frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Identity Assertion Authorization Grant

https://www.ietf.org/archive/id/draft-parecki-oauth-identity-assertion-authz-grant-03.html
12•mooreds•4d ago

Comments

bastawhiz•3h ago
Can someone provide an example of a practical use for this? It doesn't sound like a bad idea, I'm just struggling to imagine where it might be used.
junon•3h ago
In big systems it's often the case, for better or worse, that two systems don't share a connection to a central auth server.

This spec appears to outline how a user logged into one is automatically logged into another using cryptographically signed tokens.

zzo38computer•3h ago
Is that necessary?

For one thing, just because you are logged into one does not mean that you intend to be logged into other one also.

For another thing, it can be done by X.509; if there is a certificate that both systems allow for authentication, then the ones that are issued by that certificate can also be used by the other system, too.

A third thing is that partial delegation of authorization is also possible by X.509, and this can also be used to act on the user's behalf (which seems to also be mentioned in the article). The way that this would work is as follows:

1. The client uses a certificate previously issued to them to issue a certificate to the server (containing the server's public key, which the client already knows because the server also has a X.509 certificate). This certificate will contain an extension to specify the authorization.

2. The server then acts as a client, using the issued certificate for authentication, to another server.

3. The another server verifies the certificate chain, and grants the authorization according to the interaction of the authorizations permitted by each certificate in the chain (i.e. the operation must be authorized by each certificate in the chain in order to be authorized by the chain).

(Doing something like the fine-grained personal access tokens of GitHub would be similar except that the client issues a certificate to themself instead of to another server. You can also issue a certificate to yourself without limiting the permissions, e.g. in case you want to store the private key of the first certificate on a separate computer that is not connected to the internet, to be less likely to be compromised.)

ZX Spectrum graphics magic

https://zxonline.net/zx-spectrum-graphics-magic-the-basics-every-spectrum-fan-should-know/
40•ibobev•1d ago•2 comments

Generative AI coding tools and agents do not work for me

https://blog.miguelgrinberg.com/post/why-generative-ai-coding-tools-and-agents-do-not-work-for-me
137•nomdep•3h ago•117 comments

What happens when clergy take psilocybin

https://nautil.us/clergy-blown-away-by-psilocybin-1217112/
89•bookofjoe•6h ago•98 comments

Show HN: Chawan TUI web browser

https://chawan.net/news/chawan-0-2-0.html
190•shiomiru•7h ago•25 comments

Show HN: Canine – A Heroku alternative built on Kubernetes

https://github.com/czhu12/canine
181•czhu12•10h ago•82 comments

Benzene at 200

https://www.chemistryworld.com/opinion/benzene-at-200/4021504.article
189•Brajeshwar•13h ago•95 comments

WhatsApp introduces ads in its app

https://www.nytimes.com/2025/06/16/technology/whatsapp-ads.html
278•greenburger•14h ago•368 comments

Selfish reasons for building accessible UIs

https://nolanlawson.com/2025/06/16/selfish-reasons-for-building-accessible-uis/
18•feross•3h ago•6 comments

Snorting the AGI with Claude Code

https://kadekillary.work/blog/#2025-06-16-snorting-the-agi-with-claude-code
234•beigebrucewayne•17h ago•146 comments

Battle to eradicate invasive pythons in Florida achieves milestone

https://phys.org/news/2025-06-eradicate-invasive-pythons-florida-stunning.html
32•wglb•6h ago•27 comments

Show HN: Nexus.js - Fabric.js for 3D

https://punk.cam/lab/nexus
52•ges•7h ago•18 comments

The Humble Programmer (1972)

https://www.cs.utexas.edu/~EWD/transcriptions/EWD03xx/EWD340.html
9•squircle•3h ago•0 comments

How Frogger 2’s source code was recovered from a destroyed tape [video]

https://www.youtube.com/watch?v=lvEO4IaEJlw
29•perching_aix•1d ago•1 comments

Dull Men’s Club

https://www.theguardian.com/society/2025/jun/09/meet-the-members-of-the-dull-mens-club-some-of-them-would-bore-the-ears-off-you
91•herbertl•10h ago•54 comments

OpenAI wins $200M U.S. defense contract

https://www.cnbc.com/2025/06/16/openai-wins-200-million-us-defense-contract.html
117•erikrit•5h ago•61 comments

Show HN: Zeekstd – Rust Implementation of the ZSTD Seekable Format

https://github.com/rorosen/zeekstd
183•rorosen•1d ago•40 comments

Iron nitride permanent magnets made with DIY ball mill [video]

https://www.youtube.com/watch?v=M6XIgdS1rzs
13•xqcgrek2•1d ago•0 comments

OpenTelemetry for Go: Measuring overhead costs

https://coroot.com/blog/opentelemetry-for-go-measuring-the-overhead/
104•openWrangler•13h ago•36 comments

What I talk about when I talk about IRs

https://bernsteinbear.com/blog/irs/
15•surprisetalk•3d ago•19 comments

Blaze (YC S24) Is Hiring

https://www.ycombinator.com/companies/blaze-2/jobs/dzNmNuw-junior-software-engineer
1•faiyamrahman•7h ago

Privacy implications of browsers’ (mis)implementations of Widevine EME (2023)

https://hal.science/hal-04179324v1/document
89•exceptione•6h ago•52 comments

Nanonets-OCR-s – OCR model that transforms documents into structured markdown

https://huggingface.co/nanonets/Nanonets-OCR-s
293•PixelPanda•22h ago•67 comments

Retrobootstrapping Rust for some reason

https://graydon2.dreamwidth.org/317484.html
108•romac•8h ago•38 comments

Working on databases from prison

https://turso.tech/blog/working-on-databases-from-prison
726•dvektor•15h ago•471 comments

Open-Source RISC-V: Energy Efficiency of Superscalar, Out-of-Order Execution

https://arxiv.org/abs/2505.24363
70•PaulHoule•11h ago•19 comments

William Langewiesche, the 'Steve McQueen of Journalism,' Dies at 70

https://www.nytimes.com/2025/06/16/business/media/william-langewiesche-dead.html
6•rsingel•41m ago•1 comments

Breaking Quadratic Barriers: A Non-Attention LLM for Ultra-Long Context Horizons

https://arxiv.org/abs/2506.01963
46•PaulHoule•9h ago•19 comments

Is gravity just entropy rising? Long-shot idea gets another look

https://www.quantamagazine.org/is-gravity-just-entropy-rising-long-shot-idea-gets-another-look-20250613/
272•pseudolus•1d ago•236 comments

Finland warms up the world's largest sand battery, the economics look appealing

https://techcrunch.com/2025/06/16/finland-warms-up-the-worlds-largest-sand-battery-and-the-economics-look-appealing/
51•pseudolus•2h ago•7 comments

Show HN: dk – A script runner and cross-compiler, written in OCaml

https://diskuv.com/dk/help/latest/
58•beckford•13h ago•8 comments