Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
machete143
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
machete143
9y ago
That is a really bad specification with no examples, no formalization, and zero references. However, all server-side attack scenarios listed there are not possible with Hydra. Some of them also boil down to misusing OAuth2 for authenticatio
2.
▲
by
machete143
9y ago
Thank you for the valuable feedback! The dev mode is indeed a very good idea - I'll probably spin up another docker-compose example with all the default things set up. Would that make it easier?
3.
▲
by
machete143
9y ago
So how do people grant tokens then? They do need to log in somewhere?
4.
▲
by
machete143
9y ago
What I meant to ask is if this has things like user registration, password reset flow, two-factor authentication, account takeover prevention, etc. I think removing 3rd party dependencies is always a good idea - it keeps things lean and rem
5.
▲
by
machete143
9y ago
Looks interesting, does this solve authentication as well? It looks like it but from quickly scanning through the readme I didn't find anything. Also what's your reasoning for relying on 4 (etcd, consul, postgres, nats) external d
6.
▲
by
machete143
9y ago
Good idea! How could that look like on windows (the guide should work on all OS and I'm no windows pro)?
7.
▲
by
machete143
9y ago
I'm not sure if I understood you correctly. Delegation of authentication usually implies trust between the two parties. GitLab (the hosted version) does probably not trust stravros.io enough to allow people to log in through there. Por
8.
▲
by
machete143
9y ago
Good point, Hydra does this to for things like missing TLS encryption but not yet for secrets (it only rejects secrets that are too short). I've tracked this here: https://github.com/ory/hydra/issues/573
9.
▲
by
machete143
9y ago
Then I hope that this makes your life easier :)
10.
▲
by
machete143
9y ago
That is a valid concern. However, once a password is published (especially in docs or tutorials) it is insecure whether they are random values or not - simply because they are public and clearly linked to the product you're running. Th
11.
▲
by
machete143
9y ago
Yes indeed, running OAuth2 without https is madness!
12.
▲
by
machete143
9y ago
If you're not into reading the article itself and want to check out the technology first, here's the link to github: https://github.com/ory/hydra If you have any questions, feel free to ask ahead.
13.
▲
Run your own OAuth2 server
(ory.am)
235 points
by
machete143
9y ago
|
80 comments