home.social

#stateless — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #stateless, aggregated by home.social.

  1. 🔑 lesspass/lesspass

    :key: stateless open source password manager

    Generates unique passwords on demand using a master password and site details, with no vault syncing or storage. Works via browser extensions, CLI, mobile apps or self-hosted server

    ⭐ Stars: 6024
    📅 Last Update: May 25, 2026

    github.com/lesspass/lesspass

    #selfhosted #homelab #selfhost #selfhosting #opensource #passwordmanager #stateless

  2. 🔑 lesspass/lesspass

    :key: stateless open source password manager

    Generates unique passwords on demand using a master password and site details, with no vault syncing or storage. Works via browser extensions, CLI, mobile apps or self-hosted server

    ⭐ Stars: 6024
    📅 Last Update: May 25, 2026

    github.com/lesspass/lesspass

    #selfhosted #homelab #selfhost #selfhosting #opensource #passwordmanager #stateless

  3. Statelessness.
    Padawannabe is trying to maintain state, not understanding that in most cases, Tim Berners-Lee (and I agree) is still correct: The web should be stateless. That same applies to government control of the internet. With very rare exceptions. .

  4. Under #Trump approach, #foundlings given up for #adoption could be #stateless.

    5 years ago, when #SCOTUS heard arguments over whether it should overrule #RoeVWade, Justice #AmyConeyBarrett asked a series of questions about #SafeHaven laws, which allow parents to anonymously surrender newborn #babies at hospitals or firehouses, without fear of prosecution.

    #law #BirthrightCitizenship #immigration #Constitution #WhiteSupremacy #WhiteChristianNationalism #hypocrisy
    nytimes.com/2026/04/01/us/poli

  5. Under #Trump approach, #foundlings given up for #adoption could be #stateless.

    5 years ago, when #SCOTUS heard arguments over whether it should overrule #RoeVWade, Justice #AmyConeyBarrett asked a series of questions about #SafeHaven laws, which allow parents to anonymously surrender newborn #babies at hospitals or firehouses, without fear of prosecution.

    #law #BirthrightCitizenship #immigration #Constitution #WhiteSupremacy #WhiteChristianNationalism #hypocrisy
    nytimes.com/2026/04/01/us/poli

  6. Under #Trump approach, #foundlings given up for #adoption could be #stateless.

    5 years ago, when #SCOTUS heard arguments over whether it should overrule #RoeVWade, Justice #AmyConeyBarrett asked a series of questions about #SafeHaven laws, which allow parents to anonymously surrender newborn #babies at hospitals or firehouses, without fear of prosecution.

    #law #BirthrightCitizenship #immigration #Constitution #WhiteSupremacy #WhiteChristianNationalism #hypocrisy
    nytimes.com/2026/04/01/us/poli

  7. Under #Trump approach, #foundlings given up for #adoption could be #stateless.

    5 years ago, when #SCOTUS heard arguments over whether it should overrule #RoeVWade, Justice #AmyConeyBarrett asked a series of questions about #SafeHaven laws, which allow parents to anonymously surrender newborn #babies at hospitals or firehouses, without fear of prosecution.

    #law #BirthrightCitizenship #immigration #Constitution #WhiteSupremacy #WhiteChristianNationalism #hypocrisy
    nytimes.com/2026/04/01/us/poli

  8. Under #Trump approach, #foundlings given up for #adoption could be #stateless.

    5 years ago, when #SCOTUS heard arguments over whether it should overrule #RoeVWade, Justice #AmyConeyBarrett asked a series of questions about #SafeHaven laws, which allow parents to anonymously surrender newborn #babies at hospitals or firehouses, without fear of prosecution.

    #law #BirthrightCitizenship #immigration #Constitution #WhiteSupremacy #WhiteChristianNationalism #hypocrisy
    nytimes.com/2026/04/01/us/poli

  9. Is this a #secure #MessagingApp? Maybe not yet, but it’s time to think about #DigitalPrivacy.

    Imagine a #Messaging platform that’s as #secure as #Signal but requires #NoRegistration and #NoInstallation. By leveraging #WebRTC for direct #BrowserToBrowser communication, this #OpenSource project eliminates the #Middleman entirely. Simply share a unique #URL to establish an #Encrypted #PrivateChannel. It is a #Lightweight, #Disposable method to bypass #DataHarvesting and reclaim #DigitalSovereignty.

    This project introduces a new #Paradigm in #ClientSide managed #Encryption. Send #Secure messages with #NoSetup, #NoCloud, and #NoTrace.

    Experience the #Features:
    * #PWA (#ProgressiveWebApp) for instant access
    * #P2P (#PeerToPeer) connectivity
    * #EndToEndEncryption (#E2EE)
    * #SignalProtocol & #PostQuantum #Cryptography
    * #Multimedia, #FileTransfer, & #VideoCalls
    * #NoDatabase & #Stateless architecture
    * #TURN server support for reliable connections

    While not yet a direct replacement for #Simplex or #WhatsApp, this introduces a unique approach to #SecureCommunication.

    Try the #LiveDemo now:
    p2p.positive-intentions.com/if

    Explore the #Technical roadmap:
    positive-intentions.com/docs/t

    Read the full #Documentation:
    positive-intentions.com/docs/t

    #PrivacyTech #Privacy #CyberSecurity #Infosec #WebDev #JavaScript #Decentralized #EncryptionProtocol #QuantumResistant #Tech #FOSS #SoftwareEngineering #DataPrivacy #SecureChat #NoLog #P2PChat #WebRTCProtocol #Coding #DevCommunity #DigitalPrivacy #InternetFreedom #SecureMessaging #WebTech #AppDevelopment #CryptographyResearch #PrivateMessaging #WebPlatform #ZeroTrust #Innovation

  10. Is this a #secure #MessagingApp? Maybe not yet, but it’s time to think about #DigitalPrivacy.

    Imagine a #Messaging platform that’s as #secure as #Signal but requires #NoRegistration and #NoInstallation. By leveraging #WebRTC for direct #BrowserToBrowser communication, this #OpenSource project eliminates the #Middleman entirely. Simply share a unique #URL to establish an #Encrypted #PrivateChannel. It is a #Lightweight, #Disposable method to bypass #DataHarvesting and reclaim #DigitalSovereignty.

    This project introduces a new #Paradigm in #ClientSide managed #Encryption. Send #Secure messages with #NoSetup, #NoCloud, and #NoTrace.

    Experience the #Features:
    * #PWA (#ProgressiveWebApp) for instant access
    * #P2P (#PeerToPeer) connectivity
    * #EndToEndEncryption (#E2EE)
    * #SignalProtocol & #PostQuantum #Cryptography
    * #Multimedia, #FileTransfer, & #VideoCalls
    * #NoDatabase & #Stateless architecture
    * #TURN server support for reliable connections

    While not yet a direct replacement for #Simplex or #WhatsApp, this introduces a unique approach to #SecureCommunication.

    Try the #LiveDemo now:
    p2p.positive-intentions.com/if

    Explore the #Technical roadmap:
    positive-intentions.com/docs/t

    Read the full #Documentation:
    positive-intentions.com/docs/t

    #PrivacyTech #Privacy #CyberSecurity #Infosec #WebDev #JavaScript #Decentralized #EncryptionProtocol #QuantumResistant #Tech #FOSS #SoftwareEngineering #DataPrivacy #SecureChat #NoLog #P2PChat #WebRTCProtocol #Coding #DevCommunity #DigitalPrivacy #InternetFreedom #SecureMessaging #WebTech #AppDevelopment #CryptographyResearch #PrivateMessaging #WebPlatform #ZeroTrust #Innovation

  11. Is this a #secure #MessagingApp? Maybe not yet, but it’s time to think about #DigitalPrivacy.

    Imagine a #Messaging platform that’s as #secure as #Signal but requires #NoRegistration and #NoInstallation. By leveraging #WebRTC for direct #BrowserToBrowser communication, this #OpenSource project eliminates the #Middleman entirely. Simply share a unique #URL to establish an #Encrypted #PrivateChannel. It is a #Lightweight, #Disposable method to bypass #DataHarvesting and reclaim #DigitalSovereignty.

    This project introduces a new #Paradigm in #ClientSide managed #Encryption. Send #Secure messages with #NoSetup, #NoCloud, and #NoTrace.

    Experience the #Features:
    * #PWA (#ProgressiveWebApp) for instant access
    * #P2P (#PeerToPeer) connectivity
    * #EndToEndEncryption (#E2EE)
    * #SignalProtocol & #PostQuantum #Cryptography
    * #Multimedia, #FileTransfer, & #VideoCalls
    * #NoDatabase & #Stateless architecture
    * #TURN server support for reliable connections

    While not yet a direct replacement for #Simplex or #WhatsApp, this introduces a unique approach to #SecureCommunication.

    Try the #LiveDemo now:
    p2p.positive-intentions.com/if

    Explore the #Technical roadmap:
    positive-intentions.com/docs/t

    Read the full #Documentation:
    positive-intentions.com/docs/t

    #PrivacyTech #Privacy #CyberSecurity #Infosec #WebDev #JavaScript #Decentralized #EncryptionProtocol #QuantumResistant #Tech #FOSS #SoftwareEngineering #DataPrivacy #SecureChat #NoLog #P2PChat #WebRTCProtocol #Coding #DevCommunity #DigitalPrivacy #InternetFreedom #SecureMessaging #WebTech #AppDevelopment #CryptographyResearch #PrivateMessaging #WebPlatform #ZeroTrust #Innovation

  12. Is this a #secure #MessagingApp? Maybe not yet, but it’s time to think about #DigitalPrivacy.

    Imagine a #Messaging platform that’s as #secure as #Signal but requires #NoRegistration and #NoInstallation. By leveraging #WebRTC for direct #BrowserToBrowser communication, this #OpenSource project eliminates the #Middleman entirely. Simply share a unique #URL to establish an #Encrypted #PrivateChannel. It is a #Lightweight, #Disposable method to bypass #DataHarvesting and reclaim #DigitalSovereignty.

    This project introduces a new #Paradigm in #ClientSide managed #Encryption. Send #Secure messages with #NoSetup, #NoCloud, and #NoTrace.

    Experience the #Features:
    * #PWA (#ProgressiveWebApp) for instant access
    * #P2P (#PeerToPeer) connectivity
    * #EndToEndEncryption (#E2EE)
    * #SignalProtocol & #PostQuantum #Cryptography
    * #Multimedia, #FileTransfer, & #VideoCalls
    * #NoDatabase & #Stateless architecture
    * #TURN server support for reliable connections

    While not yet a direct replacement for #Simplex or #WhatsApp, this introduces a unique approach to #SecureCommunication.

    Try the #LiveDemo now:
    p2p.positive-intentions.com/if

    Explore the #Technical roadmap:
    positive-intentions.com/docs/t

    Read the full #Documentation:
    positive-intentions.com/docs/t

    #PrivacyTech #Privacy #CyberSecurity #Infosec #WebDev #JavaScript #Decentralized #EncryptionProtocol #QuantumResistant #Tech #FOSS #SoftwareEngineering #DataPrivacy #SecureChat #NoLog #P2PChat #WebRTCProtocol #Coding #DevCommunity #DigitalPrivacy #InternetFreedom #SecureMessaging #WebTech #AppDevelopment #CryptographyResearch #PrivateMessaging #WebPlatform #ZeroTrust #Innovation

  13. Is this a #secure #MessagingApp? Maybe not yet, but it’s time to think about #DigitalPrivacy.

    Imagine a #Messaging platform that’s as #secure as #Signal but requires #NoRegistration and #NoInstallation. By leveraging #WebRTC for direct #BrowserToBrowser communication, this #OpenSource project eliminates the #Middleman entirely. Simply share a unique #URL to establish an #Encrypted #PrivateChannel. It is a #Lightweight, #Disposable method to bypass #DataHarvesting and reclaim #DigitalSovereignty.

    This project introduces a new #Paradigm in #ClientSide managed #Encryption. Send #Secure messages with #NoSetup, #NoCloud, and #NoTrace.

    Experience the #Features:
    * #PWA (#ProgressiveWebApp) for instant access
    * #P2P (#PeerToPeer) connectivity
    * #EndToEndEncryption (#E2EE)
    * #SignalProtocol & #PostQuantum #Cryptography
    * #Multimedia, #FileTransfer, & #VideoCalls
    * #NoDatabase & #Stateless architecture
    * #TURN server support for reliable connections

    While not yet a direct replacement for #Simplex or #WhatsApp, this introduces a unique approach to #SecureCommunication.

    Try the #LiveDemo now:
    p2p.positive-intentions.com/if

    Explore the #Technical roadmap:
    positive-intentions.com/docs/t

    Read the full #Documentation:
    positive-intentions.com/docs/t

    #PrivacyTech #Privacy #CyberSecurity #Infosec #WebDev #JavaScript #Decentralized #EncryptionProtocol #QuantumResistant #Tech #FOSS #SoftwareEngineering #DataPrivacy #SecureChat #NoLog #P2PChat #WebRTCProtocol #Coding #DevCommunity #DigitalPrivacy #InternetFreedom #SecureMessaging #WebTech #AppDevelopment #CryptographyResearch #PrivateMessaging #WebPlatform #ZeroTrust #Innovation

  14. Heute nehmen wir uns diese Akronyme vor. Wir schauen uns an, was sie bedeuten, wofür du sie brauchst und wo die feinen, aber wichtigen Unterschiede liegen – besonders im Kontext deiner Java EE-Web-Anwendungen.

    magicmarcy.de/war-vs-ejb

    #war #ejb #akronym #jsf #primefaces #zip #web-application-archive #enterprise-javabean #unternehmenslogik #webanwendung #session-bean #stateless #stateful #message-driven #javaee

  15. Heute nehmen wir uns diese Akronyme vor. Wir schauen uns an, was sie bedeuten, wofür du sie brauchst und wo die feinen, aber wichtigen Unterschiede liegen – besonders im Kontext deiner Java EE-Web-Anwendungen.

    magicmarcy.de/war-vs-ejb

    #war #ejb #akronym #jsf #primefaces #zip #web-application-archive #enterprise-javabean #unternehmenslogik #webanwendung #session-bean #stateless #stateful #message-driven #javaee

  16. Heute nehmen wir uns diese Akronyme vor. Wir schauen uns an, was sie bedeuten, wofür du sie brauchst und wo die feinen, aber wichtigen Unterschiede liegen – besonders im Kontext deiner Java EE-Web-Anwendungen.

    magicmarcy.de/war-vs-ejb

    #war #ejb #akronym #jsf #primefaces #zip #web-application-archive #enterprise-javabean #unternehmenslogik #webanwendung #session-bean #stateless #stateful #message-driven #javaee

  17. The web was designed to be #stateless

    We've tried to make our site reflect that, as best we can.

    We need some data to demonstrate that people are reading what we write. Why else are we writing it?

    This is ... not straightforward, in 2026.

    But I think we've found a solution to one part of the puzzle. And we don't need #cookies

    We don't need #cookieConsent (that is largely a myth, anyway)

    design.scotentblog.co.uk/no-mo

  18. Heute nehmen wir uns diese Akronyme vor. Wir schauen uns an, was sie bedeuten, wofür du sie brauchst und wo die feinen, aber wichtigen Unterschiede liegen – besonders im Kontext deiner Java EE-Web-Anwendungen.

    magicmarcy.de/war-vs-ejb

    #war #ejb #akronym #jsf #primefaces #zip #web-application-archive #enterprise-javabean #unternehmenslogik #webanwendung #session-bean #stateless #stateful #message-driven #javaee

  19. Heute nehmen wir uns diese Akronyme vor. Wir schauen uns an, was sie bedeuten, wofür du sie brauchst und wo die feinen, aber wichtigen Unterschiede liegen – besonders im Kontext deiner Java EE-Web-Anwendungen.

    magicmarcy.de/war-vs-ejb

    #war #ejb #akronym #jsf #primefaces #zip #web-application-archive #enterprise-javabean #unternehmenslogik #webanwendung #session-bean #stateless #stateful #message-driven #javaee

  20. Heute nehmen wir uns diese Akronyme vor. Wir schauen uns an, was sie bedeuten, wofür du sie brauchst und wo die feinen, aber wichtigen Unterschiede liegen – besonders im Kontext deiner Java EE-Web-Anwendungen.

    magicmarcy.de/war-vs-ejb

    #war #ejb #akronym #jsf #primefaces #zip #web-application-archive #enterprise-javabean #unternehmenslogik #webanwendung #session-bean #stateless #stateful #message-driven #javaee

  21. 'You're invisible, you don't exist' - life without a birth certificate

    "Many people may take their birth certificate, or similar official papers, for granted - hidden in a drawer and rarely seeing the light of day - but for those without one, it can lead to a shadow life or an uncertain existence."

    link below:
    bbc.com/news/articles/cx2drqwp

    #Stateless #SouthAfrica #Africa

  22. Imagine If the #UK had a new government, led by a #humanrights lawyer.

    Then it would urgently overturn the #Tory removal of the #BritishCitizenship of #ShamimaBegum. She was sex trafficked as a child, had 3 children from a #forcedmarriage who all died, & was made #stateless in 2019.

    But instead of a human rights lawyer, the UK elected a cruel liar called #Starmer. He doesn't even condemn #genocide, but persecutes anti-genociders as "#terrorist".

    screenshot from bbc.co.uk/news/articles/c3wzp6 #ukpol

  23. Ethereum Foundation Ungkap Strategi Atasi State Bloat: Ancaman Baru bagi Desentralisasi Jaringan Ethereum

    Tradingan - #Ethereum Foundation (EF) #melalui #tim #Stateless #Consensus #baru-baru ini #mengungkapkan #serangkaian #gagasan #penting untuk mengatasi masalah serius yang dikenal sebagai state bloat. Masalah ini muncul akibat pertumbuhan data jaringan Ethereum yang terus membesar dan tidak pernah berkurang, sehingga semakin membebani operator node. Dalam konteks…

    tradingan.com/ethereum-foundat

  24. Ethereum Foundation Ungkap Strategi Atasi State Bloat: Ancaman Baru bagi Desentralisasi Jaringan Ethereum

    Tradingan - #Ethereum Foundation (EF) #melalui #tim #Stateless #Consensus #baru-baru ini #mengungkapkan #serangkaian #gagasan #penting untuk mengatasi masalah serius yang dikenal sebagai state bloat. Masalah ini muncul akibat pertumbuhan data jaringan Ethereum yang terus membesar dan tidak pernah berkurang, sehingga semakin membebani operator node. Dalam konteks…

    tradingan.com/ethereum-foundat

  25. "The Court of Appeal today unanimously decided that three generations of stateless persons in a Perak family are automatically Malaysians under the Federal Constitution, and also affirmed that stateless persons can legally marry under Malaysian laws even without Malaysian identity cards."

