Live data from Hacker News

Viewing profile — positiveblue

positiveblue

HN member
Joined
Mon, Jun 17, 2019, 9:46 AM UTC
HN karma
198
Public activity
28 items

About positiveblue

No profile information was provided.

Recent public activity

  1. comment
    Comment #45129309

    It’s wild, decades of work on least privilege and delegation, and we’re back to handing out root credentials to bots T.T

  2. story
  3. comment
    Comment #45106239

    Adoption is definitely the hardest "cryptographic" problem :D You can think about this as a new auth token to add in your stack. It does not need to grow and take over the world ov…

  4. comment
    Comment #45104479

    Wafers are definitely inspired by Macaroons, but the core difference is that delegation is tied to identity. In Macaroons, anyone who holds the token can tack on caveats. In Wafers…

  5. comment
    Comment #45104263

    TLDR: JWTs say who you are. Wafers say who this request is on behalf of and exactly what it can do.

  6. story
  7. comment
    Comment #45070299

    I could not give less of a shit between whitelist/allowlist. I use them indistinctly. You can sleep peacefully today but you should try to don't over stress from how other people w…

  8. comment
    Comment #45070277

    100% needs to be done at the last mile.

  9. comment
    Comment #45070271

    Hi, "this person here" Cloudflare will block that request that has a jwt because "it does not come from a person". What I was trying to say is that even the discussion "is this a b…

  10. comment
    Comment #45067747

    many people don't remember/know history though

  11. comment
    Comment #45067736

    yep, that's why I am writing this now :) You can see it in the web vs mobile apps. Many people may not see a problem on wallet gardens but reality is that we have much less innovat…

  12. comment
    Comment #45067418

    I know the image, what I do not understand is the argument between using it being incompatible with "fairness" and "openness"

  13. comment
  14. comment
    Comment #45067204

    Where everyone needs a cloudflare account to be able to pay*

  15. comment
    Comment #45067197

    > An allowlist run by one company that site owners chose to engage with. Exactly, no problem with that, just hinting that's not a protocol. > But the irony of taking an ideological…

  16. comment
    Comment #45067171

    The point is "should everyone just have an account with Cloudflare then"

  17. comment
    Comment #45067145

    This is one of the main points :+1:

  18. comment
    Comment #45067119

    I actually thought about this before publishing it hahaha Good thing they are not the only place to post!

  19. comment
    Comment #45066731

    Narrator: but he did put effort... Anyway, main take aways for you: - We REALLY need a way to tie identity to agent/requests - The idea of registering with cloudflare to be able to…

  20. story
  21. comment
    Comment #45016804

    Giving an agent full access to your data without clear guardrails is a really bad idea. We automate checkouts for e-commerce stores and work with very sensitive information, but ou…

  22. comment
    Comment #40978923

    Well, the answer is "I do not know" Now, if I had to guess, this are "a new kind of cookies" so they just took a name that went with it (like they did with biscuits https://www.bis…

  23. comment
    Comment #40973693

    Unfortunately, that is so complex and changes so often that should not be implemented at protocol level, but around it. P.S: I feel you :)

  24. comment
    Comment #40973692

    Disclaimer: I am the founder of Fewsats, former Lightning Labs employee and owner of the L402.org domain I'd like to clarify a few points and add some context to the discussion. 1)…

  25. comment
    Comment #40973604

    Well, paywall her can also mean any subscription or even credits-based system like SaaS or Compute APIs (AI inference for example) not only for content.