HN user

mooreds

93,785 karma

Solver of business problems, usually with software.

Senior Director, CIAM Strategy & Identity Standards at FusionAuth / https://fusionauth.io/

Personal site: https://www.mooreds.com, hn@mooreds.com, +1 720 560 8545 (email preferred).

@mooreds on Twitter. https://bsky.app/profile/mooreds.com on Blue Sky.

Editor/writer for https://letterstoanewdeveloper.com/

Writer at https://ciamweekly.substack.com/

LI: https://linkedin.com/in/mooreds

meet.hn/city/us-Boulder

Posts20,970
Comments5,400
View on HN
fusionauth.io 51m ago

OAuth DPoP

mooreds
2pts0
securityboulevard.com 4h ago

Build vs. Buy Auth Is the Wrong Question. Here's the Right One

mooreds
1pts0
www.hollywoodreporter.com 5h ago

'Ted Lasso' Was Finished. Then Jason Sudeikis Had an Epiphany

mooreds
7pts5
www.nytimes.com 5h ago

Soaring Egg Prices Are Hitting China Hard

mooreds
5pts0
www.youtube.com 6h ago

Intelligent MFA in FusionAuth: Smarter Security Without the Friction [video]

mooreds
2pts0
baweaver.com 6h ago

Beyond Enumerable: Testing Membership with Bloom Filters

mooreds
2pts0
en.wikipedia.org 6h ago

GPS Week Number Rollover

mooreds
2pts0
dev.jimgrey.net 7h ago

The operational risk of AI coding agents in B2B SaaS

mooreds
2pts0
launchany.com 7h ago

The Pillars of an API Platform

mooreds
8pts0
www.koat.com 7h ago

BLM proposes reopening 336k acres around Chaco Canyon to mineral leasing

mooreds
3pts0
idpro.org 21h ago

About Cidpro

mooreds
3pts0
www.eoinhurrell.com 21h ago

The Reranker Tax: When a Smart Layer Can't Save a Weak Foundation

mooreds
2pts0
www.youtube.com 21h ago

What Americans Need to Understand About China [video]

mooreds
4pts0
text.npr.org 1d ago

Amid nurse shortage, a university rolls out the welcome mat for men

mooreds
36pts84
www.cnn.com 1d ago

Titanic passenger's letter gives account of life on board before disaster

mooreds
5pts0
www.chesapeakebaymagazine.com 1d ago

Italy Puts 10M Euros into Fighting Invasive Blue Crabs

mooreds
3pts0
www.bloomberg.com 1d ago

Bump, Set, Boom: Why Girls Volleyball Is Suddenly Everywhere

mooreds
2pts1
www.youtube.com 1d ago

Designing for AI Optionality with Karl Koch from DuckDuckGo [video]

mooreds
2pts0
text.npr.org 1d ago

India's youth-led Cockroach movement vows to continue protest after crackdown

mooreds
1pts0
en.wikipedia.org 1d ago

Paul Grice

mooreds
1pts0
text.npr.org 1d ago

Post-workout essentials that boost performance and prevent injury

mooreds
2pts0
sphericalcowconsulting.com 1d ago

The Identity Salon: Five-Year Problems, Chatham House Notes, and DNS Nonsense

mooreds
3pts0
georgemauer.net 1d ago

FizzBuzz Tier List

mooreds
1pts0
masterpoint.io 1d ago

How Cursor Rebuilt Its Terraform Workflow with Masterpoint

mooreds
3pts0
www.mooreds.com 1d ago

What It's Like to Lead an Engineering Org: Thoughts on "CTO in the Loop"

mooreds
3pts0
www.tsoon.com 1d ago

Some writing keeps traveling and I can't predict which

mooreds
4pts0
seasonedleadership.substack.com 2d ago

The Messy Reality of AI Transformation

mooreds
3pts0
fusionauth.io 2d ago

Customer Identity vs. Identity Access Management Explained

mooreds
1pts0
www.axios.com 2d ago

Federal cuts threaten wildfire research as Western fire risk rises

mooreds
8pts1
deanbaker22.substack.com 2d ago

The NYT Reports on China: A Teachable Moment

mooreds
2pts0

Yeah, I was just commenting on a LinkedIn post[0] (don't hate the player, hate the game :) ). In it, someone talked about the difference between creating software and owning it.

Creating software with AI is super easy--plan, prompt, test, go, go, go!

Owning software means you're responsible for maintaining it over time, fixing edge cases, operating it well, and more.

If you're building a one-off custom webapp to meet your needs, create away. If you're writing software for a business to run on, you're owning it. My fav article on this topic is this post[1] on durable vs disposable software.

0: https://www.linkedin.com/feed/update/urn:li:activity:7482123...

1: https://www.honeycomb.io/blog/disposable-code-is-here-to-sta...

That's a great analogy. My only addition would be the nuance of that data modelling is way more flexible than authentication (and this is said as someone who is continually surprised by the business requirements, standards, and complexities of auth). Data modelling, after all, needs to handle the entirety of reality (at least what can be mapped to a computer). So you're more likely to outgrow it.

I've heard plenty of stories of folks moving from homegrown auth to a off-the-shelf solution, but that's because I'm in the off-the-shelf auth space.

It'd be super interesting to hear stories of folks who went the other way, and outgrew their service provider's auth.

Oh man, it really depends(tm). If you are building a small internal app, sure, but you'd often still be better off leveraging a social provider or employee directory.

I work in the auth space (for FusionAuth) and we run into plenty of folks that started out rolling auth themselves. Just username and password right? A bit of hashing, salting and leveraging a built-in crypto library.

But then you need to add account recovery. And then MFA. And then registration. And then progressive registration. And then webhook integration. And then passkeys. And then SAML integration. And the delegated SAML setup. And then and then and then.

You're distracted from your core application by feature requests for your login system.

You have lots of options nowadays. Use a library provided by your framework (Rails, Spring, and Django have them), use a tool like Better Auth, use a third party system like FusionAuth or Auth0. But don't build undifferentiated functionality that impacts your user experience.

PS Of course, where I stand depends on where I sit, but I firmly believe that you should not build an auth system the same way you should not build a database.

Congrats to Better Auth. I'm in the auth space and see all kinds of things.

Anything that makes it easier for developers to build secure applications is a win!

[dead] 15 days ago

Camarota does raise a fair point: US-born children of immigrants would not exist in the United States had their parents not immigrated. If the goal is to estimate the total fiscal effects attributable to immigration, then including those children alongside their parents is a reasonable exercise. Of course, that argument also means we should include the grandchildren of immigrants in the analysis because they wouldn’t be here without immigrants either. Great-grandchildren too. On second thought, Camarota doesn’t have such a good argument.

Nice bit of shade.

Yeah, the small bits of sand in the gears is something that is hard to sell when you allocating engineering effort. But it adds up over time.

It makes the difference between a tool that is a pleasure to use and one that causes dread.

FusionAuth | Principal Software Engineer, Senior Java Engineer - Cloud, Account Executive | Varies between REMOTE (in USA, also in Europe but only for the account exec position) and ONSITE in Denver, CO, USA, details in each job desc | Salary ranges for the Principal Software Engineer it is 225k-270k, but the Euro positions don't have them :(

At FusionAuth, our mission is to make authentication and authorization simple and secure for every developer building web and mobile applications. We want devs to stop worrying about auth and focus on building something awesome.

There are a lot of companies in the auth space, but we feel like we have something special:

* a relatively unique deployment model (self-host on-prem, run in your cloud or let us operate it for you in ours)

* A well designed API first approach; one customer compared our APIs to petrichor

* a mature product (the code base is nine+ years old and we've found and fixed a lot of the sharp edges around core login use cases; but don't worry, there are plenty more features to add)

* a full featured free-as-in-beer version which makes the sales cycle easier; prospects often come in having prototyped an integration

Our core software is commercial. We open source much of our supporting infrastructure. Technologies and standards that you will work with: modern Java, PostgreSQL, Docker, Kubernetes, MySQL, OAuth, SAML, OIDC.

Learn more, including benefits and salaries, and apply here: https://fusionauth.io/careers/ ( Click/tap the 'View open positions' orange button. )

it just makes the handoff between myself and the agent feel more seamless.

This terrifies me because there's no way for the services on the other side of the browser to know who is doing what.

How do you constrain the agent?

How do you keep track of what you have done vs the agent?

What am I missing? Am I just behind the times?

Edit, added reference to what terrifies me.

That's a good point. The behavior varies wildly based on the domain provider and the behavior when you let a domain expire is similar to what happens when a phone number is deactivated, but with a possibly bigger blast radius.

As someone running a company, I get 2-5 unsolicited "vulnerability reports" per week. Half of them are an LLM finding some bad CSS on our framer splash page. The other half I assume are an extortion attempt so we just mark as spam.

I don't think that is unique to the LLM era. The company I work for has been getting some form of spam vulnerability reports years before LLMs were a thing. Often similar to what you mention about 'bad CSS'.

Maybe the volume has increased a bit, but we've added in a filtering solution and I'm more distant from the reports now, so hard to be sure.

It has to come with appropriate information, not just a date.

That's a great point. You need to give the manager enough info they can determine if it makes sense to intervene. Sometimes they have enough context that a date for a decision is all they need, other times you need to provide more details.

Haha, so much to learn so I wouldn't say I'm well-versed.

But let me know when you launch. My email is in my profile.