Live data from Hacker News

Viewing profile — sophiabannet1

sophiabannet1

HN member
Joined
Tue, Jun 10, 2025, 11:08 AM UTC
HN karma
4
Public activity
23 items

About sophiabannet1

No profile information was provided.

Recent public activity

  1. comment
  2. story
  3. comment
    Comment #44708100

    Great post! The impersonation vs. delegation framing is spot on. Even in enterprise SSO, proper delegation is clunky. We've toyed with OAuth 2.0 Token Exchange (RFC 8693), but supp…

  4. comment
    Comment #44570350

    Nice move by Supabase switching to asymmetric JWTs, eliminating the need to always call getUser() for verification should noticeably reduce latency at the edge; curious if anyone’s…

  5. comment
    Comment #44570318

    This is a cool idea, so many keyword tools feel unnecessarily gated these days. Love that this removes friction: no signup, instant results, and CSV export without paywalls sounds …

  6. comment
    Comment #44497492

    We have reached a point where most B2B SaaS companies support SSO, but there is still a lot of confusion around which protocol to choose: SAML or OIDC. Both serve the same goal and…

  7. story
  8. story
    OWASP Just Dropped an AI Security Testing Guide

    Just stumbled across something interesting: OWASP quietly released a new guide focused entirely on AI system testing. It's called the AI Testing Guide (AITG). Some of the stuff it …

  9. story
  10. comment
    Comment #44386026

    A reminder that even MFA isn’t foolproof—app-specific passwords can be a weak link. This attack shows how trust and timing, not tech, were the real weapons. Best to avoid ASPs and …

  11. comment
    Comment #44375223

    because SSO is implemented using various protocols like SAML, OAuth 2.0, and OIDC, each with different use cases, data formats, and security models. Identity providers also have cu…

  12. comment
    Comment #44375177

    This is a fantastic breakdown of the real-world benefits of SSO—not just from the end-user perspective, but also from a developer and business standpoint. I especially appreciate t…

  13. comment
  14. comment
    Comment #44326194

    Excellent breakdown, this clearly illustrates why SSO is only half the story and PAM is essential for securing real privileged access.

  15. comment
    Comment #44326107

    A thought-provoking and realistic take on the evolving role of security engineers in the age of AI, versatility and orchestration are clearly the future.

  16. comment
    Comment #44316217

    A powerful reminder of why modern authentication must move beyond SMS—critical insights for anyone building secure systems today.

  17. comment
    Comment #44316161

    This is the funniest and most painfully accurate take on multi-factor authentication.

  18. comment
    Comment #44316043

    Totally agree, SaaS often shifts complexity rather than removing it, integrated platforms feel like coding with training wheels off.

  19. comment
    Comment #44298386

    Useful insight

  20. comment
  21. comment
  22. comment
  23. story