Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dickhardt
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
dickhardt
4y ago
Auth0 can be prohibitively expensive if you have low revenue per user. We are working on providing an OSS docker image that would mock Hellō so that you could get full coverage in automated testing of registration and login. Would you find
32.
▲
by
dickhardt
4y ago
Thanks & I agree!
33.
▲
by
dickhardt
4y ago
> I don't feel like it's worth giving up control over your user's authentication to an intermediary in return for saving a week of work. Maybe the case could be made for day-1 of a startup, but certainly not year-1, it
34.
▲
by
dickhardt
4y ago
Thanks for the comments and describing your interpretation -- which is correct -- clarifications follow: We not only support social login, but also crypto wallets that support browser extensions or Wallet Connect. The user can also just use
35.
▲
by
dickhardt
4y ago
Thanks for the questions! Hellō is not decentralized -- apologies for any confusion -- did I mistakenly write that somewhere? The governance is decentralized. Yes, it is another point of failure, as is any other service you build your app o
36.
▲
by
dickhardt
4y ago
The second point is more concerning. A related point is that it only works if the user already has a wallet installed that is listening on "openid:". "mailto:" and "tel:" work on a phone since there is an email
37.
▲
by
dickhardt
4y ago
My name? It is special. =)
38.
▲
by
dickhardt
4y ago
SIOP has been around for a long time without any adoption. A critical technical challenge is getting the operating systems to support managing the app that responds to the 'openid:' scheme. On iOS, the last app installed gets the
39.
▲
by
dickhardt
4y ago
Hi HN! I’m Dick Hardt[1]. Over the last twenty years, I’ve led the design of identity standards (OAuth 2.0, JWT) and systems that you and billions of others use every day.[2] You know that these systems don’t always work in your favor. Each
40.
▲
Show HN: Hellō, a cooperative approach for online identity
(hello.coop)
97 points
by
dickhardt
4y ago
|
52 comments
41.
▲
by
dickhardt
4y ago
Existing libs for JWTs and PKCE Minimizing a credential stuffing attack requires detecting the attack and then adding captchas or other bot mitigation techniques.
42.
▲
by
dickhardt
4y ago
I did!
43.
▲
by
dickhardt
4y ago
The identity federation protocol flows are pretty straight forward (I may be biased!) ... but you should use existing libraries for all the crypto. Defeating credential stuffing attacks is HARD. That is where services such as Auth0 shine.
44.
▲
by
dickhardt
4y ago
Your question is missing a couple key inputs. Q: Is your SaaS app targeting enterprise use cases, where the customer will want to enable SSO and centralized provisioning? Keybase is a reasonable choice in this case because of the SAML and
45.
▲
by
dickhardt
11y ago
My main gripe with LinkedIn is that the API is not even available for a fee through their partner programs. Yahoo! mail recently launched integration with LinkedIn data, and Salesforce.com and Microsoft Dynamics have integration, but no oth
46.
▲
by
dickhardt
11y ago
My app (Bubbler) used LinkedIn pretty heavily as a data source. There seem to be enough market demand that someone might be able to step in and be the new source of professional profiles. Does the OP have an API for taking data out for Virt
47.
▲
by
dickhardt
11y ago
Facebook cut their API heavy when they phased out v2 last month. No access to friend data and limited access to user profile. LinkedIn is following FB's lead.