HNHacker News
TopNewBestAskShowJobs

idm_guru

51 karma · joined November 30, 2016

Mike Schwartz, CEO Gluu
submissionscomments
idm_guru··on [dead]
Two claims in JWT tokens are evolving for security.
idm_guru··on An Embeddable PDP Boosts Continuous Mobile Authentication
To implement continuous authentication, mobile developers must support fine-grained enterprise security policies about the person, device state and authenticator. An embeddable Policy Decision Point (PDP) is essential for lightning fast policy evaluation, consistent decision logging, and advanced JWT validation.
idm_guru··on Did Automattic commit open source theft?
No one ever won a law suit by putting forward a tepid case. They will position for maximum damage as a bargaining position, just like any of you would.
idm_guru··on Did Automattic commit open source theft?
We will see. You can say it's bollocks, but I'm betting you are not an IP lawyer. Silverlake, the PE firm that acquired WP-Engine has a gaggle of IP lawyers that assessed the risk before the investment. Were they right or wrong? Like any sporting event, everyone has a strong opinion before the game. But it's only the final score that matters. I'm wishing Automatic the best of luck.
idm_guru··on Did Automattic commit open source theft?
This is a trademark dispute. WP-Engine uses the trademark, and made a tactical decision not to license it. Their thought was better to ask for forgiveness later then pay up front. Protecting your trademark is critical for an organization governing an open source product. Just look at Docker to see what happens when you lose control of your trademark. Last I checked, most owners aggressively protect their trademark. It's one of the few IP protections open source companies have. Why are you all defending the freeloading open source strip miner? Is WP Engine's use of the trademark fair use? Something tells me that they will end up settling this out of court...
idm_guru··on Persisting as a solo founder
Note: the definition of an entrepreneur is someone who doesn't listen to advice (some of it good). This dude says you're startup is "zombie"... Well, he might be right, but if you see an opportunity there... That's what makes you smart. And in 10 years if you're successful, the same people who said your idea was bad will be saying it was obvious.
idm_guru··on Persisting as a solo founder
As a solo founder for 10+ years, what I can say is that all "rules" in business are "rules of thumb"... Not laws. It's ok to be a solo founder... Sometimes. Bounce ideas off your team instead of your co-founders. Make use of mentors. There is a workaround for all your challenges. I also recommend listening to podcasts with other founders. I host a podcast called "Open Source Underdogs". Lots of good advice there for all founders... Even if you're not working on open source. But there are plenty more. You need outside ideas... Just seek them out.

Don't burn out your friends talking about your startup. It's not that they aren't interested. But nobody needs a single vector relationship.

Also remember that VC's give tons of bad advice to founders. Or rather founders tend to put VC's on a pedestal, and misinterpret what they are saying as advice, when it is really just filter, convenient lies or lazy analysis. Be hugely skeptical of anything VC's tell you, including "you need co-founders".

idm_guru··on 9 tips for starting an open source software company
If you are an open source software company that wants to share your story, please reach out to us on https://opensourceunderdogs.com
idm_guru··on Why There Will Never Be Another RedHat: The Economics of Open Source (2014)
I am CEO of Gluu. The podcast is an undertaking to help new open source software companies. There is no business model for the podcast, and it's attribution share alike license.
idm_guru··on Why There Will Never Be Another RedHat: The Economics of Open Source (2014)
I'm recording a podcast, called Open Source Underdogs, focusing on open source business models. You can find it on iTunes, Google, Stitcher, etc or on the website https://opensourceunderdogs.com

IBM just made it's biggest acquisition ever on an open source company... It seems strange to use that as evidence that open source is not an effective tool--in certain circumstances--for building your business.

What about Cloudera? What about Automattic? What about MongoDB? What about MariaDB?

The podcast has 9 episodes, and we have about 20 more in the queue for 2018-2019.

Tune in... Some of the gurus of open source software share some valuable insights.

idm_guru··on Se­cu­rity Keys
I prefer my HyperFIDO Mini. The Nano sends OTP text if you accidentally brush into something, and it's very awkward to get out. The light is "blinding" ??? That is ridiculous...
idm_guru··on Next wave of SaaS
Auth0's business model is a race to zero. Microsoft, Google, Salesforce, Oracle and others (for example Okta, Onelogin in the startup arena) are going to force their prices down to practically nothing. The per user pricing model in the identity space is loved by insipid venture capitalists who like simple "back of the envelope" math, but customers hate it. You are penalizing customers for using your service--rewarding them for putting as few users as possible in the system. Also, there is no one-size fits all value for users--some users are more valuable then others (for example, an employee versus a one-time ecommerce customer who buys a t-shirt). So you end up trying to price users differently, which undermines your value story. What's more likely to happen is that open standards will increase competition and centralized service providers who add very little value, and are big targets for hackers, will be lucky to get out alive.
idm_guru··on Discussion on Exploiting OAuth 2.0 in Mobile Applications by ENISA
For more info about OpenID Connect, see http://openid.net/connect
idm_guru··on OAuth vs. SAML vs. OpenID Connect
One thing to keep in mind is that Gluu is an IAM platform, not just an OpenID Connect Provider. It's a comprehensive suite that includes both central authentication, authorization, FIDO authentication (and support for many two factor technologies), mobile software, client software. Starting in version 3.0, we will bundle a special version of OpenLDAP, provided by Symas (another great FOSS vendor), specifically optimized for the Gluu Server.

An IAM platform is many products integrated together, and operationally scalable to meet mission critical requirements. An OpenID Provider is just one element of an IAM platform!

idm_guru··on OAuth vs. SAML vs. OpenID Connect
I totally agree with the lack of libraries!!! That's why we're working on oxd at Gluu: https://oxd.gluu.org

If you need a license, just email support@gluu.org It's not free open source, but it will be very inexpensive. It reduces OpenID Connect to a simple three step process (with three corresponding method calls):

1. Get code 2. Get tokens 3. Get user_info

There are two more supporting methods:

4. Register client 5. Logout

I wrote a sample cgi-bin application (and there is also a sample Flask application) that shows how to use it. https://github.com/GluuFederation/oxd-python/tree/master/dem...

idm_guru··on OAuth vs. SAML vs. OpenID Connect
It's no more confusing then LDAP. First there was LDAP 1.0, 2.0, now we all use 3.0...

OpenID 2.0 is deprecated. Don't use it.

The current OpenID authentication protocol = OpenID Connect.

In the not too distant future, no one will even remember that something called OpenID 2.0 existed.

Maybe OpenID Connect should be OpenID 3.0? I think the idea was to show alignment with Facebook Connect's design...but more open. Remember, at the time Facebook Connect provided some good data--it was a massive user acceptance test.

IMHO, the blame lies with the OIDF for not delivering this message. OpenID Connect has been final for 4+ years. What's taking so long? Maybe it's not in the interest of the OIDF's controlling board members to promote this distributed identity infrastructure? MSFT wants you to use Azure AD. Google wants you to use their IDP. Maybe they don't want to promote until they have product ready? Stay tuned... I think when it's in the interest of the current finanical backers of the OIDF to promote OpenID Connect, no one will remember that old OpenID 2.0 thing.

idm_guru··on ForgeRock quietly cuts off “trunk” access to OpenAM, OpenDJ, and OpenIDM
That's why everyone is switching to Gluu....