Hacker Newsnew | past | comments | ask | show | jobs | submit | 9dev's commentslogin

Yes. But it’s authentication, whereas OAuth is authorization.

I kinda disagree. Authentication is at OAuths core. You still need to authenticate to obtain a token and in more complex setups you don’t use it for authorization at all because tokens are stale immediately after issuing them. It’s why things like Zanzibar and OPA have been made.

It’s really not. OAuth makes zero assumptions about how you login - granted, the client credentials flow is a form of authentication if you will, but for the user perspective, OAuth starts when you’re signed in. That’s also why you can easily combine it with all kinds of authentication providers.

> OAuth makes zero assumptions about how you login

Neither does OIDC: "The methods used by the Authorization Server to Authenticate the End-User (e.g., username and password, session cookies, etc.) are beyond the scope of this specification."

OAuth makes zero assumptions about a lot of things, like even how you "authorize". That doesn't mean that authentication doesn't play a crucial role. While it doesn't specify how you authenticate the user it still specifies that you must authenticate the user. Outside of the authorization code flow, other flows strictly mandate that you should authenticate the clients.


> If the IP, Wireguard or JSON people designed an SSO system you'd telnet or HTTP into the authenticating party, perform its login steps, get a token you could copy-paste into the relying party and it would check back with the authenticating party to see if the token is valid and the username of the person who signed in - done.

That is a workable if coarse description of OIDC, which kind of fits your SAML vs. OIDC framing, although I’m pretty sure that’s not what you meant to imply.


It’s beautiful. You can even give the underclass their own bullshit economy with struggling startups competing for the scraps, sprinkle some targeted influencer ads to give people the illusion of a better future, and they will be perpetually busy fighting windmills. All the while the upperclass can shape the world however they please.

Sure does. R&D investments have a massively larger RoI than military spending - and you won’t be paying off that debt by trying to be frugal. The only way is forward, and bombing schools in Iran isn’t that. It might not be Mars either, but at the very least some interesting science falls out of it, and perhaps some interesting products out of that.

The way we spend military budget is inefficient yet, Americans grew in 90s not to say eu people tend to believe we live in the rosy world of friendly people , despite countries like North Korea , Iran , Russia , and even China to a certain extent.

I don’t think the debt has much to do with it, but I’m annoyed by the opportunity cost.

Put another way, I’m pretty sick and tired of planing 30 year long missions, with all the money an engineering and human resources, for rocks.

It was almost certainly not going to tell us conclusively about past life on mars. And if it could, let humans collect it.

The next person who suggests an $11B mission for rocks should get smacked with a yardstick.


You're missing the forest for the trees. It's not about "rocks", but the science retrieving those rocks enables.

> Put another way, I’m pretty sick and tired of planing 30 year long missions, with all the money an engineering and human resources, for rocks.

The engineering and Human Resources involved are a feature, not a bug! That's how you keep knowledge around, people employed, and strategically important industries alive, even if they nominally do not have enough orders to survive. You can't just decide "let's launch a rocket" and do so quickly when it's critically important--those capabilities have to be tended to.

The US just recently learnt this the hard way when it turned out nobody knew how to build icebreakers anymore, and had to buy them from Finland.

> It was almost certainly not going to tell us conclusively about past life on mars. And if it could, let humans collect it.

Sending humans to Mars is mindbogglingly complicated, has a massive chance of death by one of a thousand exciting possibilities, and doesn't add anything to returning samples that a robot can't do cheaper, faster, and most importantly now.

Yes, at some point it might be worthwhile to send humans there, but there are a lot of challenges that have to be overcome before we are actually ready. All the while there are samples sitting around idle.

> The next person who suggests an $11B mission for rocks should get smacked with a yardstick.

I seriously hope the yardstick hitting en vogue right now will soon be displaced by civilised discussions again.


…ridiculously low compared to a Defense budget of $1500 billion? Agreed.

I’d rather have a defense system over space junk.

What kind of defence system is to start wars with countries that don't pose any threats on you?

And now you have none.

Surely you realise that there’s a balance between “stop reproducing and die to avoid harm to the world” and “consume all resources available for short-sighted gluttony”.

There are absolutely ways to lower our impact and lots of smart people working on figuring out how this can be made to work at scaley


So far, it appears those smart people have created a ideological caused self-extinction of western civilizations and thus a take-over by unapologetic expansionist imperialist cultural systems. Not very smart and not very longterm loadbearing.. it seems those "smart" people are mostly ideological driven and unable to work with the flawed, half-animal humans given.

Honestly -- I think the deeper point here is Nietzsche's: there's nothing wrong about winning. Nothing wrong about conquest. Nothing wrong with having three kids and outcompeting your neighbor.

This cultural meme spreads because short term gluttony is not, in fact, winning: if you eat your seed-corn, next year you starve. And winning is not about quantity either, but quality: I unapologetically want to shape the light-cone in my image, and my image recoils at torment.


You seem to think design is mere flourishing, nice colors to make something pleasant to look at, but ultimately superficial and useless. I would strongly object to that--visual presentation can carry a lot of additional information, and improve the transmission as well. Giving more people the ability to present information well leads to more efficient communication, which I wouldn't just dismiss this easily.

But there isn't any extra information in AI posters. It's necessarily either something that can already be conveyed in writing (that is after all, what they're prompted in), or something the AI pulled in based off of the text unintentionally, at which point no actual information is being conveyed by the added visuals.

I think you need to remember that most people have no eye for design, and that includes even just presenting the essentials of an event in text.

And AI can actually do it much better than the average idiot. Of they ask.

Like, if you ask - "here's the event details, let's make a poster" in the right way, it's going to come back and say "you've supplied the venue name but not the street address, do you want to include that?".

And then it'll lay the info out with generally sensible relative sizes and positions, better than the average idiot would.

And, probably about equally as well as the average "I'm not a designer but I know a bit" amateur - and a lot faster.

The catch there is that the idiot only gets this if their prompt is right - and since they're an idiot, it probably isn't.

I think there's a gap in the market for a service with system prompts that make it work for people who don't think very hard.

(That might be what, say, Canva Pro does with its AI features. I don't know because I'm not paying for that.)


So you want to reduce entropy by “fixing” semantic mistakes and hardcoding some design decisions “by the book” and end up with what exactly? The exact same poster everywhere?

That's a more interesting question than you might have intended it to be.

A designer's job has two contradictory aspects. One is knowing the rules and following the rules. The other is having novel ideas, and breaking the rules when it works.

The balance between those depends on the brief, and the designer's place in the ecosystem. For example the architect I paid to design my extension wasn't in the business having novel ideas - he designs well proportioned buildings in established styles, that work as living spaces, don't fall down, and get approved by planning authorities.

But other architects are paid to design skyscrapers that look like nothing you've seen before.

For a school fete poster, you're probably more in the first category - follow the rules. But you want to know where there's room for variety within those rules. Which is where the blog post starts - not every Spring fete poster has to have bunting and daffodils.


Razor 1911! Now here’s a name I haven’t heard in a long time, but teenage me was very grateful to.

The .nfo files alone, distributed with most releases, carrying the most elaborate of ASCII art. I distinctly remember the aesthetics you mention.


> The .nfo files alone, distributed with most releases, carrying the most elaborate of ASCII art. I distinctly remember the aesthetics you mention.

See their 40 year retrospective demo for a lot more of that: https://www.youtube.com/watch?v=dybkLM-1eQo :)


I still refer to 1:37 pm (13:37) as "l33t o'clock" and 7:11 pm (19:11) as "Razor o'clock". They seem to come up remarkably often when I glance at the time, like 11:11 for normies, but I think all of these are some sort of pareidolic/selection-bias effect wherein your brain is just more likely to remember/notice times that it considers significant.

If you ever need to scratch that ASCII art itch: https://asciiarena.se/

Remember realizing it’s 0x777, one better than 666?

Probably more a reference to total file permissions.

That's 777 octal tho

I believe this was the case, as there was a lot of 666 going around at the time.

6-7 had yet to be discovered.

> people who re-use passwords and/or don't use a password manager.

So the vast majority of all humans on this very planet?


Don’t you remember the giant phishing campaigns like back when lots of celebrities got their nudes in iCloud stolen and published? These things happen all the time, and are incredibly painful. Much, much more so than being unable to share your account with a coworker.

> ...when lots of celebrities got their nudes in iCloud stolen and published?

Right-- high-value victims of targeted attacks. So not regular people.


Regular people get their data stolen all the time, you just don’t hear about it. Just look at the credential dumps and the most common passwords.

I don't get the sense that regular people get data "stolen".

Ransom is the only thing I see happening to end user data.

Credential thefts facilitate theft of money. It might might help the attacker to rifle thru somebody's data to find information that helps answer "secret" questions, to trick friend and family into getting phished, and maybe blackmail, but I don't see a market for end user data that would drive data theft. Nobody is buying end user photos, videos, email, etc. (Anybody who would possibly buy it just tricks/entices users into giving it to them for free to train their AI models anyway.)


LLMs ironically are changing this[0], but at least until now, rifling through random people's data did not scale, so aside for a subset of cases where it was possible to automate access to some services or otherwise leverage them into a scam on the cheap, it wasn't of interest because there was literally nothing useful to do with it.

--

[0] - LLMs, whether multimodal or combined with modern AI-driven STT / TTS pipeline, enable running highly personalized scams cheaply and in an automated fashion, which does scale up and suddenly makes this data important. But that's a very new consideration, one which passkeys were not designed for, because it literally was not possible or conceivable even few years ago.


At the scale you'd expect that to happen, looking at credential dumps, you'd also expect to hear a lot about it.

And yet, you don't. Which leads me to the conclusion that the data dump are overblown.

I think companies around the world come to the same obvious conclusion, which is why these data breaches keep happening, and the companies whose systems were breached are never any worse for the wear.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: