Hacker News new | past | comments | ask | show | jobs | submit login

tptacek wrote up a rather nice comparative survey of the field, including Biscuits and Macaroons

https://fly.io/blog/api-tokens-a-tedious-survey




We also did an episode of the podcast with Geoffroy:

https://securitycryptographywhatever.com/2022/01/29/biscuits...


This was a great episode, another great one I remember is https://securitycryptographywhatever.com/2021/08/12/what-do-...

I'd recommend listening (or reading the transcripts) to anyone who's needs or wants to understand more about JWT and other tokens

(And if you're not, check out the other episodes still. That podcast is great, some of the episodes get really deep into the cryptography weeds but if I get trough them I still feel like I learned something :-) thanks for making it)


Tldr client-server is different than server-server, you should think about your use case and what you need from your auth system, but tptacek thought long and hard about each at two different companies and decided on macaroons in both cases. Good to know!

(Just kidding, ish, and though they're quite long they're not too long and I did read; would recommend.)




Consider applying for YC's first-ever Fall batch! Applications are open till Aug 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: