HN user

gneray

196 karma
Posts24
Comments93
View on HN
twitter.com 1mo ago

SpaceX agrees to merge with Cursor in a $60B deal, confirmed

gneray
5pts2
agentpass.com 4mo ago

Draft RFC for AgentPass, an open protocol for agent authorization

gneray
2pts0
news.ycombinator.com 4mo ago

Ask HN: What AI can you use for personal video editing?

gneray
1pts0
github.com 4mo ago

Why Replit's $9B Valuation Looks Cheap

gneray
2pts0
nobodyreadsyourlogs.com 7mo ago

Nobodyreadsyourlogs.com

gneray
2pts1
augmentingcognition.com 1y ago

Augmenting Long-Term Memory

gneray
2pts0
blog.sbensu.com 2y ago

Industrial Macros

gneray
2pts0
github.com 2y ago

Performance isn't a strategy, community is

gneray
1pts0
www.osohq.com 2y ago

Implementing Type Inference for Data Validation

gneray
3pts0
www.osohq.com 2y ago

Why Authorization Is Hard in Microservices

gneray
2pts0
forums.superherohype.com 2y ago

Christopher Nolan Hooks Up 4-In Analog TV (Casio EV-4500) to IMAX Camera

gneray
4pts1
techcrunch.com 3y ago

Coast: Demo platform for ‘API-first’ companies

gneray
3pts0
www.osohq.com 3y ago

How and Why I Implemented Type Inference in a Logic Language

gneray
3pts0
www.osohq.com 3y ago

Implementing Type Inference in the Polar Language

gneray
4pts0
www.airplane.dev 4y ago

Airplane.dev

gneray
3pts0
medium.com 4y ago

Slack Stinks (RIP Quill)

gneray
1pts0
www.aboutwayfair.com 4y ago

Distributed Authorization and Wayfair’s Supply Chain

gneray
37pts7
www.osohq.com 4y ago

How We Turn Authorization Logic into SQL

gneray
147pts69
twitter.com 5y ago

We're giving away our interview process

gneray
1pts0
docs.osohq.com 5y ago

Polar Foundations and a Primer on Logic Programming

gneray
1pts0
www.osohq.com 5y ago

Polar: Oso's Declarative Policy Language [video]

gneray
1pts0
www.osohq.com 5y ago

Building a Django app with data access control

gneray
4pts0
www.osohq.com 5y ago

Anatomy of a Rule

gneray
3pts0
www.techrepublic.com 5y ago

Developer-Centric Security Products

gneray
4pts0

Everyone here firing shots at this guy should try holding their tongues.

You/we are all susceptible to this sort of thing, and I call BS on anyone who says they check every little thing their agent does with the same level of scrutiny as they would if they were doing it manually.

This ^^

There's a set of common needs across these gateways, and everyone is building their own proxies and reinventing the wheel, which just feels unnecessary.

~All of our customers at Oso (the launch partner in the article) have been asking us how to get a handle on this stuff...bc their CEO/board/whatever is asking them. So to us it was a no-brainer. (We're also Tailscale customers.)

Welcome to Gas Town 7 months ago

But first, before we get into Gas Town’s operation, I need to get rid of you real quick.

WARNING DANGER CAUTION GET THE F** OUT YOU WILL DIE

I have never met Steve, but this warning alone is :chefskiss:

i know calvin, and he's one of the most authentic people i've worked with in tech. this could not be more off the mark

Agreed! But you're glossing over the Zanzibar point of view on this topic, which falls back to dual-writes. That approach has a lot of downsides: "Unfortunately, when making writes to multiple systems, there are no easy answers."[0]

Having spoken with the actual creators of Zanzibar, they lament the massive challenge this design presents and the heroics they undertook over 7+ years at Google to overcome them.

By contrast, we're seeing lots of the best tech companies opt for approaches that let them leave the data in their source database wherever and as much as possible [1]

[0] https://authzed.com/blog/the-dual-write-problem

[1] https://www.osohq.com/post/local-authorization

I'm founder of Oso btw.

This is the single-biggest drawback to purely Zanzibar-based architectures. The problem with requiring the authorization system to own all authorization data is that there’s really very little pure authorization data in any application. The majority of it is just application data that is sometimes used to make authorization decisions.

Here's a technical post that details these implications in practice: https://www.osohq.com/post/authorization-for-the-rest-of-us

And another post that describes an alternative approach, Oso: https://www.osohq.com/post/local-authorization

(Shocker: I'm cofounder/CEO of Oso)

Stripe has, frankly speaking, been somewhat slow on building out more sophisticated subscription and billing products, opening the door for companies like Paddle and more recent arrivals like Lago (which focuses on open sourced billing) to create significantly more nuanced offerings

Why do you think they’ve been slow?

How Matzo Is Made 2 years ago

For all those in this thread who haven't tried Matzah, I strongly encourage you to do so. Think of it not as bread, but a cracker – a platform for spreads, if you will.

What kinds of spreads?

- Butter + salt

- Butter + jam

- I guess butter + anything

- Brie cheese

I could go on. Try it y'all!