Live data from Hacker News

Viewing profile — brokenwren

brokenwren

HN member
Joined
Wed, Mar 25, 2015, 3:45 PM UTC
HN karma
324
Public activity
120 items

About brokenwren

This is my jam: https://fusionauth.io

Recent public activity

  1. comment
    Comment #37649225

    An overview of how FusionAuth selected our SOC 2 software vendor for 2023.

  2. story
  3. story
  4. comment
    Comment #34686789

    I missed that you left Okta back in 2022, so pardon asking for a disclosure. In any case, I think your last sentence was the part that seemed a bit defensive. Dan was pretty clear …

  5. comment
    Comment #34666802

    Generally, the HN community prefers if you announce the company you are with. It helps ensure transparency in the communications. I’m the founder of FusionAuth and have deep knowle…

  6. comment
    Comment #33332008

    I think that's actually what most people are waiting for with Loom. They want it to be fully baked into the JDK and ready for production first. Then they will start using it. For j…

  7. comment
    Comment #33331804

    I'm not clear why there is a distinction here. Any HTTP server can easily use a non-blocking Selector to handle the I/O operations and then perform the application logic on Threads…

  8. comment
    Comment #33324715

    I don't think this is accurate. The Loom documentation says specifically that it is a concurrency model to replace native threads with fibers. It says very little about non-blockin…

  9. comment
    Comment #33324603

    Sounds good. Once I get the project published, it will include all of the load tests for each server as well as the setup and code for it all. Might be a couple of weeks or so, but…

  10. comment
    Comment #33324536

    Actually, Loom is about threading and helps support NIO. You'll still need Selectors, Channels, and ByteBuffers with Loom, you'll just be able to pass off the parsing and handling …

  11. comment
    Comment #33324504

    Thanks! Feel free to log any issues you encounter. TLS is complex, but I think I have it working properly now.

  12. comment
    Comment #33324500

    I thought so as well. See my comment on the other thread about Netty. I'm sure someone that is a Netty expert or committer could figure it out, but it's so complex that it makes it…

  13. comment
    Comment #33324478

    I ran the load tests and couldn't explain it either. I adjusted the thread pools, buffer sizes and a bunch of other parameters and couldn't get Netty to scale. I think Netty tries …

  14. comment
    Comment #33324453

    I wrote most of the server code for the project and I actually looked extensively at Loom. We decided to anchor the project to LTS Java versions only. The issue with Loom is that a…

  15. comment
    Comment #33020635

    As this applies to access tokens, if your application doesn't need a JWT, it shouldn't care whether the authorization server returns a JWT or an opaque token. On the flip side, if …

  16. comment
    Comment #29101818

    I agree with you, but it should be WAY faster than every 90 days. I'm trying to find articles that address the fact that NIST and others are worthless since they recommend every 1-…

  17. comment
    Comment #29101555

    So, do you know of anyone that has written this type of thing up? I'd love to have some fodder when having these types of discussions. :)

  18. comment
    Comment #29101456

    I completely agree. But even at 15 or 30 days, it's too long. The only way to protect a key would be to rotate it every day or every hour.

  19. story
    Ask HN: Articles about key rotation being worthless

    I need some articles with respect to why the current key rotation recommendations do very little to improve security overall. Given that NIST recommends 1-2 years and others recomm…

  20. comment
    Comment #28788080

    We tried to convince Twitch for years that their filters were garbage and they should use CleanSpeak. They kept insisting their engineering team had written the best filter in the …

  21. comment
    Comment #26368336

    FusionAuth also has advanced registration forms and we are working on a lot of really awesome improvements around sign-in and sign-up workflows. Stay tuned for some major updates i…

  22. comment
    Comment #26336209

    We are working on that. Our new website will include a ton of information about the company, our executive team, and our culture. Stay tuned! You can check out my LI profile for no…

  23. comment
    Comment #26336181

    You can export everything via a support ticket. We have migration scripts you can use if you come over to FusionAuth or tweak them for any other platforms as well: https://github.c…

  24. comment
    Comment #26336140

    Except for all the basics like RBAC with multiple roles, JWT modification, simple MFA, etc.

  25. comment
    Comment #26336128

    Come on over to the FusionAuth! The water is great! - https://fusionauth.io