Mark T. Tomczak<p>The open-source security / authentication stacks are great at the core of what they do.</p><p>... I still want to grab some of the devs who maintain them and shake 'em by the lapels for having really bad DevEx opinions.</p><p>Burned two hours this week failing to get basic auth working on a Docker registry instance because I wasn't properly binding the htpasswd file I set up. Time would have been cut in half if the log entry was "user not in the password file" instead of a generic "authentication failed." I'm sure someone was like "hurr durr you can't put that much detail in the logs, attackers could steal the logs and have so much info." Look... Fuck you, my (imaginary) guy, no attackers are gonna steal the logs because <em>the service won't exist because I don't have enough debug info to stand it up in the first place.</em></p><p><a href="https://mastodon.fixermark.com/tags/docker" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>docker</span></a> <a href="https://mastodon.fixermark.com/tags/auth" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>auth</span></a> <a href="https://mastodon.fixermark.com/tags/htpasswd" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>htpasswd</span></a> <a href="https://mastodon.fixermark.com/tags/openssl" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>openssl</span></a></p>