Live data from Hacker News

Okta's NextJS-0auth troubles

joshua.hu

161–167 of 167 posts

Re: Okta's NextJS-0auth troubles

#161
post #122

Earlier quoted context omitted.

Apart from auth0 getting hacked, before getting acquired by Okta. [0] [0] https://auth0.com/blog/auth0-code-repository-archives-from-2...

What is the point that you are trying to make? Okta has committed to and has had a consitent track record of delivering at least one full scale security breach and the consistent user expericence degradation to their customers every year – and completely free of charge.

Absolutely. And auth0 was also delivering that, before acquisition. It isn't a change of routine.

Re: Okta's NextJS-0auth troubles

#162
post #28

I LOVE LLMs as a learning tool. I HATE LLMs as a communication tool. I know, there are people with serious handicaps who benefit from LLMs in this area. If only I could talk to those people and not wade through all this other garbage. Especially when the AI is being represented as a person, this to me is dishonest. Not to mention annoying, almost more-so than the number of different apps that think they are important…

LLMs have definitely helped me reduce my social anxiety when writing, especially in a technical work setting. I don’t use it like the respondent in the article though, I would feel really embarassed to not edit an llm’s output to be in my own voice. But I feel it helps provide me with some structure in whatever I’m trying to write when I don’t have the mental energy or wherewithal to provide it myself.

I agree. I’ve used LLMs to aid in writing out copy and other things, but as a learning tool and not as a way to remove myself from the process. I especially don’t like where businesses are taking this. At least with the old chat bots and such you knew you were in an equivalent of a phone tree. Now it’s hard to tell what’s human and what isn’t, and therefore difficult to know how to interact.

Re: Okta's NextJS-0auth troubles

#163
post #114

Earlier quoted context omitted.

None of this rings true, and I've implemented both OAuth2 and OpenID Connect multiple times, also reading the specs, which are quite direct. I'm sure you're right that vendors take liberties -- that is almost always the case, and delinquency of e.g. Okta is what started this thread.

It's an AI bot. One for @dang

Why do you suspect that?

Re: Okta's NextJS-0auth troubles

#164

I think it is distasteful and disrespectful to call out an employee by name in this way, regardless of the merit of the rest of the OP's post.

While I think the blog post is dramatic, I don't think the author did anything wrong by mentioning the name of the person he feels wronged by. The information is public and it's the only way for that individual to be held accountable by anyone who comes across the article.

Re: Okta's NextJS-0auth troubles

#165
post #44

Earlier quoted context omitted.

well, it was distasteful of to them to close op's pr and apply the same patch with improper attribution, and then use ai to respond when they were asked about it

I agree with the parent post that it's distasteful. There's no value in naming the employee. Whatever that employee did, if the company needed to figure out who it was, they can from the commit hashes, etc. But there's no value in the public knowing the employee's name. Remember that if someone Googles this person for a newer job, it might show up. This is the sort of stuff that can disproportionately harm that perso…

> Remember that if someone Googles this person for a newer job, it might show up.

So you'd rather the company get incomplete information about a candidate with hopes the candidate gets hired from a place of ignorance? If it's something the company would avoid hiring him for, then I don't find a problem with giving them the agency to make that decision for themselves.

Re: Okta's NextJS-0auth troubles

#166

I'm shocked. Where are all the "SSO companies handle edge cases you can't even imagine" people? It's been 24 hours.

If SSO were so easy to solve we wouldn't have a gazillion companies for it. It's probably easy enough if you are a really good engineer, but like 90% working in this industry aren't. Also you ever implemented OAuth2 or shudder SAML? Not how I would like to spend the one life I have been given.

I think the fact that there are a gazillion companies for it, and they don't compete on security, but instead compete for billboard space in the Mission District of SF and Redwood City California, shows how easy it is to solve.

Re: Okta's NextJS-0auth troubles

#167

Earlier quoted context omitted.

If SSO were so easy to solve we wouldn't have a gazillion companies for it. It's probably easy enough if you are a really good engineer, but like 90% working in this industry aren't. Also you ever implemented OAuth2 or shudder SAML? Not how I would like to spend the one life I have been given.

I think the fact that there are a gazillion companies for it, and they don't compete on security, but instead compete for billboard space in the Mission District of SF and Redwood City California, shows how easy it is to solve.

I would rather say it shows that no one really cares about security...
Post reply on HN