‹ BackHN Continuity

Thread

Big Tech ruined the cloud, so we're renaming ours

212 points · 108 comments · 2sf5

  1. voidnullvalue · · focus · HN ↗
    Nabu Kasa keeps ignoring the elephant in the room of security and permissions. They have no native ability to set user groups and permissions. There is no serious RBAC. I guess it doesn't sell cloud subscriptions. I cant keep my children from affecting devices they shouldn't. I ended up replacing my automation with mqtt
    1. Aurornis · · focus · HN ↗
      I think they're reading their audience and making the correct product choice.

      Home Assistant users are the power users of the home automation world, but even among their user base I think the number of users who would use a full set of groups and permissions controls in their home is very small.

      This is a feature that would take a lot of engineering effort and only make the product more complicated for most of their users. The part of their user base that did use it would probably never be happy because they wanted something even more specific.

      Their basic permissions and control structure covers most of the common use cases. Going further would be 100X more work for something that would only be used by a very small minority of users.

      1. hobofan · · focus · HN ↗
        I think a lot of people have a wrong perception of how "complicated" authorization systems need to be, most likely because they've been confrontend with badly built ones their whole career.

        These days if you build it with a central policy engine, e.g. on top of Open Policy Agent with Rego as a policy language, and stick to a (actor, object, action) triple system, you can build an extensible and powerful authorization system that usually also is less polluting to the codebase as many other approaches. For HA specifically, where you have a quite low numbers of actors and objects, most of the headaches that could come with such a system in terms of scaling also fall away.

        1. Aurornis · · focus · HN ↗
          I had to check that this wasn’t sarcasm when the post went from this

          > I think a lot of people have a wrong perception of how "complicated" authorization systems need to be,

          To this

          > These days if you build it with a central policy engine, e.g. on top of Open Policy Agent with Rego as a policy language, and stick to a (actor, object, action) triple system,

          This is the complexity that makes it not worth the effort. That’s a lot to develop, test, document, maintain, create UX for, and continue educating people about for something so few people would ever use.

          I’m not saying it can’t be done. I’m saying doing it would be more effort than the upside. It’s into the part of the curve where you’re spending 10X the developer time as other features to cater to 1 in 1000 users who aren’t going to be happy anyway because it’s not exactly what they imagined they wanted.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.