TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Show HN: Kliento, simpler machine authentication without API keys or JWTs

1 pointsby gnareaabout 1 month ago
Kliento is a workload authentication protocol that brings the concept of Kubernetes- and GCP-style &quot;service accounts&quot; to the whole Internet in a vendor-neutral and decentralised way.<p>It uses DNSSEC to embed the full chain of trust in the credentials, so servers won&#x27;t have to query external systems during verification. Think of them as short-lived JWTs that can be verified entirely offline by the server. This means that there are no long-lived secrets to protect, or public keys to configure or retrieve during verification.<p>We built the underlying technology, VeraId, for humanitarian purposes, but we lost the funding due to the recent foreign aid cuts. VeraId has been independently audited &lt;<a href="https:&#x2F;&#x2F;veraid.net&#x2F;about&#x2F;#security-audit" rel="nofollow">https:&#x2F;&#x2F;veraid.net&#x2F;about&#x2F;#security-audit</a>&gt; and has an Internet-Draft: &lt;<a href="https:&#x2F;&#x2F;datatracker.ietf.org&#x2F;doc&#x2F;html&#x2F;draft-narea-domainauth-00" rel="nofollow">https:&#x2F;&#x2F;datatracker.ietf.org&#x2F;doc&#x2F;html&#x2F;draft-narea-domainauth...</a>&gt;.<p>I&#x27;m trying to figure out if I should continue to invest in this technology, so any feedback -- whether positive, negative or neutral -- will be much appreciated! Having worked at Auth0, I believe this could drastically simplify things on the client and server sides, but there&#x27;s still a lot to do to realise that full potential and I&#x27;d like to gauge the extent to which folks might want to try it.

no comments

no comments