Show HN: TideCloak – Decentralized IAM for security and user sovereignty

Hey HN!

After 6 years of R&D, our small team is excited to share our project TideCloak - an IAM designed to help developers move fast without worrying about catastrophic breaches or overpowered admins with keys to the kingdom.

Traditional IAMs rely on centralized authority - admins, root certificates, and decryption keys - which create glaring vulnerabilities in a breach. To address this, we’ve integrated Keycloak (Red Hat’s IAM) with a decentralized key architecture powered by our (academically validated) Ineffable Cryptography.

Here’s the idea: keys are split across a decentralized network (our Cybersecurity Fabric) so no one ever holds the full key. Even in a breach or F$%k up, there’s no unchecked authority exposed.

Right now, TideCloak uses the Cybersecurity Fabric as an IdP, meaning users authenticate without their credentials being stored or shared. Essentially, users bring their own authority - without needing to trust anyone else to keep it safe.

Coming soon: - Identity Governance Administration to prevent super admin abuse. - User-sovereign digital assets, where assets are secured with unique decentralized keys to protect against mass breaches.

We’ve just launched a free developer sandbox, and we’d love your feedback: https://github.com/tide-foundation/tidecloak-gettingstarted

It’s still early stages, and your input will help us improve.

Thanks for taking a look - ask us anything!


Comments URL: https://news.ycombinator.com/item?id=42460131

Points: 7

# Comments: 0

https://github.com/tide-foundation/tidecloak-gettingstarted

Created 1mo | Dec 19, 2024, 7:40:21 PM


Login to add comment

Other posts in this group

Show HN: Voice Cloning and Multilingual TTS in One Click (Windows)

We've created an open-source alternative to Eleven Labs for voice cloning and multilingual TTS. Key features:

- Clone voices from 15-second samples - 50+ pre-trained celebrity voice models - Sup

Jan 27, 2025, 4:20:10 AM | Hacker news
Making a live-mode test payment to yourself = a payment processor ToS violation?

To me it seemed like common sense that before you push the thing into the real world, no matter how much testing you do, you'd fire a couple test payments on the live version.

Apparently, after

Jan 27, 2025, 4:20:08 AM | Hacker news