Viewing profile — sophiabannet1
sophiabannet1
HN member- Joined
- Tue, Jun 10, 2025, 11:08 AM UTC
- HN karma
- 4
- Public activity
- 23 items
- HN profile
- View on Hacker News ↗
About sophiabannet1
No profile information was provided.
Recent public activity
- comment
- story
-
comment
Comment #44708100
Great post! The impersonation vs. delegation framing is spot on. Even in enterprise SSO, proper delegation is clunky. We've toyed with OAuth 2.0 Token Exchange (RFC 8693), but supp…
-
comment
Comment #44570350
Nice move by Supabase switching to asymmetric JWTs, eliminating the need to always call getUser() for verification should noticeably reduce latency at the edge; curious if anyone’s…
-
comment
Comment #44570318
This is a cool idea, so many keyword tools feel unnecessarily gated these days. Love that this removes friction: no signup, instant results, and CSV export without paywalls sounds …
-
comment
Comment #44497492
We have reached a point where most B2B SaaS companies support SSO, but there is still a lot of confusion around which protocol to choose: SAML or OIDC. Both serve the same goal and…
- story
-
story
OWASP Just Dropped an AI Security Testing Guide
Just stumbled across something interesting: OWASP quietly released a new guide focused entirely on AI system testing. It's called the AI Testing Guide (AITG). Some of the stuff it …
- story
-
comment
Comment #44386026
A reminder that even MFA isn’t foolproof—app-specific passwords can be a weak link. This attack shows how trust and timing, not tech, were the real weapons. Best to avoid ASPs and …
-
comment
Comment #44375223
because SSO is implemented using various protocols like SAML, OAuth 2.0, and OIDC, each with different use cases, data formats, and security models. Identity providers also have cu…
-
comment
Comment #44375177
This is a fantastic breakdown of the real-world benefits of SSO—not just from the end-user perspective, but also from a developer and business standpoint. I especially appreciate t…
- comment
-
comment
Comment #44326194
Excellent breakdown, this clearly illustrates why SSO is only half the story and PAM is essential for securing real privileged access.
-
comment
Comment #44326107
A thought-provoking and realistic take on the evolving role of security engineers in the age of AI, versatility and orchestration are clearly the future.
-
comment
Comment #44316217
A powerful reminder of why modern authentication must move beyond SMS—critical insights for anyone building secure systems today.
-
comment
Comment #44316161
This is the funniest and most painfully accurate take on multi-factor authentication.
-
comment
Comment #44316043
Totally agree, SaaS often shifts complexity rather than removing it, integrated platforms feel like coding with training wheels off.
-
comment
Comment #44298386
Useful insight
-
comment
Comment #44297452
[dead]
-
comment
Comment #44297424
[dead]
-
comment
Comment #44297405
[dead]
- story