Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

JWT is to HTTP Basic what OAuth2 is to logging in.

Auth doesn't have to be complicated to be effective.

Developers know/care very little about information security and a lot about following "standards" and "best practices."

Google and Facebook have learned over the years to take advantage of this.



> Google and Facebook have learned over the years to take advantage of this.

In what way?


If authentication is too complicated for the average developer to understand, other businesses will become more willing to use Goog & FB as identity providers.

There's also generally a lot of FUD around authentication because most web developers don't understand information security well enough to weigh the pros and cons, so technical discussions usually devolve into, "Google uses it, so it must be solid."




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: