Viewing profile — positiveblue
positiveblue
HN member- Joined
- Mon, Jun 17, 2019, 9:46 AM UTC
- HN karma
- 198
- Public activity
- 28 items
- HN profile
- View on Hacker News ↗
About positiveblue
No profile information was provided.
Recent public activity
-
comment
Comment #45129309
It’s wild, decades of work on least privilege and delegation, and we’re back to handing out root credentials to bots T.T
- story
-
comment
Comment #45106239
Adoption is definitely the hardest "cryptographic" problem :D You can think about this as a new auth token to add in your stack. It does not need to grow and take over the world ov…
-
comment
Comment #45104479
Wafers are definitely inspired by Macaroons, but the core difference is that delegation is tied to identity. In Macaroons, anyone who holds the token can tack on caveats. In Wafers…
-
comment
Comment #45104263
TLDR: JWTs say who you are. Wafers say who this request is on behalf of and exactly what it can do.
- story
-
comment
Comment #45070299
I could not give less of a shit between whitelist/allowlist. I use them indistinctly. You can sleep peacefully today but you should try to don't over stress from how other people w…
-
comment
Comment #45070277
100% needs to be done at the last mile.
-
comment
Comment #45070271
Hi, "this person here" Cloudflare will block that request that has a jwt because "it does not come from a person". What I was trying to say is that even the discussion "is this a b…
-
comment
Comment #45067747
many people don't remember/know history though
-
comment
Comment #45067736
yep, that's why I am writing this now :) You can see it in the web vs mobile apps. Many people may not see a problem on wallet gardens but reality is that we have much less innovat…
-
comment
Comment #45067418
I know the image, what I do not understand is the argument between using it being incompatible with "fairness" and "openness"
- comment
-
comment
Comment #45067204
Where everyone needs a cloudflare account to be able to pay*
-
comment
Comment #45067197
> An allowlist run by one company that site owners chose to engage with. Exactly, no problem with that, just hinting that's not a protocol. > But the irony of taking an ideological…
-
comment
Comment #45067171
The point is "should everyone just have an account with Cloudflare then"
-
comment
Comment #45067145
This is one of the main points :+1:
-
comment
Comment #45067119
I actually thought about this before publishing it hahaha Good thing they are not the only place to post!
-
comment
Comment #45066731
Narrator: but he did put effort... Anyway, main take aways for you: - We REALLY need a way to tie identity to agent/requests - The idea of registering with cloudflare to be able to…
- story
-
comment
Comment #45016804
Giving an agent full access to your data without clear guardrails is a really bad idea. We automate checkouts for e-commerce stores and work with very sensitive information, but ou…
-
comment
Comment #40978923
Well, the answer is "I do not know" Now, if I had to guess, this are "a new kind of cookies" so they just took a name that went with it (like they did with biscuits https://www.bis…
-
comment
Comment #40973693
Unfortunately, that is so complex and changes so often that should not be implemented at protocol level, but around it. P.S: I feel you :)
-
comment
Comment #40973692
Disclaimer: I am the founder of Fewsats, former Lightning Labs employee and owner of the L402.org domain I'd like to clarify a few points and add some context to the discussion. 1)…
-
comment
Comment #40973604
Well, paywall her can also mean any subscription or even credits-based system like SaaS or Compute APIs (AI inference for example) not only for content.