Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
precommunicator
on June 18, 2023
|
parent
|
context
|
favorite
| on:
Keycloak – Open-source identity and access managem...
Once you're a Keycloak user you can figure out if someone is using Keycloak within seconds, e.g. I know my credit card company uses it. And this isn't a matter of security, security by obscurity is really bad idea.
ElongatedMusket
on June 18, 2023
[–]
Are you referring to the formatting/contents of the session token, or some other way to tell within seconds?
rad_gruchalski
on June 18, 2023
|
parent
[–]
The cookie name and login/registration URL (realm) gives it away immediately.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: