HNHacker News
TopNewBestAskShowJobs

machete143

107 karma · joined October 11, 2016

submissionscomments
machete143··on Run your own OAuth2 server
That is a really bad specification with no examples, no formalization, and zero references.

However, all server-side attack scenarios listed there are not possible with Hydra. Some of them also boil down to misusing OAuth2 for authentication, which is why we have OpenID Connect.

machete143··on Run your own OAuth2 server
Thank you for the valuable feedback! The dev mode is indeed a very good idea - I'll probably spin up another docker-compose example with all the default things set up. Would that make it easier?
machete143··on Run your own OAuth2 server
So how do people grant tokens then? They do need to log in somewhere?
machete143··on Run your own OAuth2 server
What I meant to ask is if this has things like user registration, password reset flow, two-factor authentication, account takeover prevention, etc.

I think removing 3rd party dependencies is always a good idea - it keeps things lean and removes ops overhead.

machete143··on Run your own OAuth2 server
Looks interesting, does this solve authentication as well? It looks like it but from quickly scanning through the readme I didn't find anything.

Also what's your reasoning for relying on 4 (etcd, consul, postgres, nats) external dependencies?

machete143··on Run your own OAuth2 server
Good idea! How could that look like on windows (the guide should work on all OS and I'm no windows pro)?
machete143··on Run your own OAuth2 server
I'm not sure if I understood you correctly. Delegation of authentication usually implies trust between the two parties. GitLab (the hosted version) does probably not trust stravros.io enough to allow people to log in through there.

Portier looks indeed very nice, maybe I'll set up a tutorial how to get those two working together to get full Authentication (portier) + Authorization (Hydra) with using only open source technology.

machete143··on Run your own OAuth2 server
Good point, Hydra does this to for things like missing TLS encryption but not yet for secrets (it only rejects secrets that are too short). I've tracked this here: https://github.com/ory/hydra/issues/573
machete143··on Run your own OAuth2 server
Then I hope that this makes your life easier :)
machete143··on Run your own OAuth2 server
That is a valid concern. However, once a password is published (especially in docs or tutorials) it is insecure whether they are random values or not - simply because they are public and clearly linked to the product you're running.

That's why I chose to make it explicit, and thus more likely to be caught in review if done.

machete143··on Run your own OAuth2 server
Yes indeed, running OAuth2 without https is madness!
machete143··on Run your own OAuth2 server
If you're not into reading the article itself and want to check out the technology first, here's the link to github: https://github.com/ory/hydra

If you have any questions, feel free to ask ahead.