frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Authentication Explained: When to Use Basic, Bearer, OAuth2, JWT and SSO

https://javarevisited.substack.com/p/system-design-basics-authentication
8•rezaprima•1d ago

Comments

m-hodges•1d ago
> It’s simple, but insecure unless wrapped in HTTPS. That’s why it’s almost never used in production anymore.

I mean, if you’re going to write a post about auth methods, you gotta say more than this.

zzo38computer•1d ago
There is another kind, which is X.509 client certificates, which is more secure and more versatile than other kinds. However, it does mean that if you want to login from more than one computer, you need the certificate and private key on all of them (but this can be an advantage as well as being a disadvantage). It is capable of handling authorization as well as authentication, if you add extensions for this use. The private key may be passworded, which can provide additional security; storing one certificate on a computer not connected to the internet and then issuing another certificate to yourself which will be the one you will actually use, can also provide additional security; in both cases, the service provider does not need to worry about these things and the client can do how they intend to do.

Another method which may be suitable for some uses (although the working of web browsers means that it will not work securely in a web browser, unless you have an extension, but it can work easily in other programs) is HMAC, although this is not suitable for all uses. For idempotent write operations which are not intended to be secret, it might work.

Beyond the Bus Factor: Managing Tribal Knowledge

https://brihatijain.com/blog/beyond_the_bus_factor
1•brihati•1m ago•1 comments

China launches satellite 'super factory' in bid to rival Elon Musk's Starlink

https://www.scmp.com/economy/china-economy/article/3335926/china-launches-satellite-super-factory...
1•gscott•1m ago•0 comments

Computer Use 2025 Wrapped

https://www.onkernel.com/blog/computer-use-2025
1•masnwilliams•2m ago•0 comments

Chord: Open-Source Prototype for PBR Material Estimation Debuting at Siggraph

https://www.ubisoft.com/en-us/studio/laforge/news/1i3YOvQX2iArLlScBPqBZs/generative-base-material...
1•klaussilveira•4m ago•0 comments

Military's new AI: 'Hypothetical' boat strike scenario 'unambiguously illegal'

https://san.com/cc/the-militarys-new-ai-says-hypothetical-boat-strike-scenario-unambiguously-ille...
1•doener•5m ago•0 comments

LZ dark matter experiment spots neutrinos from the sun's core

https://www.llnl.gov/article/53711/lz-dark-matter-experiment-sets-worlds-best-spots-neutrinos-sun...
1•gmays•5m ago•0 comments

Meta's Pivot from Open Source to Money-Making AI Model

https://www.bloomberg.com/news/articles/2025-12-10/inside-meta-s-pivot-from-open-source-to-money-...
2•peterbonney•6m ago•0 comments

EU-US Data Transfers: Time to prepare for more trouble to come

https://noyb.eu/en/eu-us-data-transfers-time-prepare-more-trouble-come
4•tomwas54•6m ago•0 comments

Heuristics vs. RAG: Shrinkflation as a Policy Driver

https://www.unite.ai/heuristics-vs-rag-shrinkflation-as-a-policy-driver/
1•50kIters•7m ago•0 comments

Ask HN: Is there a "good" (non-privacy horror) aftermarket HUD for your car?

1•xrd•7m ago•0 comments

German unions call for French Dassault's expulsion from EU fighter jet program

https://www.reuters.com/business/aerospace-defense/powerful-german-union-calls-dassaults-expulsio...
2•alephnerd•8m ago•0 comments

Show HN: Wirebrowser – A JavaScript Debugger with Breakpoint-Driven Heap Search

https://github.com/fcavallarin/wirebrowser
2•fcavallarin•8m ago•0 comments

Explaining weird stuff via Python's compilation pipeline – UMich guest lecture [video]

https://www.youtube.com/watch?v=G2yPbg2fgQY
1•vismit2000•9m ago•0 comments

Why Tagged PDF Matters for AI

https://opendataloader.org/docs/tagged-pdf
1•Julia_Katash•10m ago•1 comments

Decide What's Human

https://kupajo.com/decide-whats-human/
1•kolyder•11m ago•0 comments

Preventing Resource Leaks in Go: How GoLand Helps You Write Safer Code

https://blog.jetbrains.com/go/2025/12/09/preventing-resource-leaks-in-go-how-goland-helps-you-wri...
1•Annprots•12m ago•1 comments

Pedantle

https://pedantle.certitudes.org/
1•knuckleheads•12m ago•0 comments

Storing OAuth Tokens

https://fusionauth.io/articles/oauth/oauth-token-storage
1•mooreds•13m ago•0 comments

Pompeii Time Capsule Reveals Secrets to Durable Ancient Roman Cement

https://www.scientificamerican.com/article/pompeii-house-frozen-mid-renovation-reveals-secrets-of...
2•Brajeshwar•13m ago•0 comments

Starlink Became the Internet Alternative

https://restofworld.org/2025/starlink-musk-internet-expansion/
2•Brajeshwar•14m ago•0 comments

James Webb Telescope detects 13B-year-old supernova with gamma-ray burst

https://www.space.com/astronomy/james-webb-space-telescope/the-james-webb-space-telescope-just-fo...
1•Brajeshwar•14m ago•0 comments

Calif. tech saddest invention has been bleeding cash

https://www.sfgate.com/food/article/california-tech-world-soylent-scrambling-adapt-21219237.php
1•deegles•14m ago•1 comments

201 Stories by Anton Chekhov

https://web.archive.org/web/20070630223838/http://chekhov2.tripod.com/
1•bookofjoe•14m ago•0 comments

Legacy Code, Live Risk: Empirical Evidence of Malware Detection Gaps

https://www.mdpi.com/2076-3417/15/22/11862
1•PaulHoule•14m ago•0 comments

39C3 Fahrplan 2025

https://fahrplan.events.ccc.de/congress/2025/fahrplan/
2•birdculture•14m ago•0 comments

Show HN: Stridewars – A team step competition with Mario Kart-style power-ups

https://www.stridewars.com
1•nugzbunny•14m ago•0 comments

Relational AI vs. Constitutional AI: Are we focusing on the right question?

1•buttersmoothAI•17m ago•0 comments

Former GitLab CEO raises money for Kilo to compete in crowded AI coding market

https://www.cnbc.com/2025/12/10/former-gitlab-ceo-raises-8-million-for-kilo-to-compete-in-vibe-co...
1•lngzl•18m ago•0 comments

How to Write Your LinkedIn

https://taylordesseyn.substack.com/p/how-to-write-your-linkedin
1•mooreds•18m ago•0 comments

Retraction of key roundup study from 2000 in Regul. Toxicol. Pharm

https://www.sciencedirect.com/science/article/pii/S0273230025002387
1•kla-s•19m ago•0 comments