Hacker News new | past | comments | ask | show | jobs | submit | caloique's comments login

Co-founder of BoxyHQ here - We've crafted an open-source enterprise SSO because we firmly believe that robust security shouldn't be a privilege limited to large organizations. Ideally, essential enterprise-level features like this should become commonplace for all.

While we acknowledge the reasons behind SSO being in the enterprise tier, we're all on a collective journey to enhance our security measures. Open Core models are indeed a good option (my preference), yet the dynamics vary across solutions and industries. It's up to each of us to explore, experiment, and discover what resonates with our market. In doing so, we can foster growth while maintaining our commitment to supporting the community in the long run.


Well stated. I was merely showing how one could implement an open core strategy. I’m a firm believer in SSO for all (and not limited to social platforms or GitHub).


Supertokens also allows you to implement enterprise SSO through their integration to SAML Jackson (by BoxyHQ).

https://boxyhq.com/guides/jackson/integrations/supertokens


Reading this blog post made me think if there are other options for open source companies to generate revenue.

Besides Donations, Support, Licensing, Cloud-hosted Services or the Open-core model.

Any ideas/suggestions? And which one would you recommend (ideally based on experience)?


1) The richest man in Babylon 2) The four agreement 3) Secrets of the Millionaire Mind


Hey everyone, Retraced is an audit logs OSS product, that was initially built by Replicated and it has been enhanced by BoxyHQ.

With it you can now give your users the superpower to track every critical event within your product, and get full visibility over their account’s activities on your app. You will also allow them to send security-related events to their SIEM. It would be great to get your feedback.

Key features: - Compliant audit logs for your product - Record user and system activities - Admin UI to view logs. Also embed the viewer anywhere in your product - Export events to CSV or security systems like your favourite SIEM - Cryptographically guaranteed immutability of logs with a verifiable digest


Plus one! I was recommended the book "The Hidden Life of Trees". Did anyone read it? Any related articles, please share :)


Thanks for the insights, have you seen any good practice (tips) on how 'security mechanisms for development' could actually help security teams and developers work smoothly? Instead of being the reason for conflict.


I think the most trivial mechanism is to have your own subnet for developers that maybe has fewer restrictions. Not really a DMZ, but perhaps skip deep package inspections. Most tools can be configured to allow self-signed certs, but it is still a lot of hassle, especially for test systems. In exchange the dev subnet should only have restricted access to the rest of the internal network. But lacking convenience here is preferable to not being able to download some dependencies.


Interesting point, and why do you think is that?


Incentives.

Ensuring the security of a product doesn't have as tangible bragging points as shipping new features. Failing the former is unlikely to be blamed on product, but achieving the latter will almost certainly be credited to them. Responsibility for an insecure endpoint or poorly configured service falls to the engineers, despite the managerial influences that will often lead engineers to cut corners on things like security in the first place.


Pricing is one aspect, but OSS solutions bring community and a level of transparency that most closed source companies don't.


Until the VCs turn the screws and they don't anymore.


If that happens, fork. It's (literally) free.


Does that ever work in practice? Has there been a standard fork of Audacity that everyone flocked to since they got purchased by Muse?


Tons of example. Most wildly used forks out there are probably WebKit and Blink, the engines of two popular browsers.

Some other notable projects that started as forks: postgres, Wordpress, Apache Server, OpenSSH. I'm sure there are others I forgot.


Sounds like BoxyHQ could be relevant here. Plug-n-play for developers that need to build enterprise features like SSO, audit logs, directory sync, privacy vault and other boring stuff that are required to be compliant.

100% free & self-hosted. It's Open source (Apache-2.0 license) [I am one of the co-founders, sorry for the plug]


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: