- https://oauth.net/articles/authentication/
- https://tools.ietf.org/html/rfc6749 - The OAuth 2.0 Authorization Framework
206 karma · joined December 27, 2018
- https://oauth.net/articles/authentication/
- https://tools.ietf.org/html/rfc6749 - The OAuth 2.0 Authorization Framework
If you want a list of things that can go wrong, look here: https://tools.ietf.org/id/draft-ietf-oauth-security-topics-1...
Generally you probably do not need OAuth2: https://www.ory.sh/hydra/docs/concepts/before-oauth2/
But if you do don’t roll your own but use proven open source like https://github.com/ory/hydra
It is about time for a new generation of identity systems in my opinion. This acquisition shows the risk of centralized, vendor locked-in services.
We build stuff for an emerging cloud infrastructure. It's security, zero trust, hardcore bullet proof engineering. It's Golang, K8S, React, Hashicorp etc. - no more buzzwords! We are looking for people with a broad set of technical skills who are ready to take on some of technology's challenges and work with others to create modern world class solutions. We like React, Go and Kubernetes (among other things) and love learning how to push the boundaries with those technologies! Drop us a short introductory email to jobs@ory.sh. We believe that great engineering deserves to be paid accordingly.
https://github.com/ory https://github.com/ory/jobs https://www.ory.sh
My tip is to read a (or more) actual (read: printed) newspapers:
- they are printed daily or weekly (e.g. The Economist), keeping you out of the "Breaking News" loop every 60 minutes; - they have more weight within the news organization because they are the primary driver of revenue; - are therefore written by actual professional journalists in a proper journalistic process.
I recommend just picking up any news paper and comparing that to the online presence of that news paper, you will notice the tremendous difference.
In my opinion, a lot of the "media mistrust" comes from the constant barrage of so-called "news" articles with the primary goal of being shared on social media and bubbling up in Google News. Just check how many news articles are 1:1 copies of AP or any other news conglomerate.
However, OIDC and OAuth2 are complex protocols which is also why we encourage most greenfield and small projects to avoid it unless explicitly required.
It’s also important to note that that particular person voiced criticism, but most of the biggest names in tech (GCP, AWS, ...) heavily rely on those protocols (+ extensions). His proposed alternative protocol Oz never got to real world adoption (to my knowledge) and has recently been archived. The prediction that we would see major OAuth2 security wholes within 3 years (so 2015j never came true. It doesn’t mean that he was wrong, but that there are opinions that contradict him, and that those opinions and voices have established themselves in the industry.
Also, you have complete control over the ui and user experience and must not learn a template language (Keycloak) or fork (Dex) the project to customize it.
Compared to Keycloak, Hydra is much more lightweight (no JVM/JBoss). However, you need to implement the user database yourself and/or write your own connector for it.
Most advice in the comments is pretty bad though. Stuff like "API Clients need bearer tokens" is completely backwards and pushed by marketing people from companies (Auth0, Okta, ...) that misuse open protocols (OAuth2, OIDC) as a way to legitimize the closed source saas approach they took. Along the lines "if it looks complex it looks secure because most people have no idea". It's actually very easy to use cookies (httpOnly, secure) with API clients and you're saving yourself so much complexity with refreshing tokens and all that stuff.
Yet another possibility for super rapid prototyping is: https://github.com/bitly/oauth2_proxy
edit:// I forgot KeyCloak, but it's also for advanced enterprise use cases (SAML, OIDC, Realms, ...) and (from what I've heard) with a steep learning curve and heavy.