Discussion about this post

User's avatar
Alexander Salkever's avatar

The letter from Opet focused on security but it really extends to all technology, particularly as it relates to open source. Another point highlighted by my colleague Bill Barton:

From Opet's open letter, this seems really key: "In practice, these integration models collapse authentication (verifying identity) and authorization (granting permissions) into overly simplified interactions, effectively creating single-factor explicit trust between systems on the internet and private internal resources. This architectural regression undermines fundamental security principles that have proven durability." The fact that many people (probably including many of us) tend to abbreviate both authentication and authorization as 'auth', is a signal of the unfortunate conflation.

Expand full comment

No posts