Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
spiffe
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
spiffe
7mo ago
Thanks, but I'm likely going to tune out. None of the 3 points address the fundamental issue. IMO, it appears you are trying to reinvent a tiny part of OAuth2 w/ DCR, but without any of the security or trust underpinnings. I'
2.
▲
by
spiffe
7mo ago
One does not need to break any endpoint or look for things in transit. Any app that calls an agent within your design receives the jwt, and can turn around and masquerade as the agent.
3.
▲
by
spiffe
7mo ago
Sorry, but to call a spade a spade, but this is a convoluted mess of faux-security without actually solving your problem statement. Faux-security because there is no security - anyone that steals the jwt can impersonate the agent for the li