Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rishabhpoddar
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
91.
▲
by
rishabhpoddar
6y ago
Thanks! As of now, there is only one version - the pro version. We may add an open source version soon. If we do, it will be clearly mentioned on our site along with what the feature differences between the non-pro and pro versions are.
92.
▲
by
rishabhpoddar
6y ago
Noted. Thank you for the suggestions. I may reach out to you sometime in the future :)
93.
▲
by
rishabhpoddar
6y ago
I wouldn't consider them as "edge cases" per say. It's an end to end session management solution that aims to be secure and covers all needs for simple and complex apps.
94.
▲
by
rishabhpoddar
6y ago
Awesome!! Your site looks really clean! Will reach out!
95.
▲
by
rishabhpoddar
6y ago
Not all apps will want to have a good level of session security (as of today). But there are enough that do. We have a self hosted version that uses your own db to store tokens. So you don't need to give us any "user data".
96.
▲
by
rishabhpoddar
6y ago
I see. Thanks for the clarification. So when you are verifying an incoming JWT, don't you need to check what the allowed counter is for that session? If yes, then doesn't that require a database / cache lookup for each verifi
97.
▲
by
rishabhpoddar
6y ago
Actually yes! We are already working on providing session management for FaunaDB users. Using us, you can easily get a FaunaDB token for a user on your backend and frontend. We take care of all the heavy lifting of creating those tokens and
98.
▲
by
rishabhpoddar
6y ago
We are in the authentication space. Sessions is a way to get into the space.
99.
▲
by
rishabhpoddar
6y ago
Thanks for your comment. There are a couple of points for this answer: -> Short lived sessions: A lot of the guidelines (OWASP, NIST, industry compliances) recommend having short inactivity timeouts, and "in session", frequent
100.
▲
by
rishabhpoddar
6y ago
Yea! That's why we have a frontend SDK that solves for issues like these. Our SDK uses a library called browser-tabs-lock which provides locking across tabs ( https://www.npmjs.com/package/browser-tabs-lock ). So es
101.
▲
by
rishabhpoddar
6y ago
Thank you :) We can add that to our roadmap. We are also happy to prioritise depending on your use case and commitment! Do reach out to us via email (team@supertokens.io)
102.
▲
by
rishabhpoddar
6y ago
Sounds interesting! I'll have a look at your library. Our solution takes relevant aspects of the OAuth specs. Specifically the idea of using rotating refresh tokens to detect session theft. That being said, we have not had any formal v
103.
▲
by
rishabhpoddar
6y ago
I understand that this is annoying. The reason we have it that way is cause we are experimenting with pricing on a per user basis - it's like the "contact us" pricing plan for other SaaS products. Soon, we plan on standardisi
104.
▲
by
rishabhpoddar
6y ago
Thanks! And more proof for this comment is the sheer number of questions / blog posts written about sessions and JWTs almost weekly on reddit, HN, stackoverflow etc.. If this was very simple to solve, securely, those questions, blog po
105.
▲
by
rishabhpoddar
6y ago
Technically, you do not need to exactly follow OAuth methodology for sessions. You are right. However, there is one common problem with sessions and OAuth, which is token theft. In order to detect token theft, we use the general principle o
106.
▲
by
rishabhpoddar
6y ago
Thanks! The benefits we provide are session security and convenience (not having to know or think about tokens and session management). We don't use normal refresh tokens. We use one time use refresh tokens. This allows to detect token
107.
▲
by
rishabhpoddar
6y ago
Sure! Briefly, we use JWT access tokens which are used for session verification. JWTs can be verified using just a secret key which can be stored in memory. Hence, no network calls = < 1MS latency. However, there are issues with using ju
108.
▲
by
rishabhpoddar
6y ago
Yup. For blitz, there is a default session management solution that's essentially based on a long lived, opaque access token. There is also going to be one which is what SuperTokens is. Either using SuperTokens directly, or an implemen
109.
▲
by
rishabhpoddar
6y ago
Noted. Thank you!
110.
▲
by
rishabhpoddar
6y ago
They do! But most open source solutions to not follow them, which means most apps do not follow them, and for those who care about OWASP session guidelines, need to mostly build their own system.
111.
▲
by
rishabhpoddar
6y ago
Thank you!! We use rotating refresh tokens to detect session theft reliably.
112.
▲
by
rishabhpoddar
6y ago
We believe that session attacks are going to increase in the future given that login is becoming more secure (passwordless, hardware keys etc etc).. As such, for long lived sessions, just having one token makes that the weakest link in that
113.
▲
by
rishabhpoddar
6y ago
Thanks for pointing that out :) But we also are going to release an open source version soon (if not make the whole thing open source). Also, for now, we have removed that claim from our Twitter.
114.
▲
by
rishabhpoddar
6y ago
Thanks! Will investigate & fix.
115.
▲
by
rishabhpoddar
6y ago
Thanks for letting us know! We use Cloudflare and had to purge the cache today cause of some changes.. Is it laggy while scrolling any specific page? Or only when switching pages? About compliance & code audits, those are being planned.
116.
▲
Ask HN: What does the deprecation of 3rd party cookies imply?
2 points
by
rishabhpoddar
6y ago
|
0 comments
117.
▲
by
rishabhpoddar
6y ago
It seems that Twitter has not said anything about this yet. If I had to guess, it could be that because of remote work, the employees had to use Twitter's VPN. Because they were using it, the attackers somehow managed to get access to
118.
▲
by
rishabhpoddar
6y ago
Credentials to VPN can be obtained as well. I assume that's what happened in the twitter hack? Surely they must not have not allowed that tool to be used without being connected to their VPN. Hardware keys probably would work. But can
119.
▲
Twitter hack discussion and a way to secure internal apps
11 points
by
rishabhpoddar
6y ago
|
5 comments