Hacker News new | ask | show | jobs
by usui 69 days ago
> Every manageable element in an IPv8 network is authorised via OAuth2 JWT tokens served from a local cache. Every service a device requires is delivered in a single DHCP8 lease response.

Isn't it 2 weeks late for April Fools'?

2 comments

I'm not going to pretend I know all about IP routing and networking. I understand enough of it to have a home server all appropriately set up with IPv4.

But what makes this quote a problem? I mean, it seems a bit excessive, but I don't understand why...

IP is what, four layers of protocols lower than OAUTH?
and they might as well earmark oauth3
OAuth8, you surely meant.
Just a gut check but it feels ugly to put auth in an L3 proposal.
Even skipping the hard parts:

to make a request you need to receive a token

to receive a token you need to make a request

This is pure Catch-22.

hell, before we get and send the token how do we get a list of authorized users and systems over?

and if we're going to use IPv4 / 6 to get set up, why switch to IPv8? we're already talking, and it's working so use certs and tokens over those protocols

It's a collection of words that don't actually say anything. What's being protected by these tokens and how? How is trust established? How do you bootstrap L3 authentication when you first need to reach a remote server over the internet?

Like most AI slop it might sound reasonable at first glance but there's no substance behind it. Usually there's some (deeply flawed) substance but here it's just completely absent.

I feel the same, I guess using JWT is the joke here?
It's never too late for a savory blend of tomato, carrot, celery, beet, parsley, lettuce, watercress, and spinach.