frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Better Auth, by a self-taught Ethiopian dev, raises $5M from Peak XV, YC

https://techcrunch.com/2025/06/25/this-self-taught-ethiopian-dev-built-an-authentication-tool-and-got-into-yc/
31•bundie•5h ago

Comments

dang•1h ago
Related:

Launch HN: Better Auth (YC X25) – Authentication Framework for TypeScript - https://news.ycombinator.com/item?id=44030492 - May 2025 (106 comments)

Better Auth – Authentication library for TypeScript - https://news.ycombinator.com/item?id=42272707 - Nov 2024 (32 comments)

Show HN: Comprehensive authentication library for TypeScript - https://news.ycombinator.com/item?id=41678652 - Sept 2024 (44 comments)

blackhaj7•1h ago
So pumped for Bereket. Better Auth is awesome.

I am also interested on how they plan to monetise it. I love the library and the success story but hope that the weight of this VC money doesn’t impact its awesomeness

yewenjie•1h ago
Can anyone compare Better Auth with something more barebones like Lucia?
threatofrain•58m ago
Lucia has been converted into a kind of tutorial, which is another way of saying the author is going to college now and is busy or interested in other things.

As an aside OpenAuth seems dead. No activity for 2 months.

haneul•1h ago
Love this news! Amazing by Bereket!
abetancort•1h ago
Trump will kick him out of the US.
reactordev•52m ago
He just raised enough for a golden ticket
yodon•1h ago
Pretty sure auth is not something I want a self-taught dev (or even most CS-graduate devs) writing.

Oauth2, JWT's, hashes, timestamps, validations, and such, are all totally simple until they're not. The black hats have way more experience and way more time invested in this space than most any normal dev.

vmg12•55m ago
Auth is really not difficult to write. It's don't roll your own crypto, not don't roll your own auth. People need to stop spreading this fud.
risyachka•49m ago
Yeah it’s not difficult if you know all the specs.

The issue is 99% don’t know them and are not very good at following them. And the cost of error is very high.

I’ve seen a lot of startups that failed to implement even google oauth securely.

So yeah it’s a far cry from fud and you really should not do it unless you are actually good.

threatofrain•44m ago
But given that BetterAuth is an open source project with a large following, and also given that they just got funding so they can hire more help, now we can evaluate BetterAuth's competency in terms of their ability to coordinate help.
hobofan•45m ago
What? No!

There are plethora of mistakes one can make in implementing AuthN/AuthZ, and many of them almost immediately will lead to either the direct leak of PII or can form the start of a chain of exploits.

Storing password hashes in an inappropriate manner -> BOOM, all your user's passwords are reversible and can be used on other websites

Not validating a nonce correctly -> BOOM, your user's auth tokens can be re-used/hijacked

Not validating a session timestamps correctly -> BOOM, your outdated tokens can be used to gain the users PII

vmg12•42m ago
None of those things are difficult to do correctly.
hobofan•35m ago
Yeah, one would think so. Evidence in the wild shows otherwise.
programmarchy•6m ago
With 5M you can get white hat audits. Even big boys like Okta have had serious fuckups [1].

[1] https://trust.okta.com/security-advisories/okta-ad-ldap-dele...

sunrunner•47m ago
I learnt to program (in a very basic way) before doing the whole paper qualification thing. Am I self taught? Is that some kind of signifying badge one loses once one gets a 'proper' education? I also know many people _with_ the paper qualification I wouldn't necessarily trust

Rhetorical questions of course as we all know it's a clickbait title, but perhaps it would be nice for this label to stop being thrown around like it has any real consistent meaning or significance?

pinkmuffinere•36m ago
> The black hats have way more experience and way more time invested in this space than most any normal dev.

Surely the black hats you refer to are themselves self-taught? They didn't find a school that would teach them about crime, right? In that case it seems like self-taught can be good enough.

exiguus•42m ago
If i get it correctly, it solves the problem, to store data on MVP/Prototype Auth providers like Superbase, Auth0 or Firebase.

How does it compare to something mature like keycloak?

And what is the difference to just self-host superbase?

sebmellen•33m ago
Curious how this compares to something like Ory Kratos? And what would the projected revenue stream be?
alephnerd•7m ago
Glad to hear Peak XV getting it's moment on a competitor's forum. Jokes aside, congrats Bereket.