    malaymail.com/news/malaysia/20

    #Malaysia #Families #Stateless

  26. [Перевод] Почему мы отказываемся от serverless

    Когда находишься на критическом пути API-аутентификации, важна каждая миллисекунда. Спустя два года борьбы с ограничениями serverless мы пересобрали весь наш стек API, добившись таким образом существенного снижения сквозных задержек. Когда мы запускали наш API на Cloudflare Workers, они казались идеальным выбором для сервиса API-аутентификации. Глобальная периферийная инфраструктура, автоматическое масштабирование и оплата только за использование. Разве это не замечательно? Перенесёмся в будущее: мы полностью пересобрали эту систему на основе Go-серверов с хранением состояния, в результате получив шестикратный рост производительности и существенное упрощение архитектуры, позволившее реализовать самохостинг и платформонезависимость. TL;DR: • Мы перешли с Cloudflare Workers на Go-серверы • Снизили задержки в шесть раз • Устранили сложные механизмы обхода кэшей и оверхед конвейеров данных • Упростили архитектуру, перейдя от распределённой системы к простому приложению • Обеспечили возможность самохостинга и платформонезависимость В статье мы расскажем о том, почему совершили этот переход, о проблемах, вынудивших нас на это пойти, и о том, чему мы научились в процессе.

    habr.com/ru/articles/958814/

    #serverless #самохостинг #cloudflare #cloudflare_workers #stateless #stateful

  27. 𝑯𝒂𝒏𝒏𝒂𝒉 𝑨𝒓𝒆𝒏𝒅𝒕 - 𝑪𝒉. 9: 𝑻𝒉𝒆 𝑫𝒆𝒄𝒍𝒊𝒏𝒆 𝒐𝒇 𝒕𝒉𝒆 𝑵𝒂𝒕𝒊𝒐𝒏-𝑺𝒕𝒂𝒕𝒆 𝒂𝒏𝒅 𝒕𝒉𝒆 𝑬𝒏𝒅 𝒐𝒇 𝒕𝒉𝒆 𝑹𝒊𝒈𝒉𝒕𝒔 𝒐𝒇 𝑴𝒂𝒏

    youtu.be/0lMIRmv8uCk

    Reading guide and more at waywordsstudio.com/project/are

    #democracy #readingguide #arendt #hannaharendt #theoriginsoftotalitarianism #reflections #chapterreflections #history #literacy #totalitarianism #dictatorship #tyranny #antisemitism #imperialism #ww2 #holocaust #oligarchy #refugees #stateless #nationstate #humanrights

  28. Jose Takei, an 82-year-old man of Japanese descent who became stateless after being left in the Philippines as a child following the end of World War II, is keen to get Japanese citizenship while he is in good health. japantimes.co.jp/news/2025/08/ #japan #philippines #wwii #foreignministry #shigeruishiba #citizenship #stateless

  29. Many people are #computer illiterate. Even more people are #AI illiterate. How to train these people to become AI literate? Current #LLMs are like #Lucy in the #movie called the Fifty First Dates.

    You need to understand their basic architecture. These LLMs are #stateless. They have message length, window length, long-term memory, and other limits. To work with them in long projects like my ICandy #browser #dashboard, you need to create a lot of progress notes and documentations.

  30. OK, and Marta Dusseldorp. Also great acting.

    Did the complete above mentioned series [2019] in two days and it's a great piece of story, approx. 6 hours arching all the relevant aspects. And btw CREATED AND PRODUCED by Cate Blanchett [and others], by far not just the minor role that I mentioned in the first toot.

    #CateBlanchett #Stateless #MartaDusseldorp #Australia #Detention

  31. OK, and Marta Dusseldorp. Also great acting.

    Did the complete above mentioned series [2019] in two days and it's a great piece of story, approx. 6 hours arching all the relevant aspects. And btw CREATED AND PRODUCED by Cate Blanchett [and others], by far not just the minor role that I mentioned in the first toot.

