To implement continuous authentication, mobile developers must support fine-grained enterprise security policies about the person, device state and authenticator. An embeddable Policy Decision Point (PDP) is essential for lightning fast policy evaluation, consistent decision logging, and advanced JWT validation.
No one ever won a law suit by putting forward a tepid case. They will position for maximum damage as a bargaining position, just like any of you would.
We will see. You can say it's bollocks, but I'm betting you are not an IP lawyer. Silverlake, the PE firm that acquired WP-Engine has a gaggle of IP lawyers that assessed the risk before the investment. Were they right or wrong? Like any sporting event, everyone has a strong opinion before the game. But it's only the final score that matters. I'm wishing Automatic the best of luck.
This is a trademark dispute. WP-Engine uses the trademark, and made a tactical decision not to license it. Their thought was better to ask for forgiveness later then pay up front. Protecting your trademark is critical for an organization governing an open source product. Just look at Docker to see what happens when you lose control of your trademark. Last I checked, most owners aggressively protect their trademark. It's one of the few IP protections open source companies have. Why are you all defending the freeloading open source strip miner? Is WP Engine's use of the trademark fair use? Something tells me that they will end up settling this out of court...
Note: the definition of an entrepreneur is someone who doesn't listen to advice (some of it good). This dude says you're startup is "zombie"... Well, he might be right, but if you see an opportunity there... That's what makes you smart. And in 10 years if you're successful, the same people who said your idea was bad will be saying it was obvious.
As a solo founder for 10+ years, what I can say is that all "rules" in business are "rules of thumb"... Not laws. It's ok to be a solo founder... Sometimes. Bounce ideas off your team instead of your co-founders. Make use of mentors. There is a workaround for all your challenges. I also recommend listening to podcasts with other founders. I host a podcast called "Open Source Underdogs". Lots of good advice there for all founders... Even if you're not working on open source. But there are plenty more. You need outside ideas... Just seek them out.
Don't burn out your friends talking about your startup. It's not that they aren't interested. But nobody needs a single vector relationship.
Also remember that VC's give tons of bad advice to founders. Or rather founders tend to put VC's on a pedestal, and misinterpret what they are saying as advice, when it is really just filter, convenient lies or lazy analysis. Be hugely skeptical of anything VC's tell you, including "you need co-founders".
I am CEO of Gluu. The podcast is an undertaking to help new open source software companies. There is no business model for the podcast, and it's attribution share alike license.
I'm recording a podcast, called Open Source Underdogs, focusing on open source business models. You can find it on iTunes, Google, Stitcher, etc or on the website https://opensourceunderdogs.com
IBM just made it's biggest acquisition ever on an open source company... It seems strange to use that as evidence that open source is not an effective tool--in certain circumstances--for building your business.
What about Cloudera? What about Automattic? What about MongoDB? What about MariaDB?
The podcast has 9 episodes, and we have about 20 more in the queue for 2018-2019.
Tune in... Some of the gurus of open source software share some valuable insights.
I prefer my HyperFIDO Mini. The Nano sends OTP text if you accidentally brush into something, and it's very awkward to get out. The light is "blinding" ??? That is ridiculous...
Auth0's business model is a race to zero. Microsoft, Google, Salesforce, Oracle and others (for example Okta, Onelogin in the startup arena) are going to force their prices down to practically nothing. The per user pricing model in the identity space is loved by insipid venture capitalists who like simple "back of the envelope" math, but customers hate it. You are penalizing customers for using your service--rewarding them for putting as few users as possible in the system. Also, there is no one-size fits all value for users--some users are more valuable then others (for example, an employee versus a one-time ecommerce customer who buys a t-shirt). So you end up trying to price users differently, which undermines your value story. What's more likely to happen is that open standards will increase competition and centralized service providers who add very little value, and are big targets for hackers, will be lucky to get out alive.
One thing to keep in mind is that Gluu is an IAM platform, not just an OpenID Connect Provider. It's a comprehensive suite that includes both central authentication, authorization, FIDO authentication (and support for many two factor technologies), mobile software, client software. Starting in version 3.0, we will bundle a special version of OpenLDAP, provided by Symas (another great FOSS vendor), specifically optimized for the Gluu Server.
An IAM platform is many products integrated together, and operationally scalable to meet mission critical requirements. An OpenID Provider is just one element of an IAM platform!
I totally agree with the lack of libraries!!! That's why we're working on oxd at Gluu: https://oxd.gluu.org
If you need a license, just email [email protected]
It's not free open source, but it will be very inexpensive. It reduces OpenID Connect to a simple three step process (with three corresponding method calls):
It's no more confusing then LDAP. First there was LDAP 1.0, 2.0, now we all use 3.0...
OpenID 2.0 is deprecated. Don't use it.
The current OpenID authentication protocol = OpenID Connect.
In the not too distant future, no one will even remember that something called OpenID 2.0 existed.
Maybe OpenID Connect should be OpenID 3.0? I think the idea was to show alignment with Facebook Connect's design...but more open. Remember, at the time Facebook Connect provided some good data--it was a massive user acceptance test.
IMHO, the blame lies with the OIDF for not delivering this message. OpenID Connect has been final for 4+ years. What's taking so long? Maybe it's not in the interest of the OIDF's controlling board members to promote this distributed identity infrastructure? MSFT wants you to use Azure AD. Google wants you to use their IDP. Maybe they don't want to promote until they have product ready? Stay tuned... I think when it's in the interest of the current finanical backers of the OIDF to promote OpenID Connect, no one will remember that old OpenID 2.0 thing.