Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
121.
▲
by
jf
4y ago
Good question! If I remember correctly, the downstream system has only one chance to handle the HTTP request from Okta.
122.
▲
by
jf
4y ago
(Disclaimer: I’m an Okta employee) Okta works really well in your use case. I recommend trying it out yourself. Since you mention YubiKeys, I’d also suggest that you try removing passwords from your setup entirely by using YubiKeys and one
123.
▲
by
jf
4y ago
The short version of why SAML is bad is because it’s based on XML. This means that SAML is not only subject to the usual vulnerabilities that you’d expect, but also XML vulnerabilities! A slightly longer explanation is that SAML is based on
124.
▲
by
jf
4y ago
As someone who has implemented SAML and SCIM, I agree with you about SAML. However, I’m curious to learn why you think SCIM is a “bad” protocol, can you explain why you don’t like it?
125.
▲
by
jf
4y ago
It presumes that the legacy app supports an SSO protocol like OIDC, SAML, or WS-Fed. Ideally the app will support one of those protocols directly, otherwise it’s possible to bolt on support for one of those protocols via a proxy.
126.
▲
by
jf
4y ago
Can someone fill me in as to why they can’t just store the password using something like bcrypt? Okta uses bcrypt to store passwords. Are there any techniques for identity providers to authenticate people without storing or transmitting
127.
▲
by
jf
4y ago
Typically, when you build an authentication system, you design your code to not store the password in plaintext so that there is no possibility of the password being read back out of the system, but Okta isn't doing this because they
128.
▲
by
jf
4y ago
There seems to be a lot of confusion here. First of all, for the users that have passwords, Okta stores those passwords as hashes. The claim that Okta exposes plain text passwords is only true in an edge case: When an Okta administrator has
129.
▲
by
jf
4y ago
As someone who has organized many dozens of events, and attended hundreds, my core thesis for running a good event is: "Make events attendees want" The only good events are those made specifically to benefit the attendees of the e
130.
▲
by
jf
4y ago
I also want to add my enthusiastic recommendation for the Garmin InReach mini. I purchased one to keep as an emergency communications device. It’s small, lightweight, keeps a charge for months when powered off, and (in a pinch) can be used
131.
▲
by
jf
4y ago
Is there a newsletter I can subscribe to so that I get get notified of new posts to your blog?
132.
▲
by
jf
4y ago
I’ve looked into getting Genera open sourced. Long story short, it’s very unlikely to happen anytime soon.
133.
▲
by
jf
4y ago
Thanks for this comment. I didn't realize that cooking green chiles was different! My grandfather was a farm worker. He would bring home red chiles from the fields and roast them in the sun on his roof. So my first reaction to this sto
134.
▲
by
jf
4y ago
Take a look at Apptron: https://progrium.com/blog/apptron-announcement/
135.
▲
Shell Scriptable Native APIs
(youtube.com)
2 points
by
jf
4y ago
|
0 comments
136.
▲
by
jf
4y ago
You're welcome! I hope that you spent many happy hours reading Krazy Kat
137.
▲
by
jf
4y ago
If you're new to Krazy Kat, I highly recommend reading it! I put a bunch of Krazy Kat comics that are in the public domain online here: https://joel.franusic.com/krazy_kat/
138.
▲
Apptron
(progrium.com)
3 points
by
jf
4y ago
|
0 comments
139.
▲
by
jf
4y ago
If you want to your site to be online when your DNS provider isn’t, then having a secondary DNS provider is an absolute must.
140.
▲
by
jf
4y ago
Previous discussion (with comments from a ThorCon employee): https://news.ycombinator.com/item?id=8863535
141.
▲
by
jf
5y ago
I'm the Joël Franusic mentioned in this article. Ask me anything! If you want more technical details about how I do literate programming, you can see this article I posted on dev.to about four years ago: https://dev.to/
142.
▲
Infinite Mac: An Instant-Booting Quadra in the Browser
(blog.persistent.info)
281 points
by
jf
5y ago
|
103 comments
143.
▲
Sculptures
(bhoite.com)
2 points
by
jf
5y ago
|
0 comments
144.
▲
by
jf
5y ago
Learning that this website exists, and then finding detailed and accurate information in my record is what convinced me to start sharing my salary data with my peers. As I see it, this database is a breach of an implicit social contract bet
145.
▲
by
jf
5y ago
My understanding is that employers provide this data in exchange for getting access to the database
146.
▲
by
jf
5y ago
I was ready to dislike this on principle, but was surprised to find myself slightly interested in the product. What’s a good way to get started with CPU mining Etherium?
147.
▲
Anne Eunson’s Artistry
(kddandco.com)
1 points
by
jf
5y ago
|
0 comments
148.
▲
by
jf
5y ago
I also recommend buying a paper copy of the Family Medical Guide by the American Medical Association
149.
▲
by
jf
5y ago
I’ve spent a lot of time thinking about this because of the Playable Quotes [0] project that I worked on with @rndmcnlly. First off, I love embedding data into images. It’s surprising how useful it is to do this! The main reason that I like
150.
▲
by
jf
5y ago
Could you dig a hole for your batteries and store them below the frost line?
More ›