Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
prabaths
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Interested in building a homegrown IAM solution?
(twitter.com)
1 points
by
prabaths
8y ago
|
0 comments
2.
▲
Facebook Security Breach: What Happened?
(medium.facilelogin.com)
3 points
by
prabaths
8y ago
|
0 comments
3.
▲
What Went Wrong? Facebook Is in Crisis Again
(medium.facilelogin.com)
2 points
by
prabaths
8y ago
|
0 comments
4.
▲
Google Home Mini Identity Test
(youtube.com)
1 points
by
prabaths
9y ago
|
0 comments
5.
▲
IDENTITY is the NEW MONEY
(medium.facilelogin.com)
2 points
by
prabaths
9y ago
|
0 comments
6.
▲
Nuts and Bolts of Transport Layer Security (TLS)
(medium.facilelogin.com)
1 points
by
prabaths
9y ago
|
0 comments
7.
▲
Short-Lived Certificates at Netflix
(medium.facilelogin.com)
102 points
by
prabaths
9y ago
|
47 comments
8.
▲
The Starfish and the Spider
(medium.facilelogin.com)
1 points
by
prabaths
9y ago
|
0 comments
9.
▲
Building Microservices – Designing Fine-Grained Systems
(medium.facilelogin.com)
1 points
by
prabaths
9y ago
|
0 comments
10.
▲
by
prabaths
9y ago
I guess the subtitle of the blog says that - How to Create a Private Ethereum Blockchain from Ground-up?'
11.
▲
by
prabaths
9y ago
Well, in this case it is still a permissionless blockchain. But there are many use cases why we need private permissioned blockchains. For example Hyperledger Fabric is mostly used for different purposes. You can find some use cases here:
12.
▲
How to Create a Private Ethereum Blockchain
(medium.facilelogin.com)
151 points
by
prabaths
9y ago
|
45 comments
13.
▲
The Mystery Behind Block Time (Bitcoin and Ethereum)
(medium.facilelogin.com)
1 points
by
prabaths
9y ago
|
0 comments
14.
▲
by
prabaths
9y ago
The EU General Data Protection Regulation (GDPR) is the regulation 2016/679 of the European parliament and of the council, which replaces the Data Protection Directive 95/46/EC and was designed to harmonize data privacy laws
15.
▲
GDPR for Everyone Who Hates Reading Law
(medium.facilelogin.com)
3 points
by
prabaths
9y ago
|
1 comments
16.
▲
by
prabaths
9y ago
I assume SPIFFE is more useful to system to system authentication without the end user context - like how Netflix uses short-lived certificates to secure interactions between microservices ( https://medium.facilelogin.com/sho
17.
▲
JWT, JWS and JWE Internals
(medium.facilelogin.com)
2 points
by
prabaths
9y ago
|
0 comments
18.
▲
by
prabaths
9y ago
This was discussed at a Netflix meetup. The official site is www.padme.io. Also you can find the video recording of that meetup from https://www.youtube.com/watch?v=dim85J5cLq4 - OPA and PADME are discussed from 33:49. Also
19.
▲
by
prabaths
9y ago
Okay - rereading your comments - looks like you have misinterpreted this one. "A signed JWT is known as a JWS (JSON Web Signature) and an encrypted JWT is known as a JWE (JSON Web Encryption)" This is a correct statement. This doe
20.
▲
by
prabaths
9y ago
Well I am not quite clear from your comment how you interpret. This is my point - as also rightly in the JWT RFC. "JSON Web Token (JWT) is a compact, URL-safe means of representing claims to be transferred between two parties. The cla
21.
▲
by
prabaths
9y ago
I agree XACML has lot of complexities. But if you look at the recent developments, you can now have both XACML request and response JSON based - and the communication between the PEP and PDP in a RESTful manner. Also - there is a standard c
22.
▲
by
prabaths
9y ago
In fact JWT is an abstract concept - I have written a blog about that in detail. Please find it here - https://medium.facilelogin.com/jwt-jws-and-jwe-for-not-so-du... HMAC is not recommended - as it will be symmetric key. I
23.
▲
by
prabaths
9y ago
Yes - revocation is always tricky - that's why Netflix moved to short-lived certs - and forgot about cert revocation. Here is a blog I wrote on Netflix model: https://medium.facilelogin.com/short-lived-certificates-netf
24.
▲
by
prabaths
9y ago
It should be signed by the STS - which is trusted by all the downstream microservices. The STS, who validates the access_token, in the response can send back this signed JWT to the gateway. The STS of the access_token and this JWT can be th
25.
▲
by
prabaths
9y ago
Well... yes - one way to do that is to have a way to propagate revocation events from the issuer to the up stream applications - and each upstream application, possibly at the gateway level or at an inceptor will check the incoming tokens a
26.
▲
GSMA Mobile Connect vs. OpenID Connect
(medium.facilelogin.com)
1 points
by
prabaths
9y ago
|
0 comments
27.
▲
Securing Microservices
(medium.facilelogin.com)
162 points
by
prabaths
9y ago
|
56 comments
28.
▲
General Data Protection Regulation (GDPR) for Identity Architects
(medium.facilelogin.com)
2 points
by
prabaths
9y ago
|
0 comments
29.
▲
Identity and Access Management Design Principles
(medium.facilelogin.com)
2 points
by
prabaths
9y ago
|
0 comments
30.
▲
by
prabaths
9y ago
Yes... its Identity and Access Management
More ›