see the plug in the article for their services that you mention.
- combatentropy 8y agoIt's at the end: "This is one of the reasons why [...] we spend tons of time and effort trying to build [...] client libraries [...] to hide those complexities and make securing your web applications simpler." It may be the lightest of plugs, but it means that the writer is biased. Being biased doesn't mean you're wrong, but it throws the entire argument into doubt. I feel like I wasted my time. Also, any security professional who just mentions in passing that OAuth was for authorization loses a little of my trust. It's true that Auth is short for Authorization. But an important nuance is that it isn't authorization for the user but for the application, authorization by the user for this new app to get some information from one of the user's old apps (like Google). For a programmer like me, this clears up why OAuth stands for authorization but always seemed more like authentication. From my understanding, OAuth doesn't handle any authorization of the user within your app. You have to handle that some other way.
- asdf333 8y agoWhose bread I eat his song I sing. I have a ton of respect for Todd but yes, this writer is just doing their job which is to promote okta
- james_s_tayler 8y agoI agree the article title comes off as a bit tone deaf to the developmer community. Maybe it's aimed at management?