5 ms·
Woof. Literally nobody likes x509. Is anyone seriously working on an alternative? I think there’s room for a more modern, simpler cert format. Sort of related
by mmalone 6y ago
Woof.
Literally nobody likes x509. Is anyone seriously working on an alternative? I think there’s room for a more modern, simpler cert format.
Sort of relatedly, I actually really like JWK for representing keys.
Do you think a professionally built solution that gets the details right is possible?
- colmmacc 6y agoI'm biased because I work at AWS, and even more biased because I now work on our IAM team, but I really like AWS SIGv4 and IAM policy. SIGv4 signing itself is request-level, and is incredibly simple with a tiny pre-authorization TCB. IAM policy is a full and expressive authorization language with a rich grammar. They're then paired with an ecosystem of features like CloudTrail and last-use-of-credential that give meaningful controls that avoid trade-offs between availability and security. It doesn't have to be AWS, but I do think that solutions in this space really have to be operational services, and not just technologies or standards. It has to be someone's full time job to look at this stuff and make sure it's working and secure, and that's just very hard to match. If I quit my job tomorrow and was building a startup, I'd use AWS API Gateway's SIGv4 and policy support and leave it at that.
- mmalone 6y agoYou’d use that for service-to-service stuff, to mutually authenticate services (not users), as well? I’ve always thought of AWS IAM as: great for my-service-to-cloud-service, not so great for my-service-to-my-service. I haven’t looked at AWS IAM in a while. I’m gonna take another look now :)