Hacker Newsnew | past | comments | ask | show | jobs | submit | authnopuz's commentslogin

One of the Co-Authors here

There are two elements here. Agent can start a full authorization request with AS through authorization code grant flow, even requiring a step-up or some rich authorization details, therefore whatever OTP by SMS or Magic link is an AS - Subject/Client "problem".

For Agent that cannot start a full authorization request (too costly, to complex, subject directly unreachable at the moment), we have a mention to OpenID Connect CIBA into it. With it, the Agent will start a back channel authorization request with the AS and the AS will use a method of authentication / confirmation with the subject in front channel, for example sending a SMS or sending a link to click. Again the resolution will remain an AS - Subject/Client "problem".


Nightfall by Asimov was a 7 bodies problem - https://en.wikipedia.org/wiki/Nightfall_(Asimov_novelette_an...


And to be fair, Liu Cixin's book is a 4 bodies problem :)


This made me irrationally annoyed, lol. But that was only the start (I've only seen the TV show though)


Seriously there was so much wrong with that book.


There was a lot right with it as well IMHO. It was very original (I've only read the first book so far).


To each their own, I suppose.


hug of death? I fear the temperature will get very high in his laundry room


I'm sure it depends on how much laundry he is doing - his dryer is probably heated entirely by servers.

He can then exhaust the remaining server heat through the dryer vent stack.


Keep going. I love dry humor.


Its dryer sheets soften the soul.


Untill the exhaust starts "Feeling leaky" I guess.


Might not even need a dryer :-)


Change it to a sauna?


I thought of this a whole ago when I was a Datacentre monkey. In the winter it was pleasant to walk down the hot aisles.

However the exhausted hot air never had the same feel of a sauna. It left the air stale and dry.



The authentication section is very bizarre, the Agent should go through an OAuth(2?) process to finally access server through an API Key? That sounds more painful than bringing a better state of security...


Man, we all have been bluffed by this scene


Another good source of NHI definitions, concepts, and threats https://nhimg.org/the-ultimate-guide-to-non-human-identities


If you consider the newest rfc9068: https://datatracker.ietf.org/doc/html/rfc9068 for JWT profiled Access Token, the list of discrepancies is even longer.


Hear. This one! So many of customers have been stabbed in the back with this one


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: