3 ms·
> It’s generally not considered safe to expose the raw tokens I think the article muddies the waters on this point because the the sentence defining tokens in
by sixbrx 5y ago
> It’s generally not considered safe to expose the raw tokens
I think the article muddies the waters on this point because the the sentence defining tokens in the intro says they "are safe to expose".
- aconbere 5y agoYeah, I can’t really speak for the article. I ran a large production tokenization system for a payments company. Most of my experience is within the narrow context of protecting credit card numbers. In other contexts maybe you’re more accepting of public exposure. For example tokenization can be an effective GDPR mitigation, but i don’t think folks are particularly worried about reuse attacks when the information contains a name or email (I’m sure there are instances where they are concerned as well) But at least when talking about tokenizing actionable information (credit card, bank account, whatever) implementors should be careful to keep them out of their public apis.