frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Decentralized Auth for Information Exchange?

2•vxsz•10h ago
I have a media server project that I want to work on. But I'm stuck on one thing, convenience vs privacy.

As the project is about spinning your own server (media server), I want to have a smoother way to have a simple account system where the user just enters an email and a password, and get the server/ip list (everything from there is done on the actual server). For example, a user could be invited to 2 servers, and would see them in the same page, which makes things more straight-forward and a lot easier.

Now, I thought a lot about it, and mostly came down to the conclusion that centralizing it is the most sane option. The data itself comes down to: email, encrypted password, encrypted IP(s) list (via key exchanges).Is there any-way to do it decentralized? I searched, even asked LLMs, but nothing felt solid (best was a Nostr suggestion) but such method would make emails, password resets painful or almost impossible. I don't know a lot regarding this topic so its quite the challenge.

What's the point/why not just use URL? convenience. I know, but it SUCKS having to give a parent a URL, even with some techy friends it takes a bit communicating it. I want to eliminate as much friction as possible. Also, if centralized, this has the ability that users don't need to buy a domain, setup lets encrypt and all that which costs money and time (especially for simple/new selfhosters); its a lot nicer and smoother and in a way provide better privacy out-of-the-box.

Note, This project doesn't even exist yet. But I'm pursuing quite soon. I also only took 1 encryption course back in college days, while I understood and was good at it, I still need to audit/verify my method. It basically is: 1. hash the password+salt in a different algorithm, save the private key from it and send the public key to the central server 2. (media server owner wants to invite) the media server checks for a public key, encrypts the message containing all the details (IP, status, ports etc), and sends the encrypted message to the central server. 3. The client later checks, if there's a new message, it decrypts the ip/info from the server and connect.

Every device can login in this way and grab server list info securely. There's gonna be some sort of way to "quick connect" on TVs and such, and change passwords, but I don't want to get ahead of myself for now. I don't think the IP/server-info encryption suffers from any major things, but that's the general core principle. I maybe (probably?) have missed something.

The only issues I can maybe think of, is a "centralized" URL/domain would be showing up all the time instead of the owner. Note, it would be designed in a way that would allow you to instead send them to your own URL/domain and such.

Anyways, let me know what would be best. btw I'm not rich but such simple "auth" server would probably cost like $5/m + 2x5/m for redundancies, shouldn't be too bad.

Comments

ZuoCen_Liu•10h ago
As an entrepreneur, this feels like a classic case of over-engineering for a problem you haven't earned yet.

Decentralized auth is a fascinating technical rabbit hole, but it introduces a massive friction point for your first 1,000 users. For a new, unproven project, credibility is your biggest bottleneck, not decentralized storage.

By building your own complex auth/privacy stack, you are asking users to trust you to get the crypto right—which is a huge leap of faith.

A more pragmatic approach: Outsource the trust. > Use 'Sign in with Google/Apple/GitHub.' You leverage their multi-billion dollar security infrastructure and their existing trust relationship with the user. It provides immediate convenience (one-click onboarding) and shifts the perceived privacy liability to a known entity.

Don't spend your innovation tokens on auth. Spend them on the core value of your information exchange. You can always 'decentralize' the back-end later once you have enough users to actually make it matter.

vxsz•10h ago
Yeah I think decentralization will be a stretch, especially at the beginning.

About the login, SSO is nice and it will probably be an option, but I heavily prefer good old email+password. It might be trickier, haven't explored SSO before.

The auth/central server will be open source of course, and I'm hoping I could get feedback/auditing that way if anything's wrong (even tho I feel like the process is simple with encryption libs and knowledge). At first it will be heavily experimental and will hold just dummy data and then gradually go from there if it works out.

Ask HN: Those making $500/month on side projects in 2025 – Show and tell

388•cvbox•18h ago•432 comments

Tell HN: HN was down

590•uyzstvqs•1d ago•320 comments

Ask HN: Who here is not working on web apps/server code?

9•ex-aws-dude•1h ago•6 comments

Ask HN: Does anyone understand how Hacker News works?

143•jannesblobel•20h ago•192 comments

Is analytics a necessary evil rather than a real value driver?

5•tiazm•2h ago•4 comments

Ask HN: How to fight back against Lovable, Replit, etc. in enterprise products

3•bears123•3h ago•1 comments

Ask HN: What Are You Working On? (December 2025)

437•david927•4d ago•1432 comments

Ask HN: Should I Open Source Every Product I Build as an Indie Developer?

6•tomfox2•4h ago•10 comments

Ask HN: If you had to get a non-tech masters degree, what would you go for?

2•highwayman47•4h ago•6 comments

Tell HN: AI coding is sexy, but accounting is the real low-hanging target

62•bmadduma•6d ago•55 comments

Ask HN: Why do official-looking emails cause anxiety before I read them?

4•BianDan•7h ago•4 comments

Ask HN: Is RSS Still Alive?

7•militanz•12h ago•10 comments

Ask HN: Decentralized Auth for Information Exchange?

2•vxsz•10h ago•2 comments

Ask HN: Etiquette giving feedback on mostly AI-generated PRs from co-workers

4•chfritz•16h ago•4 comments

Ask HN: Should I start a software foundation (goal: help emergency services)?

9•strgcmc•20h ago•0 comments

Ask HN: Is starting a personal blog still worth it in the age of AI?

62•nazarh•3d ago•75 comments

FWS – pip-installable embedded process supervisor with PTY/pipe/dtach back ends

2•mrsurge•13h ago•0 comments

Ask HN: Is building a calm, non-gamified learning app a mistake?

86•hussein-khalil•3d ago•122 comments

Computer animator and Amiga fanatic Dick van Dyke turns 100

280•ggm•5d ago•93 comments

Ask HN: What are your predictions for 2026?

24•mfrw•1d ago•21 comments

Ask HN: How can I get better at using AI for programming?

466•lemonlime227•5d ago•466 comments

Memory Safety in C# vs. Rust

14•northlondoner•2d ago•12 comments

Ask HN: How are you vibe coding in an established code base?

10•adam_gyroscope•2d ago•7 comments

Ask HN: Was HN just down for anyone else?

84•rozenmd•1d ago•2 comments

Ask HN: Claude Opus 4.5 vs. GPT 5.1 Codex Max for coding. Worth the upgrade?

5•terabytest•2d ago•6 comments

Ask HN: Bloggers, how do you manage your content?

11•freemanjiang•3d ago•14 comments

Who has enjoyed using PR code reviewers? What worked and what didn’t?

3•yashwantphogat•1d ago•4 comments

Ask HN: Did anyone else notice that the OpenAI Labs website was completely gone?

27•underlipton•6d ago•9 comments

Ask HN: Thought-Provoking Books

21•Agraillo•5d ago•18 comments

Ask HN: Best back end to run models on Google TPU?

8•vood•3d ago•0 comments