Awesome List Updates on Oct 27, 2023
7 awesome lists updated today.
🏠 Home · 🔍 Search · 🔥 Feed · 📮 Subscribe · ❤️ Sponsor
1. Awesome Naming
Tools, Applications, Libraries, Frameworks
- Safari - Web browser developed by Apple.
2. Awesome Board Games
Strategy
The Old King's Crown
The Old King’s Crown is a game of card-driven conquest, where you play as heirs to a vacant throne, vying for control of an ancient, overgrown kingdom. Wield unique abilities and leverage your followers’ traits to best outwit your opponents across a map that stretches from the teetering heights of the castle to the dappled light of the necropolis.
As leader of your faction you will be staking claims with Heralds openly as well as positioning your forces in secret, hoping to claim the locations that fit your designs. However, keep an eye on your rivals, as they too have agents and agendas, poised to undo your best laid plans.
Royalty, rebels or ruses. What crown will you wear?
In The Old King's Crown, players move their Herald to locations, hoping to claim them. Then simultaneously players play cards from their hand, facedown to regions of the board. These are then revealed and resolved. Winning these clashes will result in different rewards that further their position and grant them the game's primary goal, influence. When a player is able to reach a set number of influence, dependent on player count, and is able to retain it until the end of a round, they win the game.
/pic7508098.jpg)
| Players | Min. Age | Time |
|---|---|---|
| 1 - 4 | 12 | 60-90m |
3. Static Analysis
Programming Languages / Other
- luacheck (⭐400) — A tool for linting and static analysis of Lua code.
4. Awesome Iam
Multi-factor auth / Identifiers
- SMS Multifactor Authentication in Antarctica - Doesn't work because there are no cellphone towers at stations in Antarctica.
Password-less auth / SMS-based
- An argument for passwordless - Passwords are not the be-all and end-all of user authentication. This article tries to tell you why.
- Magic Links – Are they Actually Outdated? - What are magic links, their origin, pros and cons.
Password-less auth / WebAuthn
- WebAuthn guide - Introduce WebAuthn as a standard supported by all major browsers, and allowing “servers to register and authenticate users using public key cryptography instead of a password”.
Password-less auth / Security key
- Webauthn and security keys - Describe how authentication works with security keys, details the protocols, and how they articulates with WebAuthn. Key takeaway: “There is no way to create a U2F key with webauthn however. (…) So complete the transition to webauthn of your login process first, then transition registration.”
- Getting started with security keys - A practical guide to stay safe online and prevent phishing with FIDO2, WebAuthn and security keys.
- Solo (⭐2.3k) - Open security key supporting FIDO2 & U2F over USB + NFC.
- OpenSK (⭐3.1k) - Open-source implementation for security keys written in Rust that supports both FIDO U2F and FIDO2 standards.
- YubiKey Guide (⭐12k) - Guide to using YubiKey as a SmartCard for storing GPG encryption, signing and authentication keys, which can also be used for SSH. Many of the principles in this document are applicable to other smart card devices.
- YubiKey at Datadog (⭐498) - Guide to setup Yubikey, U2F, GPG, git, SSH, Keybase, VMware Fusion and Docker Content Trust.
Password-less auth / JWT
loginsrv- Standalone minimalistic login server providing a JWT login for multiple login backends (htpasswd, OSIAM, user/password, HTTP basic authentication, OAuth2: GitHub, Google, Bitbucket, Facebook, GitLab).
Authorization / ReBAC frameworks
- Warrant (⭐1.3k) - A relationship based access control (ReBAC) engine (inspired by Google Zanzibar) also capable of enforcing any authorization paradigm, including RBAC and ABAC.
OAuth2 & OpenID / Other tools
- An Illustrated Guide to OAuth and OpenID Connect - Explain how these standards work using simplified illustrations.
- OAuth 2 Simplified - A reference article describing the protocol in simplified format to help developers and service providers implement it.
- OAuth 2.0 and OpenID Connect (in plain English) - Starts with an historical context on how these standards came to be, clears up the innacuracies in the vocabulary, then details the protocols and its pitfalls to make it less intimidating.
- OAuth in one picture - A nice summary card.
- Open-Sourcing BuzzFeed's SSO Experience - OAuth2-friendly adaptation of the Central Authentication Service (CAS) protocol. You'll find there good OAuth user flow diagrams.
- Hidden OAuth attack vectors - How to identify and exploit some of the key vulnerabilities found in OAuth 2.0 authentication mechanisms.
- PKCE Explained - “PKCE is used to provide one more security layer to the authorization code flow in OAuth and OpenID Connect.”
- Keycloak - Open-source Identity and Access Management. Supports OIDC, OAuth 2 and SAML 2, LDAP and AD directories, password policies.
- Casdoor (⭐12k) - A UI-first centralized authentication / Single-Sign-On (SSO) platform based. Supports OIDC and OAuth 2, social logins, user management, 2FA based on Email and SMS.
- ZITADEL (⭐11k) - An Open-Source solution built with Go and Angular to manage all your systems, users and service accounts together with their roles and external identities. ZITADEL provides you with OIDC, OAuth 2.0, login & register flows, passwordless and MFA authentication. All this is built on top of eventsourcing in combination with CQRS to provide a great audit trail.
- a12n-server (⭐483) - A simple authentication system which only implements the relevant parts of the OAuth2 standards.
SAML / Other tools
- SAML vs. OAuth - “OAuth is a protocol for authorization: it ensures Bob goes to the right parking lot. In contrast, SAML is a protocol for authentication, or allowing Bob to get past the guardhouse.”
- The Difference Between SAML 2.0 and OAuth 2.0 - “Even though SAML was actually designed to be widely applicable, its contemporary usage is typically shifted towards enterprise SSO scenarios. On the other hand, OAuth was designed for use with applications on the Internet, especially for delegated authorisation.”
- What's the Difference Between OAuth, OpenID Connect, and SAML? - Identity is hard. Another take on the different protocol is always welcome to help makes sense of it all.
- Web Single Sign-On, the SAML 2.0 perspective - Another naive explanation of SAML workflow in the context of corporate SSO implementation.
- The Beer Drinker's Guide to SAML - SAML is arcane at times. A another analogy might helps get more sense out of it.
- SAML is insecure by design - Not only weird, SAML is also insecure by design, as it relies on signatures based on XML canonicalization, not XML byte stream. Which means you can exploit XML parser/encoder differences.
- The Difficulties of SAML Single Logout - On the technical and UX issues of single logout implementations.
Secret Management / Other tools
- HashiCorp Vault - Secure, store and tightly control access to tokens, passwords, certificates, encryption keys.
- Infisical (⭐19k) - An alternative to HashiCorp Vault.
5. Awesome Jax
Libraries / New Libraries
- Spyx (⭐123) - Spiking Neural Networks in JAX for machine learning on neuromorphic hardware.
6. Awesome Datascience
Comparison / Supervised Learning
- Classification
7. Awesome Angular
Editor Components / Google Developer Experts
- ngx-simple-text-editor (⭐10) - Ngx Simple Text editor or ST editor is a simple native text editor component for Angular 9+.
- Prev: Oct 28, 2023
- Next: Oct 26, 2023