Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
anderslemke
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
anderslemke
6y ago
I get where you're coming from, and this is something I've been thinking a lot about. It would be possible to not save the map, and then use some kind of hashing to infer user ids for each site. I chose not to do this, to be a
2.
▲
by
anderslemke
6y ago
Yes. Promise keeps a map of your sites and IDs.
3.
▲
by
anderslemke
6y ago
Promise is basically challenging the assumption that authentication has anything to do with both personal identity and being able to contact a user. If a site needs to contact the user, it's reasonable to ask for eg. an email. But now
4.
▲
by
anderslemke
6y ago
I'm really happy that you're willing to take this discussion with me. I totally understand what makes IndieAuth is a good solution. And it seems really easy. For me. But I have no idea how I would go about explaining it to, let&#x
5.
▲
by
anderslemke
6y ago
Being a non-profit, collectively owned service, which Promise is, will make it difficult to ban users and relying parties. Just like the DNS can block users, Promise can ban users and relying parties. This is not something Promise should ta
6.
▲
by
anderslemke
6y ago
That is an interesting point. Internet identity could maybe be a layered thing where one layer takes care of authentication, which is where Promise lives. The next layer could handle information like name and email. And finally a layer that
7.
▲
by
anderslemke
6y ago
That sounds painful in so many ways...
8.
▲
by
anderslemke
6y ago
Yes. The fragmentation is part of what makes authentication a horrible experience. But most of all, what I'm missing is at least one good option on the sign-in screen. And using a password manager is not it.
9.
▲
by
anderslemke
6y ago
I didn't know SimpleLogin. It seems really nice. Kind of what Apple does with their "Sign In with Apple". It's not exactly a SSO, though.
10.
▲
by
anderslemke
6y ago
Being pseudonymous is one of the main selling points of Promise. Only by being pseudonymous can it provide the level of privacy that should be expected from the global authentication infrastructure that Promise wants to be.
11.
▲
by
anderslemke
6y ago
I would love to understand the reasoning here. Sincerely. What makes OIDC a "non starter"? I see OIDC as an implementation detail, and have no strong opinions about it.
12.
▲
by
anderslemke
6y ago
Ok, you're not the first to say that... I hate it, when I type my email and password (correct, that is), and get an error saying "You already have an account. You need to sign in". OK. But would you please just sign me in the
13.
▲
by
anderslemke
6y ago
WebAuthn is great! I don't see any reason why Promise shouldn't implement it. I see it this way, that Promise makes it possible for all its relying parties leverage WebAuthn by implementing it once, so they don't have to.
14.
▲
by
anderslemke
6y ago
I'm a bit divided on whether or not the "centralized" thing is actually a problem Promise should tackle. On one hand, I want to tell you that Promise is only centralized by default. Which is good for people that doesn't
15.
▲
by
anderslemke
6y ago
I've built Promise, to prove (to myself at least), that it would be technically possible to build authentication infrastructure, that can be used across sites, without having to store any data unencrypted, and furthermore, not storing
16.
▲
by
anderslemke
6y ago
The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as t
17.
▲
by
anderslemke
6y ago
Hi benzgou. It seems login.land is down. What happened?
18.
▲
by
anderslemke
6y ago
login.land seems to be down. What happened?