Hacker News new | ask | show | jobs
by arekkas 3073 days ago
It's really nice that we see more and more awareness for Zero Trust and specifically Google's BeyondCorp whitepaper. If you're looking to experiment with this model yourself, check out the following open source projects. While they might not implement everything in Google's BeyondCorp paper yet, they are pretty close to the full thing, and address many issues raised in the comments.

-> OAuth2 Authorization Server https://github.com/ory/hydra

-> Identity & Access Proxy (early access): https://github.com/ory/oathkeeper

If you have questions don't hesitate to ask.

2 comments

These look great, a couple questions:

1) Are these deployed at scale anywhere?

2) Any known security audits?

Thanks!

1) Hydra is deployed at scale, Oathkeeper is our new kid on the block

2) We have an OpenID Connect certification coming in, but no security audits so far

Early access? What's next? DLC and loot boxes?
You play too many video games ;)