HNHacker News
TopNewBestAskShowJobs

advaitruia

428 karma · joined September 12, 2016

YC Badge: 0xc94861973c23bd9ef99326efc950c7f20b35aef9
submissionscomments
advaitruia··on OpenAI uses open source Ory to authenticate over 400M weekly active users
Funny thing is that its powered by Auth0. Its funny that Ory is asking for the HAR file
advaitruia··on OpenAI uses open source Ory to authenticate over 400M weekly active users
Could you clarify what OpenAI actually uses Ory for? Their main login page is powered by Auth0
advaitruia··on How shut-down Bay Area tech companies ditch their fancy gear
Nothing like buying 12 TGIFs in the midwest?

https://svdisposition.hibid.com/catalog/607470/tgi-fridays--...

advaitruia··on Thank HN: My bootstrapped startup got acquired today
Congratulations! This is great - one of the few globally successful SaaS cos from India with an exit!
advaitruia··on Show HN: I built an app to manage your eBooks
This is cool!

Can checkout SuperTokens which is also open source and self hostable but not sure if its worth it for now.

advaitruia··on Ask HN: How would you implement auth for a self hosted product?
Have you seen open source authentication products like SuperTokens or Keycloak?

Alternatively, you could use framework specific authentication libraries like nextjs or Devise (Ruby)

advaitruia··on When 'open core' projects reject contributions for competing with the EE
Chiming in here as the cofounder of an 'open core' company:

This obviously wasnt handled as well as it could have been.

On the fundamental issue of building EE features: If 100% of the code was open source, there would be less incentive for them to continue to maintain, update, upgrade the product. The EE features ensures that there is an incentive for them to continue to work on this project. Infact, the community _should_ want project maintainers to be compensated.

As someone else said, the project is open source, you can always fork and add any specific feature you want. It comes down to how useful is the actual open source project. If it is very limited in features and functioning, then yes - it is against the spirit of the open source. But if its a fully usable, functioning product (not for all but atleast some number of usecases), then it has created value which it is not capturing for itself - which is a net good for society and the industry.

advaitruia··on Okta says hackers stole data for all customer support users
Supertokens - open source user authentication.

Our UI is native to your website (no redirects) and the auth logic sits within your backend api layer - giving you a lot more control

advaitruia··on HashiCorp switching to BSL shows a need for open charter companies
Im a OSS founder.

This is a balanced article and I definitely agree about being clear on what constitutes competition. A few questions:

1. Does Gitlab see much competition from hyperscale providers like AWS?

2. Given that Gitlab has a thicker proprietary crust and a relatively smaller open source core (compared to hashi), is Gitlab more insulated from these types of issues?

advaitruia··on American stocks are at their most expensive in decades
The metric to measure how expensive equity is sounds flawed. Expected earnings divided by share price is not indicative of actual equity returns - especially over 1 year?
advaitruia··on Infisical – open-source HashiCorp Vault alternative
More often than not, making money and making good software are complimentary outcomes. Its difficult to do the former without the latter.

Infisical is an open core business model. While there is a proprietary crust, the core is truly open source.

Disclaimer: I run an open core venture

advaitruia··on HashiCorp adopts Business Source License
Most of the comments on this thread make it appear that everyone will be affected by this change. The vast majority wont be affected at all.

This only affects people who are directly competing with hashicorp using hashicorps code. That sounds like a reasonable thing to want to prohibit.

Why should hashicorp have to spend tens of millions on product development only for a competitor to spend zero but be able to offer the same product? That sounds like a net negative for the whole industry as it disincentivizes R&D

advaitruia··on Show HN: Launching Struct – Knowledge-Rich, AI-Powered Chat Platform
Happy user here of the newly launched Discord integration :)
advaitruia··on Ask HN: What is up with Auth0's terrible account deletion procedure?
Not ideal..

What are you planning on using instead?

advaitruia··on Are there off-the-shelf tools for multi-tenant application administration?
We're launching exactly this at supertokens.com

We wont have all the things you mention but will everything to do with tenant onboarding, identity management, user authentication will be out of the box. So in terms of functionality, it would be comparable to keycloak but easier to extend and integrate monitoring and billing tools.

advaitruia··on Supertokens: Open-Source Alternative to Auth0 / Firebase Auth / AWS Cognito
Agreed on feature naming - will fix!

Also I definitely understand your perspective and it makes sense. SuperTokens still is 100% open source - but you are right, as we evolve into a paid offering, there is scope for improvement

advaitruia··on Supertokens: Open-Source Alternative to Auth0 / Firebase Auth / AWS Cognito
We've raised money every year in the last 3 years. We just dont update crunchbase.

we're being used at scale of millions of monthly active companies by very large companies - which have done deep technical evaluation.

If the company dies or gets acquired (possible with companies of almost all stages), the product is actually open source. You can self host it without any permissions and we provide daily database backups

advaitruia··on Supertokens: Open-Source Alternative to Auth0 / Firebase Auth / AWS Cognito
|| Without qualifying the weight of every feature, it numerically raises a significant challenge to your statement.

Well i think that is the only thing that matters.

If I split all auth methods into the 6 different features it really is, then it becomes 13 free features.

The ones listed as not open source is to indicate what we plan to build for our paid offering. If we removed those and 13/13 were open source, would that change your views? If yes, then that qualification is pretty important.

SAML client and OAuth client are both free. You can add auth with any OAuth 2.0 provider to SuperTokens.

Being an OAuth 'provider' (emphasis) is not open source as it is a feature you need for complex use cases.

You can add 2FA with email or SMS in the open source product too (just requires some customizations and overrides)

advaitruia··on Supertokens: Open-Source Alternative to Auth0 / Firebase Auth / AWS Cognito
Yes, its a very subjective point.

We've mentioned the source (if you hover) and it is based on our internal user research and conversations with users of these products. By no means is it perfect and there are many many satisfied customers of each of the other products.

Your point is taken though and maybe we will edit that point out or try to add further nuance.

I do believe however that broadly speaking, that reviews of keycloak lean towards it being relatively harder to use and maintain than Firebase. Arguably the reviews of Cognito are more mixed than "Low"

advaitruia··on Supertokens: Open-Source Alternative to Auth0 / Firebase Auth / AWS Cognito
Many of the core features are open source. Eg all the authentication methods - email password, passwordless, social etc are all in the open source product. You can also use the open source components to implement email based or SMS based 2FA.

RBAC, session management and user management dashboard are open source too. Its several years of an engineering team's work that is all open source.

Our philosophy is to keep features that are broadly required by developers and small companies in the open source version. Things that large companies require, will be source available.

We have several enterprises (more than $100M raised or several hundred employees) that are using SuperTokens at the scale of millions of monthly active users - all using the open source product. We think the open source product is a sufficient alternative (for a large enough population).

Are there any other features you feel should be in the open source version? Happy to hear any feedback and improve

(Project creator here)

advaitruia··on Supertokens: Open-Source Alternative to Auth0 / Firebase Auth / AWS Cognito
All the features you see on github / the website is under the apache 2.0 license - truly open source.

The only code in EE so far is the feature flags. We will implement certain "source available" features in the future

advaitruia··on How and why we acquired our .com domain
The claim is that we saw traffic patterns on the .com mirror that of the .io even though nothing was on it yet and we had not migrated.

Our inference or best guess based on the above is that people were typing supertokens.com directly in the URL bar on the browser. Like you said - I would not have expected that (and still doubt it) but dont have any alternative explanations for why that would be the case.

Our agency doesnt know we've even written this. I still need to share it with them.

advaitruia··on How and why we acquired our .com domain
Thats a really interesting anecdote.. Most squatters sit on domains for 10+ years though. Both the 'good' .com domains I've bought were held unused by squatters for almost 20 years. Maybe thats what you need to do when you have a domain like that?
advaitruia··on How and why we acquired our .com domain
We used Ritch at acquirable
advaitruia··on How and why we acquired our .com domain
How much does SEO play a role in your customer acquisition? Do you have a lot of existing backlinks to the .net domain? Do you plan to continue building this product for a long time?

Depending on the answers to these questions, I would evaluate the tradeoffs of migrating. If SEO is not critical or if you already have a certain domain authority / backlinks or dont plan to continue for a long period of time - then it may not make sense to migrate.

advaitruia··on How and why we acquired our .com domain
Why not reach out to a domain broker to acquire it? Or even reach out yourself?
advaitruia··on How and why we acquired our .com domain
Yes we are a OAuth 2.0 client (and have SAML integrations too).

So if PingFederate is the provider, you can add "sign in with Ping" on an app that uses SuperTokens

advaitruia··on How and why we acquired our .com domain
Right - that makes sense. Unfortunately cant edit the title now
advaitruia··on How and why we acquired our .com domain
Haha, that was a straightforward purchase. I dont think i've ever been able to find another advaitruia (advait on its own is an uncommon name)
advaitruia··on How and why we acquired our .com domain
Correct. I've edited it to say that clearly (finally). Sorry about all the confusion here
Page 1 of 4Next →