HNHacker News
TopNewBestAskShowJobs

edwardr

-1 karma · joined August 25, 2014

submissionscomments
edwardr··on WeChat permanently closes account after user sets offensive password
As an alternative to this checkout TozID. The premise of their authentication model is to avoid sending the password all together and use public key crypto to sign and verify requests between the client and the auth server.

https://tozny.com/tozid/

edwardr··on Ask HN: What's the best corporate password manager?
I'd agree that SSO is a good option. Check out our SSO solution and ping me with any questions!

https://tozny.com/tozid

edwardr··on Show HN: Identity management with end-to-end encryption
It is an SSO platform with authentication based on client side cryptography that enables end-to-end encryption for applications. It supports SAML clients like other SSO platforms.
edwardr··on [dead]
Yes - happening here as well.
edwardr··on FileKit: An open source end-to-end encrypted cloud storage service in JavaScript
Browser crypto has come a long way. With libraries like libsodium and proper implementation I think it’s drastically better than at the time of those articles (2013 and 2011).

Source: we also write encryption libraries and have a free implementation of our browser sdk at https://share.labs.tozny.com

edwardr··on Show HN: Encrypted One Time Secret Sharing
We made this using sodium for end to end encryption - let me know what you think!

If you're interested in reading more about it check out this blog post https://tozny.com/blog/encrypted-one-time-secret-sharing-app...

edwardr··on RSA is a fragile cryptosystem
Try reading up this guide for a great intro into application level crypto... https://tozny.com/security-guides/
edwardr··on Privacy Is Just the First Step, the Goal Is Data Ownership
I agree w/ OP. Using cryptography for privacy and data control is a step in the right direction and needs some critical mass behind it for broader adoption.

Shameless plug - that is exactly what Tozny provides. An easy way to have end to end crypto with a sharing model that keeps data in control of the original writer.

edwardr··on How to prevent cryptographic pitfalls by design [video]
Helping developers avoid the pitfalls of cryptography is the main problem we at Tozny (http://tozny.com) are trying to solve.

We found that there is so much mis-information available online it's too easy to shoot yourself in the foot with cryptography so we're trying to make tools that make strong crypto easy to implement.

edwardr··on Ask HN: Who is hiring? (October 2018)
Tozny | Multiple Positions | Portland, OR | ONSITE FT https://tozny.com

Tozny provides end to end encryption as a service. We work with public and private organizations to create easy to use cryptography services.

https://tozny.com/hiring/

We're funded and growing rapidly. Our backend is primarily Scala and we have SDK's in many languages including node, swift, java, php, etc.

edwardr··on Webhook Tester
Nice! Some services don't allow non-https URLs for the webhook even for development (slack...), so might be nice to support that. Let's Encrypt provides free SSL certs if you wanted to go that route.
edwardr··on Ask HN: Growing faster and starting to have scaling issues. Where to go from here?
Assuming you are on AWS you could look into using some of their tools like Opsworks to help deal with the growing pains.

Its a temporary solution since you would just be using more servers to alleviate the root cause rather than optimizing the code. Opsworks will let you deploy additional servers easily and a contractor can do all the technical setup for you. You can queue servers based on load or time of day and it can run all of your php/database servers for you.

Hope it helps and you can use something like New Relic to help notify you of downtime or performance gaps in your application.