3 ms·
If you're like me and are wondering what Macaroons are, some searching revealed to me that this is the 2014 paper [1] that introduced them to the public. It's a
by sarcasmic 8y ago
If you're like me and are wondering what Macaroons are, some searching revealed to me that this is the 2014 paper [1] that introduced them to the public. It's a nested, chained HMAC construction that's useful for delegation, and here's a library and some code examples [2] that one can play with to get a feel for what they do and how.
No wonder it's not well known: it hasn't been picked up by the blog treadmill where dudes on Medium post half-baked info they just found out about, and isn't being pushed by commercial auth proxies.
On that note, posts by Latacora or affiliated persons, there and here, seem to mix well-researched opinions and advice with in-jokes that are lost on all but other experts, assumptions of an inconsistent amount of domain expertise, and quips that muddy some topics more than a bystander would reasonably expect. Why not be more dry and less wry, include links, and morph the FUD around JWT to something real?
[1] https://static.googleusercontent.com/media/research.google.com/en//pubs/archive/41892.pdf https://static.googleusercontent.com/media/research.google.c... [2] https://github.com/rescrv/libmacaroons https://github.com/rescrv/libmacaroons
- tptacek 8y agoMail us any time for a refund. :) I'm fucking around, but really the answer is: if we didn't have the presumptive informality of a "blog" or some-such, we just wouldn't write; we'd get 20% of the way through a draft and just pick at it, hoping to make it more correct and authoritative, until our will to keep going evaporated. I have a whole folder full of things I started doing that with. The in-jokes and snark are what trick us into writing in the first place. There's no getting rid of it. I'm hopeful that people can at least appreciate that we aren't confining this stuff to Twitter threads anymore.
- tango24 8y agoI, for one, appreciate it. Thanks for taking the time to publish!
- Robin_Message 8y agoThe jokes make it readable as well as writeable. Keep them.
- jessaustin 8y agoThese libs seem to have seen more recent maintenance: https://github.com/go-macaroon https://github.com/go-macaroon
- evancordell 8y agoI have written a blog post on macaroons for you: http://evancordell.com/2015/09/27/macaroons-101-contextual-confinement.html http://evancordell.com/2015/09/27/macaroons-101-contextual-c... It may be sufficiently half-baked (not because I'm unfamiliar with the material but because I'm not sure I wrote it for the right audience).
- lvh 8y agoRe: JWT; sure, but it’s a multifaceted problem that’s more than one blog post. We’ll get there. Unfortunately, we’ve been saying most of that for years now, just because it’s not easily accessible in one place (a valid criticism!) doesn’t mean I’m not exhausted talking about it :)
- closeparen 8y agoHow would a service come into possession of a Macaroon good for another service? I could see getting a macaroon for a username/password/2FA in a frontend context, but how does it solve backend service authentication?