    #CateBlanchett #Stateless #MartaDusseldorp #Australia #Detention

  32. OK, and Marta Dusseldorp. Also great acting.

    Did the complete above mentioned series [2019] in two days and it's a great piece of story, approx. 6 hours arching all the relevant aspects. And btw CREATED AND PRODUCED by Cate Blanchett [and others], by far not just the minor role that I mentioned in the first toot.

    #CateBlanchett #Stateless #MartaDusseldorp #Australia #Detention

  33. OK, and Marta Dusseldorp. Also great acting.

    Did the complete above mentioned series [2019] in two days and it's a great piece of story, approx. 6 hours arching all the relevant aspects. And btw CREATED AND PRODUCED by Cate Blanchett [and others], by far not just the minor role that I mentioned in the first toot.

    #CateBlanchett #Stateless #MartaDusseldorp #Australia #Detention

  34. OK, and Marta Dusseldorp. Also great acting.

    Did the complete above mentioned series [2019] in two days and it's a great piece of story, approx. 6 hours arching all the relevant aspects. And btw CREATED AND PRODUCED by Cate Blanchett [and others], by far not just the minor role that I mentioned in the first toot.

    #CateBlanchett #Stateless #MartaDusseldorp #Australia #Detention

  35. Just started #STATELESS on #Netflix because of Cate Blanchett [who actually just seems to be a side character] and like it VERY much. It's an Australian limited series, main topic are the stateless refugees that are held in [kind of administrative] detention centers. The series captures the lives of many people who are somewhat connected with those and the respective work done there and slowly centers in where it hurts.

    Inspired by true events - I'm excited how it will turn out.

    #CateBlanchett

  36. Zero Trust Login
    How I Stopped Reading Your Data in my services

    I build systems where not even the almighty admin (me) can read your data.
    No backdoors. No db.users.find(). Just encrypted chaos. Beautiful, unreadable, untouchable chaos.

    Security isn't magic, we are just scared to lose control.
    If I'm debugging live prod data, I've already failed my architecture exam.

    Many pretend to do the same using JWTs/JWKs. Cute. But let's be honest:
    There's always someone with access. Production isn't a vault, it's just a cleaner sandbox.

    Most systems cling to readable tokens, human friendly JSON, and debug services like a comfort blanket.
    I don't.

    Zero trust could work like this:

    1. User signs up
    ➤ They give a password.
    ➤ I derive a unique key from that password.
    ➤ That key encrypts a randomly generated User Key.
    ➤ That User Key encrypts everything else (emails, usernames, secrets, hopes, dreams).

    2. User logs in
    ➤ Same password = same derived key.
    ➤ That unlocks their User Key.
    ➤ That unlocks their encrypted data.
    ➤ Voilà. Magic. But not magic. Math.

    3. Token generation
    ➤ It has no traceable info and All Session Data are encrypted with the backend-only key.
    ➤ It expires. Quickly.
    ➤ It is fingerprinted to the device/browser.
    ➤ You steal it? Good luck. Doesn’t work on your laptop, Dave.

    👁️ Zero Visibility ≠ Zero Functionality
    • 🔒 I can’t decrypt your data. Not even if I'm angry.
    • 🛡️ Backend is stateless. Frontend is stateless. Token is everything.
    • 👨‍💻 No user ID in memory. No session storage. No cookies.
    • 🪪 You want access? Bring your password, WebAuthn, 2FA or other login methods.
    • 🕵️ No OAuth weirdness, no redirect hell.
    • 🧠 Works like OAuth, but with actual privacy. Not even a user ID is exposed
    • ⚙️ Agnostic to used technologies - Cloud, OnPremise, SQL, NoSQL, doesn't matter.

    Because security isn't magic. It's math, discipline, and just enough spite to not let anyone (including yourself) peek behind the curtain.

    Until then, I'll be in the server room. Giggling at encrypted documents I can't read.

    #ZeroTrust #Encryption #Security #Stateless #PrivacyByDesign #BackendOnlyAccess #NoRootForYou #Coding #Programming

  37. Zero Trust Login
    How I Stopped Reading Your Data in my services

    I build systems where not even the almighty admin (me) can read your data.
    No backdoors. No db.users.find(). Just encrypted chaos. Beautiful, unreadable, untouchable chaos.

    Security isn't magic, we are just scared to lose control.
    If I'm debugging live prod data, I've already failed my architecture exam.

    Many pretend to do the same using JWTs/JWKs. Cute. But let's be honest:
    There's always someone with access. Production isn't a vault, it's just a cleaner sandbox.

    Most systems cling to readable tokens, human friendly JSON, and debug services like a comfort blanket.
    I don't.

    Zero trust could work like this:

    1. User signs up
    ➤ They give a password.
    ➤ I derive a unique key from that password.
    ➤ That key encrypts a randomly generated User Key.
    ➤ That User Key encrypts everything else (emails, usernames, secrets, hopes, dreams).

    2. User logs in
    ➤ Same password = same derived key.
    ➤ That unlocks their User Key.
    ➤ That unlocks their encrypted data.
    ➤ Voilà. Magic. But not magic. Math.

    3. Token generation
    ➤ It has no traceable info and All Session Data are encrypted with the backend-only key.
    ➤ It expires. Quickly.
    ➤ It is fingerprinted to the device/browser.
    ➤ You steal it? Good luck. Doesn’t work on your laptop, Dave.

    👁️ Zero Visibility ≠ Zero Functionality
    • 🔒 I can’t decrypt your data. Not even if I'm angry.
    • 🛡️ Backend is stateless. Frontend is stateless. Token is everything.
    • 👨‍💻 No user ID in memory. No session storage. No cookies.
    • 🪪 You want access? Bring your password, WebAuthn, 2FA or other login methods.
    • 🕵️ No OAuth weirdness, no redirect hell.
    • 🧠 Works like OAuth, but with actual privacy. Not even a user ID is exposed
    • ⚙️ Agnostic to used technologies - Cloud, OnPremise, SQL, NoSQL, doesn't matter.

    Because security isn't magic. It's math, discipline, and just enough spite to not let anyone (including yourself) peek behind the curtain.

    Until then, I'll be in the server room. Giggling at encrypted documents I can't read.

    #ZeroTrust #Encryption #Security #Stateless #PrivacyByDesign #BackendOnlyAccess #NoRootForYou #Coding #Programming

  38. Zero Trust Login
    How I Stopped Reading Your Data in my services

    I build systems where not even the almighty admin (me) can read your data.
    No backdoors. No db.users.find(). Just encrypted chaos. Beautiful, unreadable, untouchable chaos.

    Security isn't magic, we are just scared to lose control.
    If I'm debugging live prod data, I've already failed my architecture exam.

    Many pretend to do the same using JWTs/JWKs. Cute. But let's be honest:
    There's always someone with access. Production isn't a vault, it's just a cleaner sandbox.

    Most systems cling to readable tokens, human friendly JSON, and debug services like a comfort blanket.
    I don't.

    Zero trust could work like this:

    1. User signs up
    ➤ They give a password.
    ➤ I derive a unique key from that password.
    ➤ That key encrypts a randomly generated User Key.
    ➤ That User Key encrypts everything else (emails, usernames, secrets, hopes, dreams).

    2. User logs in
    ➤ Same password = same derived key.
    ➤ That unlocks their User Key.
    ➤ That unlocks their encrypted data.
    ➤ Voilà. Magic. But not magic. Math.

    3. Token generation
    ➤ It has no traceable info and All Session Data are encrypted with the backend-only key.
    ➤ It expires. Quickly.
    ➤ It is fingerprinted to the device/browser.
    ➤ You steal it? Good luck. Doesn’t work on your laptop, Dave.

    👁️ Zero Visibility ≠ Zero Functionality
    • 🔒 I can’t decrypt your data. Not even if I'm angry.
    • 🛡️ Backend is stateless. Frontend is stateless. Token is everything.
    • 👨‍💻 No user ID in memory. No session storage. No cookies.
    • 🪪 You want access? Bring your password, WebAuthn, 2FA or other login methods.
    • 🕵️ No OAuth weirdness, no redirect hell.
    • 🧠 Works like OAuth, but with actual privacy. Not even a user ID is exposed
    • ⚙️ Agnostic to used technologies - Cloud, OnPremise, SQL, NoSQL, doesn't matter.

    Because security isn't magic. It's math, discipline, and just enough spite to not let anyone (including yourself) peek behind the curtain.

    Until then, I'll be in the server room. Giggling at encrypted documents I can't read.

  39. Zero Trust Login
    How I Stopped Reading Your Data in my services

    I build systems where not even the almighty admin (me) can read your data.
    No backdoors. No db.users.find(). Just encrypted chaos. Beautiful, unreadable, untouchable chaos.

    Security isn't magic, we are just scared to lose control.
    If I'm debugging live prod data, I've already failed my architecture exam.

    Many pretend to do the same using JWTs/JWKs. Cute. But let's be honest:
    There's always someone with access. Production isn't a vault, it's just a cleaner sandbox.

    Most systems cling to readable tokens, human friendly JSON, and debug services like a comfort blanket.
    I don't.

    Zero trust could work like this:

    1. User signs up
    ➤ They give a password.
    ➤ I derive a unique key from that password.
    ➤ That key encrypts a randomly generated User Key.
    ➤ That User Key encrypts everything else (emails, usernames, secrets, hopes, dreams).

    2. User logs in
    ➤ Same password = same derived key.
    ➤ That unlocks their User Key.
    ➤ That unlocks their encrypted data.
    ➤ Voilà. Magic. But not magic. Math.

    3. Token generation
    ➤ It has no traceable info and All Session Data are encrypted with the backend-only key.
    ➤ It expires. Quickly.
    ➤ It is fingerprinted to the device/browser.
    ➤ You steal it? Good luck. Doesn’t work on your laptop, Dave.

    👁️ Zero Visibility ≠ Zero Functionality
    • 🔒 I can’t decrypt your data. Not even if I'm angry.
    • 🛡️ Backend is stateless. Frontend is stateless. Token is everything.
    • 👨‍💻 No user ID in memory. No session storage. No cookies.
    • 🪪 You want access? Bring your password, WebAuthn, 2FA or other login methods.
    • 🕵️ No OAuth weirdness, no redirect hell.
    • 🧠 Works like OAuth, but with actual privacy. Not even a user ID is exposed
    • ⚙️ Agnostic to used technologies - Cloud, OnPremise, SQL, NoSQL, doesn't matter.

    Because security isn't magic. It's math, discipline, and just enough spite to not let anyone (including yourself) peek behind the curtain.

    Until then, I'll be in the server room. Giggling at encrypted documents I can't read.

    #ZeroTrust #Encryption #Security #Stateless #PrivacyByDesign #BackendOnlyAccess #NoRootForYou #Coding #Programming

  40. Zero Trust Login
    How I Stopped Reading Your Data in my services

    I build systems where not even the almighty admin (me) can read your data.
    No backdoors. No db.users.find(). Just encrypted chaos. Beautiful, unreadable, untouchable chaos.

    Security isn't magic, we are just scared to lose control.
    If I'm debugging live prod data, I've already failed my architecture exam.

    Many pretend to do the same using JWTs/JWKs. Cute. But let's be honest:
    There's always someone with access. Production isn't a vault, it's just a cleaner sandbox.

    Most systems cling to readable tokens, human friendly JSON, and debug services like a comfort blanket.
    I don't.

    Zero trust could work like this:

    1. User signs up
    ➤ They give a password.
    ➤ I derive a unique key from that password.
    ➤ That key encrypts a randomly generated User Key.
    ➤ That User Key encrypts everything else (emails, usernames, secrets, hopes, dreams).

    2. User logs in
    ➤ Same password = same derived key.
    ➤ That unlocks their User Key.
    ➤ That unlocks their encrypted data.
    ➤ Voilà. Magic. But not magic. Math.

    3. Token generation
    ➤ It has no traceable info and All Session Data are encrypted with the backend-only key.
    ➤ It expires. Quickly.
    ➤ It is fingerprinted to the device/browser.
    ➤ You steal it? Good luck. Doesn’t work on your laptop, Dave.

    👁️ Zero Visibility ≠ Zero Functionality
    • 🔒 I can’t decrypt your data. Not even if I'm angry.
    • 🛡️ Backend is stateless. Frontend is stateless. Token is everything.
    • 👨‍💻 No user ID in memory. No session storage. No cookies.
    • 🪪 You want access? Bring your password, WebAuthn, 2FA or other login methods.
    • 🕵️ No OAuth weirdness, no redirect hell.
    • 🧠 Works like OAuth, but with actual privacy. Not even a user ID is exposed
    • ⚙️ Agnostic to used technologies - Cloud, OnPremise, SQL, NoSQL, doesn't matter.

    Because security isn't magic. It's math, discipline, and just enough spite to not let anyone (including yourself) peek behind the curtain.

    Until then, I'll be in the server room. Giggling at encrypted documents I can't read.

    #ZeroTrust #Encryption #Security #Stateless #PrivacyByDesign #BackendOnlyAccess #NoRootForYou #Coding #Programming

  41. 🌍✈️ So you're #stateless and want to travel? 🤔 Here's a #whimsical #guide that may or may not help you navigate the world's #bureaucratic #mazes without a #passport. Just remember, if it all goes south, don’t call Taejun – he’s already busy crafting #disclaimers. 🙅‍♂️📄
    taejun.substack.com/p/travel-g #travel #issues #HackerNews #ngated

  42. 🌍✈️ So you're #stateless and want to travel? 🤔 Here's a #whimsical #guide that may or may not help you navigate the world's #bureaucratic #mazes without a #passport. Just remember, if it all goes south, don’t call Taejun – he’s already busy crafting #disclaimers. 🙅‍♂️📄
    taejun.substack.com/p/travel-g #travel #issues #HackerNews #ngated