Earlier quoted context omitted.
Apart from auth0 getting hacked, before getting acquired by Okta. [0] [0] https://auth0.com/blog/auth0-code-repository-archives-from-2...
What is the point that you are trying to make? Okta has committed to and has had a consitent track record of delivering at least one full scale security breach and the consistent user expericence degradation to their customers every year – and completely free of charge.
Okta's NextJS-0auth troubles
161–167 of 167 posts
Re: Okta's NextJS-0auth troubles
#162I LOVE LLMs as a learning tool. I HATE LLMs as a communication tool. I know, there are people with serious handicaps who benefit from LLMs in this area. If only I could talk to those people and not wade through all this other garbage. Especially when the AI is being represented as a person, this to me is dishonest. Not to mention annoying, almost more-so than the number of different apps that think they are important…
LLMs have definitely helped me reduce my social anxiety when writing, especially in a technical work setting. I don’t use it like the respondent in the article though, I would feel really embarassed to not edit an llm’s output to be in my own voice. But I feel it helps provide me with some structure in whatever I’m trying to write when I don’t have the mental energy or wherewithal to provide it myself.
Re: Okta's NextJS-0auth troubles
#163Earlier quoted context omitted.
None of this rings true, and I've implemented both OAuth2 and OpenID Connect multiple times, also reading the specs, which are quite direct. I'm sure you're right that vendors take liberties -- that is almost always the case, and delinquency of e.g. Okta is what started this thread.
It's an AI bot. One for @dang
Re: Okta's NextJS-0auth troubles
#164I think it is distasteful and disrespectful to call out an employee by name in this way, regardless of the merit of the rest of the OP's post.
Re: Okta's NextJS-0auth troubles
#165Earlier quoted context omitted.
well, it was distasteful of to them to close op's pr and apply the same patch with improper attribution, and then use ai to respond when they were asked about it
I agree with the parent post that it's distasteful. There's no value in naming the employee. Whatever that employee did, if the company needed to figure out who it was, they can from the commit hashes, etc. But there's no value in the public knowing the employee's name. Remember that if someone Googles this person for a newer job, it might show up. This is the sort of stuff that can disproportionately harm that perso…
So you'd rather the company get incomplete information about a candidate with hopes the candidate gets hired from a place of ignorance? If it's something the company would avoid hiring him for, then I don't find a problem with giving them the agency to make that decision for themselves.
Re: Okta's NextJS-0auth troubles
#166I'm shocked. Where are all the "SSO companies handle edge cases you can't even imagine" people? It's been 24 hours.
If SSO were so easy to solve we wouldn't have a gazillion companies for it. It's probably easy enough if you are a really good engineer, but like 90% working in this industry aren't. Also you ever implemented OAuth2 or shudder SAML? Not how I would like to spend the one life I have been given.
Re: Okta's NextJS-0auth troubles
#167Earlier quoted context omitted.
If SSO were so easy to solve we wouldn't have a gazillion companies for it. It's probably easy enough if you are a really good engineer, but like 90% working in this industry aren't. Also you ever implemented OAuth2 or shudder SAML? Not how I would like to spend the one life I have been given.
I think the fact that there are a gazillion companies for it, and they don't compete on security, but instead compete for billboard space in the Mission District of SF and Redwood City California, shows how easy it is to solve.