HNHacker News
TopNewBestAskShowJobs

mffap

454 karma · joined April 14, 2021

working at https://github.com/zitadel
submissionscomments
mffap··on OpenAUTH: Universal, standards-based auth provider
It's probably going to be vendor-specific or you will implement your own auth. At ZITADEL we decided to offer all the standards like OIDC and SAML, and offer a session API for more flexible auth scenarios. You will also be able to mix.
mffap··on [dead]
Hi HN, we're thrilled to announce that Zitadel just raised $9M in Series A funding! This will help us make Zitadel, our open source identity platform, even better for developers to build secure applications.

Zitadel simplifies user management, authentication, and authorization with built-in multi-tenancy, making it easy to manage users across different customers, departments, or organizations. This way, you can focus on what matters most: creating amazing products. We're also working on exciting new features like user activity monitoring, which will allow you to easily audit user behavior, build custom reports, and enhance security with tools to detect and react to threats.

We believe everyone deserves access to simple and secure identity solutions. Check out Zitadel and let us know what you think!

mffap··on OpenID Connect specifications published as ISO standards
https://github.com/zitadel/zitadel
mffap··on Launch HN: Fortress (YC S24) – Database platform for multi-tenant SaaS
If you prefer an open source, and maybe more mature, alternative for multi tenant/b2b auth then have a look at https://zitadel.com (disclosure: work for zitadel)
mffap··on Ask HN: Who wants to be hired? (August 2024)
Hey Adil. We're looking for a Go backend engineer and experience with cloud native architectures. Happy to connect. You can find the job here: https://zitadel.com/jobs
mffap··on Ask HN: How would you implement auth for a self hosted product?
Depends on what you need. If you look for SSO or a turnkey solution for auth, then maybe have a look at https://github.com/zitadel/zitadel

Check out the community chat, there are many people having implemented auth for self hosted setups that can share some insights.

mffap··on Ask HN: Which Authentication provider to use?
ZITADEL would be a good choice if you have multiple tenants and want delegate things like access management and configuring auth per tenant in self-service - that part comes out of the box with ZITADEL and could save you quite some development. I wanted to throw that in, because for the authentication part most solutions would match your requirements, but keep also authorization and auditability in mind.

That being said with ZITADEL you can also move between self-hosted and cloud: https://zitadel.com/docs/guides/migrate/sources/zitadel

ps: I'm biased (see bio).

mffap··on Auth0 OSS alternative Ory Kratos now with passwordless and SMS support
Yes that's correct. Get a quote for your use case, if you are already running on higher numbers. Pricing might not fit all cases, that's why there's also an Enterprise tier.
mffap··on Auth0 OSS alternative Ory Kratos now with passwordless and SMS support
All of these features are included. Main drivers for pricing in this case, I assume will be daily active users (sum over the month) and how many third-party identity providers you have configured. Unlimited tenants, users, permissions etc. are included. We use DAU instead of MAU, since there are many different use cases and that seems work quite well. Just take the MAU and multiply by how many times per month your users will sign-in. In the enterprise tier we offer more custom quotes for higher volumes, guarantee requirements, and support SLAs.
mffap··on Auth0 OSS alternative Ory Kratos now with passwordless and SMS support
Have a look at ZITADEL (https://github.com/zitadel/zitadel or https://zitadel.com/), I think that does what you want. You can create multiple tenants (called Organizations) and you can setup security / login rules per organization such as enforcing MFA. Furthermore you can configure on each tenant a separate SSO and users are directly forwarded to their identity provider. When you first enter your username (could be an email) on the login screen, the policies of the user's organization will be applied. That allows you to route users based on their email domain etc. One additional thing to mention is that ZITADEL does not only handle authentication, but also authorization with self-service. Managers of an organization can, for example, assign users of their organization roles.
mffap··on Keycloak SSO with Docker Compose and Nginx
Nice to hear. Glad you like it. What was the winning thing for you?
mffap··on Keycloak SSO with Docker Compose and Nginx
That's true it requires its own db. Way forward will be postgres as db, which makes it hopefully easier to deploy alongside other tools.
mffap··on Keycloak SSO with Docker Compose and Nginx
If you look for 2FA with otp, email, sms and also passkeys foe self-hosting, then give zitadel a spin. All features are included in the open source version. Should also work nicely with docker compose + nginx. In case you have issues, join the chat. https://github.com/zitadel/zitadel
mffap··on Password Hashing Package for Go
Between different algos or compared to other tools?
mffap··on Ask HN: Technical Challenges in Building Multi-Tenant SaaS Products
For RBAC, I see two main challenges. You need to make sure that you get all the roles for all client applications for a user to make a decision. That becomes a bit more complex if you go into scenarios where each tenant can also manage their own clients and roles. Secondly, complexity comes from the self-service to assign roles, ie. delegating access management to the tenants. You need to allow certain users to assign the roles to users in their organization, or in general manage their users. That authorization model has to be applied to the whole system, including APIs obviously.

Most solution solve the authentication part, so login with a local user or federated users via identity brokering (eg, OIDC/SAML via EntraID). The main selling point of ZITADEL is that it also solves the authorization, as mentioned above, across multiple tenants as well as the self-service aspect of delegating configuration of security policies and user management to "Managers" in the tenants. You get that out of the box, no development needed. You can read more here: https://zitadel.com/blog/multi-tenancy-with-organizations Also, you can self-host ZITADEL which is not available for all solutions, but is quite a selling point when talking to enterprise customers.

I think the b2b niche was already mentioned in this thread. But I don't think it is underserved, as many vendors jump onto that. Healthcare and Manufacturing are two sectors that are hard to crack with IAM for their special requirements. The tools I've seen are working but very expensive and customized. Yet also the two sectors are very traditional (read: on-prem AD) and need a lot of work if they want to move to more federated IAM systems.

mffap··on Ask HN: Technical Challenges in Building Multi-Tenant SaaS Products
One of the challenges we see is providing self-service for team management. That includes letting an admin assign roles to their users, manage user lifecycle (eg through sso), and setting up security policies. For sure you can build the basics, but it becomes complex later on if you manage a lot of tenants or or more enterprise customers. For Auth only there are many solutions out there that work great. There's only a few solutions with multi-tenancy at the core, though, like https://github.com/zitadel/zitadel
mffap··on Governments turn to Open Source for sovereignty
Thanks for sharing, interesting. But the named components in the article seem not to have received funding.
mffap··on Governments turn to Open Source for sovereignty
Is Germany funding the oss projects as well? Traditionally they have this mindset of free open source software, with a strong emphasis on free, while not factoring in the cost of maintaining a project. When the usage gets higher there should be a plan for sustainable progress and maintenance.
mffap··on Fly.io Postgres cluster down for 3 days, no word from them about it
zitadel supports service users with rbac. maybe give it a look/try: https://github.com/zitadel/zitadel
mffap··on Ask HN: Is GitHub Down?
Same here. Their status page shows all green, though https://www.githubstatus.com/
mffap··on Keycloak with PostgreSQL on Kubernetes
That's basically what it does. You can activate Domain Discovery and verify a Domain on an organization, with that zitadel routes users to the organization based on the suffix (ie. email domain)
mffap··on Keycloak with PostgreSQL on Kubernetes
You can enable Domain Discovery to route users to the correct organization. Or you send a reserved scope with the auth request to select the organization. Building an own Login UI will be available in a couple of weeks (https://github.com/zitadel/zitadel/issues/5015)
mffap··on Show HN: Open Source Authentication and Authorization
The software is open source under Apache 2.0 (https://github.com/zitadel/zitadel). No open core or similar, we run the same version on our Cloud Service and for Enterprises. Thanks for the feedback, we need to make that more obvious then.
mffap··on Show HN: Open Source Authentication and Authorization
Thanks for mentioning ZITADEL. Co-founder here. Supertokens is a good solution with obviously a lot of open source traction, which is great to see in this space. Expanding to authorization makes a lot of sense. ZITADEL supports both authentication and authorization in a turnkey solution (AuthN, AuthZ, APIs, UI, DB). Looking at Supertoken's roadmap, Zitadel seems to be more feature rich offering Passkeys, OTP, multi-tenancy, account linking and a management ui.
mffap··on 'Securing Open Source Software Act' introduced to US Senate
a radical thought: how about hiring some engineers to contribute to oss that's being used in critical infrastructure?

I believe that most of the assessment stuff is covered by many NIST recommendations anyways.

mffap··on Is public WiFi as dangerous as people claim?
Unfortunately, very valid point. Love the example btw :)

Browsers have been getting better at warning users. Which is actually a great help, I think. But no guarantee at all, especially for less tech-savvy users.

mffap··on [dead]
Hey HN

happy to share with you that we've now officially released v2.0 of ZITADEL. Integrate user management and authentication easy as pie.

Check out the TL;DR in the release notes on what's changed.

We also launched on ZITADEL on ProductHunt. Share with us what you like best about the project, what's the one thing you would improve, or what you want to see next!

Happy to answer any questions. Cheers.

mffap··on Show HN: Lldap, a Simplified LDAP Server
You might want to give ZITADEL a spin https://github.com/zitadel/zitadel SAML2.0 is on a PR right now, but ready to be merged very soon. Would be glad to get your feedback. (discl. I work for ZITADEL)
mffap··on Show HN: Logto beta – build universal sign-in, auth, and identity with ease
In case you're looking for multi-tenancy with self-service, maybe try out https://github.com/zitadel/zitadel Would be glad to get your thoughts on the platform. (discl: I work for ZITADEL.
mffap··on Are Magic Links Outdated?
Yes. To my knowledge WebAuthN works great on Chrome, Safari, Firefox (most times) on MacOS/iOS and Windows devices. Linux is still an issue unfortunately as it seems.
Page 1 of 2Next →