Hacker News .hnnew | past | comments | ask | show | jobs | submit | k8_maze's commentslogin

It is a "sandbox" project, a description of what that means you can find at: https://www.getory.io/docs/ecosystem/versioning/

Hope this helps!


It does, a lot! Although I wasn’t able to find an exact answer, this seems to suggest that it’s too early to use in production. Thanks!


If this is not a spin on the linked article, that would definitely be terrifying. A bit as if stack overflow and reddit had a baby.

If it is a spin, the identity system used is a popular open source system which you can find at https://github.com/ory/kratos. The react code is a reference implementation of the same people who wrote that thing, and the article is intended to help people get started with the open source stack. So if you were indeed applying for a job interview, and the task would be to write such an app - you would know where to look. Plus, this would probably reduce the amount of terrible login solutions we have today in the WWW ;)


Sorry to be that guy - the title tag has a typo: Mistaeks instead of Mistakes.

I promise that I will contribute more substantial feedback once I've read the piece :D


I believe that's the intentional name of his blog.


Whoops, now I feel dumb.


You just made a mistaek. :)


And bad mistaeks, I've made a fwe...


No, they laid out several issues with Apple's OpenID Connect implementation with one of them being an actual security-related issue (missing nonce which can enhable replay and csrf attacks). You only have to pay if you certify and even then, 15k is not that much.


$15k is an inconsequential amount for the OpenID Foundation, either. Just based on members listed on their site, they're making around $966 thousand.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: