Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nick-garfield
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
Openhouse – An Open-Source Clubhouse
(openhouse.substack.com)
1 points
by
nick-garfield
6y ago
|
0 comments
2.
▲
by
nick-garfield
6y ago
Nick here, one of the developers behind Feather. When we set out to build an auth API, one of the first big challenges was just wrapping our heads around all the various acronyms and protocols. Despite the existence of standards like OAuth,
3.
▲
Show HN: Feather – A Lightweight Auth API
(feather.id)
4 points
by
nick-garfield
6y ago
|
2 comments
4.
▲
Anyone want to build an open-source Clubhouse?
(openhouse.substack.com)
3 points
by
nick-garfield
6y ago
|
0 comments
5.
▲
by
nick-garfield
6y ago
wow, just reading that term "line of business" makes me anxious. I used to work on a global payments platform that supported "multiple LOBs", and it was a nightmare of ifs and switch statements all the way down. The situ
6.
▲
by
nick-garfield
6y ago
If you're in the "talking with customers" phase, you should also check out "The Mom Test" by Rob Fitzpatrick. http :// momtestbook .com (EDIT: I just noticed this is an http site... breaking up the link in
7.
▲
by
nick-garfield
6y ago
My friend and I got really frustrated with existing authentication providers like Auth0, so we decided to create API called Feather to make it easier to add authentication to our web/mobile apps. https://feather.id Still qu
8.
▲
by
nick-garfield
6y ago
Hmm that's a bit disappointing.. I feel like Ive and Cook could be wrong on this one. If desktop/mobile is an appropriate parallel, then it seems like they've decided to undercut their desktop machine to have the "ergono
9.
▲
by
nick-garfield
6y ago
This was an amazing post! 100% spot on that the external distractors are easier to manage than the internal ones. A buzzing phone, tempting social media websites, and loud rooms all tend to be relatively easy problems to fix. As for interna
10.
▲
by
nick-garfield
6y ago
This is interesting.. I've never heard of the term "tacit knowledge" before, but it makes a lot of sense to me. It particularly reminds me of my experience being on-call at my last company. Our systems were pretty unstable, a
11.
▲
by
nick-garfield
6y ago
What do you mean by DNS-based PKI? That sounds interesting, but I can't quite visualize what that is.
12.
▲
by
nick-garfield
6y ago
Yeah this is really interesting. The "velocity" of upvotes/comments seems to be more important than the actual raw count.
13.
▲
by
nick-garfield
6y ago
I'm sure you're right that people occasionally leverage a friend network to upvote content to the front-page. I get the sense this happens a lot on Product Hunt. But I know for a fact this isn't the _only_ way to reach the fr
14.
▲
by
nick-garfield
6y ago
woah, this is crazy! The flamewar detector (# comments > upvotes) is pretty funny
15.
▲
by
nick-garfield
6y ago
Haha good point
16.
▲
Ask HN: Do posts by authors with more karma rank higher?
52 points
by
nick-garfield
6y ago
|
53 comments
17.
▲
by
nick-garfield
6y ago
I've got to recommend refactoringui.com. They sell a (rather expensive) book on web/mobile app design that explains how to build your design system and use it to create great looking apps. They cover all the bases you would expect
18.
▲
by
nick-garfield
6y ago
Definitely! And it depends on what key you're storing, but if you use AWS Secrets Manager, you can setup automatic key rotation to run periodically.
19.
▲
by
nick-garfield
6y ago
Am I understanding the article right: the endpoint would accept any email address and generate a valid JWT without verifying the caller owned the email address? If so, what extra validation did Apple add to patch the bug?
20.
▲
by
nick-garfield
6y ago
> No one should be using JWT What??
21.
▲
by
nick-garfield
6y ago
AFAIK Firebase doesn't actually offer any real authorization do they? It was some time ago I last built a project with them, but I remember having to create a custom "roles" attribute in the Realtime DB for users.
22.
▲
by
nick-garfield
6y ago
I agree with this. I think Auth0 at one point was building tools for indie devs, but are now focused mostly on enterprises. What have you used instead of Auth0?
23.
▲
by
nick-garfield
6y ago
Hi psankar, we ran across Ory when we were doing our initial "does this exist?" Google search, but haven't actually looked into that project too deeply. And we'd never heard of Keycloak before, so thanks for pointing the
24.
▲
by
nick-garfield
6y ago
Thanks for the feedback! We should hopefully find time to optimize the site for mobile in the coming weeks
25.
▲
by
nick-garfield
6y ago
Thanks for this comment! We had the same exact experience. Couldn't have explained the state of the docs any better!
26.
▲
by
nick-garfield
6y ago
I really thought the same when we first integrated with Auth0 for one of our projects! Most of our frustration with them boiled down into 2 points: 1. The Auth0 universal login solution is not "white-label". It requires pushing us
27.
▲
by
nick-garfield
6y ago
Apologies in advance if you try to sign in and cannot! We're running with extremely light infra on AWS and just hit our max-db-connections to MySQL. Good lesson for the future, because it looks like we're not cleaning up the conne
28.
▲
by
nick-garfield
6y ago
My friend and I got really frustrated by the available third-party authentication platforms like Auth0, so we began building our own instead. https://feather.id It's a RESTful server-side API for adding user authentication
29.
▲
by
nick-garfield
7y ago
The "complex" math in this poster disguises the simplicity of these chords and transitions.. If you're really interested in music theory (and why those transitions sound the way they do), "The Songwriting Secrets of The