Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mcstempel
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
How to block AI web crawlers
(stytch.com)
7 points
by
mcstempel
1y ago
|
0 comments
2.
▲
Mcp-scan: NPM-audit-style security scanner for MCPs
(stytch.com)
2 points
by
mcstempel
1y ago
|
0 comments
3.
▲
by
mcstempel
2y ago
There are options beyond auth walls for detecting/enforcing behavior as well since these scrapers have very recognizable device signatures: https://stytch.com/blog/detecting-ai-agent-use-abuse/
4.
▲
by
mcstempel
2y ago
thanks for sharing!
5.
▲
by
mcstempel
2y ago
wow, this is wonderfully made
6.
▲
by
mcstempel
2y ago
Ah, this is great feedback -- I don't think we do enough to articulate how much we're doing beyond that simplified explanation of device fingerprinting on those docs. I'll get that page updated, but 2 main things worth mentio
7.
▲
by
mcstempel
2y ago
CAPTCHAs have been ineffective as a true "bot detection" technique for a while as tools like anti-captcha.com allow for outsourcing it to real humans. BUT they have been successful at the economic side of raising the cost of progr
8.
▲
by
mcstempel
2y ago
You read our mind! https://stytch.com/blog/the-age-of-agent-experience/ Very much agreed that's the long-term goal, but I think we'll live in a world where most apps don't support oauth for a while
9.
▲
by
mcstempel
2y ago
LinkedIn always hits me with those frustrating custom CAPTCHAs where you have to rotate the shape 65 degrees -- they've taken a pretty blunt, high-friction approach to bot detection I think most apps should primarily start with just mo
10.
▲
by
mcstempel
2y ago
Hey there, I'm the author of the post. I'm actually pretty sympathetic to your viewpoint, and I wanted to clarify my stance. I actually spent years working at a "good bot" company (Plaid), which focused on making users&#
11.
▲
by
mcstempel
3y ago
We built Stytch's B2B SaaS solution with this specific shortcoming in mind -- most other solutions aren't actually built with an organization-first data model (they're user-first like Auth0 but support the general concept of
12.
▲
by
mcstempel
3y ago
You can now set up passkeys on your personal gmail, which I've found to be particularly nice for times when I'm trying to log in via webview
13.
▲
by
mcstempel
3y ago
Yeah, +1. Even vanilla puppeteer is pretty successful against Cloudflare
14.
▲
by
mcstempel
3y ago
To your point, the market will decide, but I'm hopeful passkeys will ultimately be one of the key solutions here. Already seeing a lot more app adoption (e.g. Shopify, Google, Docusign) than original webauthn given some of the UX probl
15.
▲
by
mcstempel
3y ago
Co-founder of Stytch ( http://stytch.com/ ) here -- would love to see if you think we're a fit. We have a generous free tier and we're more reasonably priced that tools like Auth0, but not as cheap as tools like Cog
16.
▲
FingerprintJS Transitioning from MIT to Business Source License
(fingerprint.com)
2 points
by
mcstempel
3y ago
|
0 comments
17.
▲
by
mcstempel
3y ago
TL;DR as a dev tools company, we took a lot of inspiration from how Stripe built their product, including their very simple approach to self-serve pricing. However, we found there are some key reasons this approach doesn't translate we
18.
▲
Simplicity can become a false idol in SaaS pricing
(stytch.com)
6 points
by
mcstempel
3y ago
|
1 comments
19.
▲
by
mcstempel
4y ago
> this worked for a little bit longer, but he proceeded to get on a VPN, and then another when i blocked that IP, then another when i blocked that IP, etc, etc. Beyond VPNs, I've even seen attackers leverage residential IP networks
20.
▲
by
mcstempel
4y ago
Also, a tip for anyone that feels like the low hanging fruit prevention methods aren't working (e.g. CAPTCHA, rate limits, etc.) Consider installing a device fingerprinting system -- this has be the single most effective solution we&#x
21.
▲
by
mcstempel
4y ago
I find it particularly frustrating that they force you to upgrade to Verify to solve the problem unless you want to build out a lot of your own internal risk detection (which we ended up doing instead) With the rise of AI APIs, I expect we&
22.
▲
by
mcstempel
4y ago
Ah yes, good call out! Didn't mean to exclude Google's contributions to this step forward in auth. I was super excited to read those additional details in Google announcement earlier this week. For those that haven't seen it:
23.
▲
by
mcstempel
4y ago
As usual - it depends. There have been two main problems with WebAuthn as a primary factor. The first is that the UX experience of WebAuthn as a primary factor - either for "passwordless" or "usernameless" scenarios - ha
24.
▲
by
mcstempel
4y ago
No problem – I’m happy to engage in good-faith discussions like this one when there are valid nuances to explore. One callout I’d like to make is that there are two kinds of SDKs. Client-side ones (like Javascript SDKs) and Server-side ones
25.
▲
by
mcstempel
4y ago
Yes, Firebase also stores refresh tokens client-side [1]. The trade-off that both Firebase and Stytch are managing when we follow this pattern is the following: - You can provide a significantly better developer experience and set-up with t
26.
▲
by
mcstempel
4y ago
Happy to dive into that. For those unfamiliar, XSS attacks are a type of vulnerability where an attacker tricks a website into running the attacker’s code on an end user’s browser. For example, an attacker might set their profile picture UR
27.
▲
by
mcstempel
4y ago
I think your summary of how the post is framed is correct, but as the founder/CEO of Stytch, I wanted to call out that the claims of the author are incorrect. https://news.ycombinator.com/reply?id=33164969&goto=item
28.
▲
by
mcstempel
4y ago
Hey there, I'm the founder/CEO at Stytch. I provided some more responses in this reply on the general post, but I'd also add that login and sign up links are invalidated after their first-time use https://news.ycom
29.
▲
by
mcstempel
4y ago
I’m the founder/CEO at Stytch, and the amount of misinformation and direct falsehoods in this post are pretty jarring. I’m surprised this has gotten any traction on HN, but I’m happy to go point-by-point: - OP claims we do not have a b
30.
▲
by
mcstempel
4y ago
Here's a bit more background on WebAuthn: https://stytch.com/blog/an-introduction-to-webauthn/ What makes it unphishable is that the authentication is not based upon something that a user can be deceived into
More ›