Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sophiabannet1
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
Ever had to implement SAML SSO in PHP?
(ssojet.com)
1 points
by
sophiabannet1
1y ago
|
1 comments
2.
▲
by
sophiabannet1
1y ago
Great post! The impersonation vs. delegation framing is spot on. Even in enterprise SSO, proper delegation is clunky. We've toyed with OAuth 2.0 Token Exchange (RFC 8693), but support is patchy and confusing. An actor claim baked into
3.
▲
by
sophiabannet1
1y ago
Nice move by Supabase switching to asymmetric JWTs, eliminating the need to always call getUser() for verification should noticeably reduce latency at the edge; curious if anyone’s benchmarked how much faster auth.getClaims() actually is in
4.
▲
by
sophiabannet1
1y ago
This is a cool idea, so many keyword tools feel unnecessarily gated these days. Love that this removes friction: no signup, instant results, and CSV export without paywalls sounds super useful, especially for quick research sessions or test
5.
▲
OIDC vs. SAML: Which Protocol Should You Use for Single Sign-On?
(ssojet.com)
3 points
by
sophiabannet1
1y ago
|
1 comments
6.
▲
by
sophiabannet1
1y ago
We have reached a point where most B2B SaaS companies support SSO, but there is still a lot of confusion around which protocol to choose: SAML or OIDC. Both serve the same goal and allow users to authenticate using a trusted Identity Provid
7.
▲
OWASP Just Dropped an AI Security Testing Guide
5 points
by
sophiabannet1
1y ago
|
0 comments
8.
▲
by
sophiabannet1
1y ago
A reminder that even MFA isn’t foolproof—app-specific passwords can be a weak link. This attack shows how trust and timing, not tech, were the real weapons. Best to avoid ASPs and use OAuth or passkeys when possible. Big thanks to Google an
9.
▲
by
sophiabannet1
1y ago
because SSO is implemented using various protocols like SAML, OAuth 2.0, and OIDC, each with different use cases, data formats, and security models. Identity providers also have custom implementations, which lead to variations in endpoints,
10.
▲
by
sophiabannet1
1y ago
This is a fantastic breakdown of the real-world benefits of SSO—not just from the end-user perspective, but also from a developer and business standpoint. I especially appreciate the points about centralized user access control and reduced
11.
▲
by
sophiabannet1
1y ago
Excellent breakdown, this clearly illustrates why SSO is only half the story and PAM is essential for securing real privileged access.
12.
▲
by
sophiabannet1
1y ago
A thought-provoking and realistic take on the evolving role of security engineers in the age of AI, versatility and orchestration are clearly the future.
13.
▲
by
sophiabannet1
1y ago
A powerful reminder of why modern authentication must move beyond SMS—critical insights for anyone building secure systems today.
14.
▲
by
sophiabannet1
1y ago
This is the funniest and most painfully accurate take on multi-factor authentication.
15.
▲
by
sophiabannet1
1y ago
Totally agree, SaaS often shifts complexity rather than removing it, integrated platforms feel like coding with training wheels off.
16.
▲
by
sophiabannet1
1y ago
Useful insight