3 ms·
It is great that people are concerned about UUID entropy, because some implementations actually got much less than ~120 bits. However, I think article missed t
by DethNinja 4y ago
It is great that people are concerned about UUID entropy, because some implementations actually got much less than ~120 bits.
However, I think article missed the point that you shouldn’t use UUIDs as a security measure anyway.
- indigodaddy 4y agoWhat about his solution (160-bit (20 byte) random value that is then URL-safe base64-encoded)? Is that a good and properly used security measure for a URL?
- fbdab103 4y agoDepending on how many characters of representation you are willing to stomach, I prefer to use a more limited encoding than base64. Something that avoids IL1o0 so that a human could type it without guess work. As your human is not likely to know that you are including "0" but not "o", you have to nix both of them. This only matters if the url has any chance of being read by a human (ie ids). If it is some monstrous 2000 character thing that already contains gobs of metadata, go nuts.
- myaccount9786 4y agoJust to be clear, 122 random bits are just fine as a security measure depending on what you want to do. For example, if I have 1 URL and I'm trying to prevent someone from guessing it. How you choose to encode the bits doesn't affect the security; if you use UUID form it's just as secure as if you use Base64. Regardless, if I had my 122 random bits, you would require 2^121 guesses to have a 50% chance of guessing it. Edit: this is in the non-quantum case cf. https://en.m.wikipedia.org/wiki/Grover%27s_algorithm https://en.m.wikipedia.org/wiki/Grover%27s_algorithm Edit 2: (3:32 ET) done editing