Creative Commons Signals: A New Social Contract for the Age of AI

https://creativecommons.org/2025/06/25/introducing-cc-signals-a-new-social-contract-for-the-age-of-ai/
1•dannyobrien•2m ago•0 comments

The pitfall of Open-weight LLMs

1•hiddenest•5m ago•0 comments

Swift Android Workgroup

https://www.swift.org/android-workgroup/
2•gok•7m ago•0 comments

Puerto Rico's Solar Microgrids Beat Blackout

https://spectrum.ieee.org/puerto-rico-solar-microgrids
1•ohjeez•8m ago•0 comments

Multi-Agent Systems Hands on in Python: Full 4-HR Workshop Feat. MCP and CrewAI

https://www.youtube.com/watch?v=LSk5KaEGVk4
1•jonkrohn•9m ago•0 comments

I made a history timeline to learn what events happened around the same time

https://seanhollen.com/1300-2000/
1•Akranazon•12m ago•0 comments

Fannie Mae Freddie Mac ordered to consider crypto an asset when buying mortgages

https://apnews.com/article/mortgages-crypto-fannie-mae-freddie-mac-housing-285fad5490a59c3476f7908f444e9fe9
1•healsdata•12m ago•0 comments

ENTS – Extendable Nested Tagging Schema

https://diegocabello.com/ents/
1•dxcab•13m ago•0 comments

ICE Has No Right to Anonymity

https://www.nytimes.com/2025/06/25/opinion/trump-ice-arrests-los-angeles.html
3•whack•16m ago•0 comments

Docs for AI Agents

https://technicalwriting.dev/ai/agents/
1•kaycebasques•18m ago•0 comments

OpenRouter Raises $40M

https://www.wsj.com/articles/openrouter-a-marketplace-for-ai-models-raises-40-million-168073de
1•ent101•18m ago•0 comments

Meta wins artificial intelligence copyright case in blow to authors

https://www.ft.com/content/6f28e62a-d97d-49a6-ac3b-6b14d532876d
2•sega_sai•18m ago•1 comments

AI market analysis tool, Limited spots for testers

https://aique.markets
1•ensgoat•19m ago•1 comments

Trump Considers Naming Next Fed Chair Early in Bid to Undermine Powell

https://www.wsj.com/economy/central-banking/trump-considers-naming-next-fed-chair-early-in-bid-to-undermine-powell-d3edcb9c
1•cempaka•19m ago•0 comments

The Waste Musk Created

https://www.nytimes.com/2025/06/21/opinion/waste-musk-trump.html
1•archagon•19m ago•1 comments

The Android Workgroup

https://forums.swift.org/t/announcing-the-android-workgroup/80666
1•MBCook•21m ago•0 comments

QEMU: Define policy forbidding use of AI code generators

https://github.com/qemu/qemu/commit/3d40db0efc22520fa6c399cf73960dced423b048
26•todsacerdoti•22m ago•8 comments

PEM Fatigue Can Shatter a Person

https://www.theatlantic.com/health/archive/2023/07/chronic-fatigue-long-covid-symptoms/674834/
2•mitchbob•25m ago•2 comments

Spineless Traversal for Layout Invalidation

https://dl.acm.org/doi/10.1145/3729322
1•djoldman•28m ago•0 comments

Learn – Computer-Aided Instruction on Unix

https://wolfram.schneider.org/bsd/7thEdManVol2/learn/learn.html
2•foresto•29m ago•0 comments

Anomalous radio signals detected in Antarctica coming upward from Earth

https://www.popularmechanics.com/science/environment/a65089793/mysterious-signals-antarctica-physics/
1•Jimmc414•30m ago•0 comments

The scam that is Visa Account Updater

6•mountainriver•32m ago•2 comments

Project Indigo, a Google Pixel-like computational photography camera app

https://research.adobe.com/articles/indigo/indigo.html
1•phsilva•33m ago•1 comments

The Tail at Scale

https://cacm.acm.org/research/the-tail-at-scale/
2•ekiauhce•34m ago•0 comments

Fred Espenak, Astrophysicist Known as Mr. Eclipse, Dies at 73

https://www.nytimes.com/2025/06/25/science/space/fred-espenak-dead.html
2•sohkamyung•34m ago•1 comments

Show HN: Anagnorisis, local data-management with trainable recommendation engine

https://github.com/volotat/Anagnorisis
1•volotat•42m ago•0 comments

Ultimadownloader

https://www.ultimadownloader.xyz
1•robertprogram•43m ago•0 comments

The Hollow Men of Hims

https://www.alexkesin.com/p/the-hollow-men-of-hims
10•quadrin•50m ago•0 comments

A Clean Break: A New Strategy for Securing the Realm

https://en.wikipedia.org/wiki/A_Clean_Break:_A_New_Strategy_for_Securing_the_Realm
1•handfuloflight•51m ago•0 comments

Roblox's back end scales to 30M concurrent players and over 21M for a experience

https://corp.roblox.com/newsroom/2025/06/roblox-infrastructure-supporting-record-breaking-games
2•ak009•51m ago•2 comments