Live data from Hacker News

Viewing profile — krooj

krooj

HN member
Joined
Tue, Jan 12, 2016, 4:56 PM UTC
HN karma
191
Public activity
84 items

About krooj

No profile information was provided.

Recent public activity

  1. comment
  2. comment
    Comment #48594167

    Oh wow - seeing my own work in the wild is ... wild. I implemented the RAS end of this for Atlassian. There will certainly be iterations around this flow - CIMD, better tenancy sup…

  3. comment
    Comment #48058458

    My man, all these fuckers use the same parasitic management consultancies. That's why all this shit looks the same.

  4. comment
    Comment #47852530

    Interesting - I wonder if this isn't a case of theft on a refresh token that was minted by a non-confidential 3LO flow w/PKCE. That would explain how a leaked refresh token could t…

  5. comment
    Comment #46547002

    Question - from the perspective of the actual silicon, are these NPUs just another form of SIMD? If so, that's laughable sleight of hand and the circuits will be relegated to some …

  6. comment
    Comment #44160267

    The comment in lines 163 - 172 make some claims that are outright false and/or highly A/S dependent, to the point where I question the validity of this post entirely. While it's po…

  7. comment
    Comment #44076876

    This is one of those cases where I would hope that extremely strong federalism is exercised from Ottawa: essentially, Alberta could be dissolved, stripped of its provincial status …

  8. comment
    Comment #42249601

    Yep - I remember the CCAT from 4th grade that resulted in my being placed into a different class for 5th. AFAIK, we were given this test "cold" (no prep) and I remember it being ti…

  9. comment
    Comment #42104604

    > In short, Open ID Connect is quite accurately described as an Authentication standard. But OAuth 2.0 has little to do with Authorization. It allows clients to specify the "scope"…

  10. comment
    Comment #41270441

    > The industry predominately rewards writing code, not designing software. The sad part of this is that code is absolutely a side-effect of design and conception: without a reason …

  11. comment
    Comment #41269385

    Linus always has a great way of summarizing what others might be thinking (nebulously). What's being said in the article is really mirrored in the lost art of DDD, and when I say "…

  12. comment
    Comment #40753607

    Weird - this is the first place I saw the "internet" on display as a kid. Shame to see it close in such an unceremonious way.

  13. comment
    Comment #40149460

    [flagged]

  14. comment
    Comment #40107438

    You'd be surprised at how little cloud vendors give a shit about security internally. Story time: I recently went ahead and implemented key rotation for one of our authz services, …

  15. comment
    Comment #40027532

    You really think that's anti-social behaviour? It's a matter of practicality, my delicate flower.

  16. comment
    Comment #40026047

    This is basically how I handle it, and we live in the neighborhood mentioned by this article. The disability claim is largely a straw man argument: I've never seen someone in a whe…

  17. comment
    Comment #39656373

    I also have the same mutation, as does my wife. From what I've been told by various hematologists, vascular surgeons, and interventional radiologists, it's a very weak clotting dis…

  18. comment
    Comment #39654337

    I'll echo this - I have had two left leg DVTs, spaced about 7 years apart, and after the second event, really started diving into medical publications - surgical journals, medical …

  19. comment
    Comment #38870951

    They absolutely do not and also introduce a significant amount of overhead with respect to key/certificate management.

  20. comment
    Comment #38870793

    No, there's no explanation.

  21. comment
    Comment #38731128

    Agree - you only need to look at things like the hybrid flows to see where things fall apart: why would you issue an id_token that contains user information to a client which hasn'…

  22. comment
    Comment #38731070

    Yup - OIDC can be boiled down to: 1. The OG OAuth2 spec never said anything about identifying principals 2. OIDC mandated an id_token to avoid the hit of POSTing the access token t…

  23. comment
    Comment #38731044

    1000x this - each and every CAIM has their own "interpretation" of what the various constructs actually mean in the various RFCs and it leads to a lot of hodge-podge integrations t…

  24. comment
    Comment #38722715

    I feel as though this is a consequence of organizations not really understanding how complex the space truly is. The way I've watched OAuth2 + OIDC get adopted in various companies…

  25. comment
    Comment #38510348

    If you do this and I am the one interviewing you, I will fail you. I will figure out what you actually do/don't know and if you are incapable of performing at the applied level, I …