Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
lhazlewood
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
JSON Web Token (JWT) Library for the JVM
(github.com)
1 points
by
lhazlewood
12y ago
|
0 comments
2.
▲
by
lhazlewood
13y ago
HMAC authentication requires both the client and the server to have a shared secret (or more likely a derived key based on a shared secret). The secret cannot be saved as a one-way hash (as might be common for a password). So you couldn't u
3.
▲
by
lhazlewood
13y ago
I gathered as much. But in practice, how often do you see RFC 2617 Digest authc used in non-browser scenarios? (I'm genuinely curious. I haven't seen it used much at all outside of web browsers, so I'm curious what others may have come ac
4.
▲
by
lhazlewood
13y ago
Totally agree. The key here is that you're doing the work to implement the algorithms, not your customers. If they had to do it, they probably just wouldn't use it.
5.
▲
by
lhazlewood
13y ago
You shouldn't ever use username/password pairs for API authentication. If the user ever changed their password, then their API calls would immediately fail! This is one of many benefits of using multiple (revokable) API Keys.
6.
▲
by
lhazlewood
13y ago
Stormpath's custom scheme is very similar to Amazon's. But per the blog article, you'd only want to do this if you are willing to support client libraries/sdks that implement it as well. No one wants to spend the time to implement non-stan
7.
▲
by
lhazlewood
13y ago
Depends on the UA (curl?)
8.
▲
by
lhazlewood
13y ago
There are many types of digest authentication - OAuth1.0a and Amazon's and Stormpath's custom schemes are examples. Browser-specific digest authentication wasn't covered however since the article was about REST APIs and most REST clients a
9.
▲
by
lhazlewood
13y ago
A UUID is first and foremost a 128 bit number, irrespective of its text encoding. Its 'canonical' form uses HEX-only encoding. A 'Url62' can be another encoding. 'Url62' wouldn't be a canonical encoding, but it's still a 128 bit UUID numb
10.
▲
by
lhazlewood
14y ago
Depends on the customer - if it is a government agency and SHA2 is mandated for their own passwords (per NIST standards), we comply (with a huge number of iterations based on CPU/GPU target specs). Additionally, we automatically increase i
11.
▲
by
lhazlewood
14y ago
Great questions. With regard to CSPNG, this SO post answer is good: http://stackoverflow.com/questions/536584/non-random-salt-fo... As for bcrypt/scrypt vs iterations, there is a difference, but it's minor. Bcrypt is not demonstrably an
12.
▲
by
lhazlewood
14y ago
BCrypt (level 3) is getting the basics right. Levels 4 and 5 are techniques beyond the basics used to minimize potential brute force attacks, which _are_ an issue, depending on the attack target (read the Verizon report referenced by anoth