3 ms·
If, like me, you had no idea what this was from reading the release announcement: Biscuit is an authorization token with decentralized verification, offline at
by grncdr 4y ago
If, like me, you had no idea what this was from reading the release announcement:
Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforcement based on a logic language.
- https://www.biscuitsec.org/ https://www.biscuitsec.org/
Seems like an elegant replacement for use cases where people commonly reach for JWTs.
- outofpaper 4y agoTheir documentation needs to lead with this instead on only having it in the home page.
- radicalbyte 4y agoIs it another one of those "cool new technologies" which exist only to push ETH? Or is it from the "hey we might have learned something from blockchain so we will apply some of the techniques but leave out the grift" side of the spectrum (so like KERI)?
- ithkuil 4y agoWhen I first heard of biscuits it was in the context of addressing the issues of macaroons. Macaroons have nothing to do with ETH. I don't care if biscuits can also be used in the context of ETH. I love macaroons and I wish they could be used in practice. Perhaps biscuits can be a good replacement for macaroons
- geal 4y agoThis is not a cryptocurrency technology,it was designed with microservices authorization in mind, inspired from JWT and macaroons. I have looked at cryptocurrency related tech earlier though (pairing libs from zcash, gamma signatures), because it could be a good basis for attenuation, but moved to simpler solutions lately
- francislavoie 4y agoAs a JWT replacement, I prefer PASETO: https://paseto.io/ https://paseto.io/
- tasuki 4y agoWhy?
- francislavoie 4y agoSee the link at the top, it explains all the problems with JWT/JOSE. But also PASETO is an unopinionated token format with strong security guarantees from using modern cryptographic algorithms. Edit: Looks like the ParagonIE website is returning 502s right now. Here's the archive: https://web.archive.org/web/20230123041631/https://paragonie.com/blog/2017/03/jwt-json-web-tokens-is-bad-standard-that-everyone-should-avoid https://web.archive.org/web/20230123041631/https://paragonie...
- geal 4y agoPASETO is great! It's way better than JWT, for the use cases targeted by JWT. Biscuit explores other use cases, like attenuation
- quickthrower2 4y agoBasically JWT + Attenuation? Attenuation does seem cool though.
- ciuncan 4y agoThank you, and I'd also like to point out that adding a little description to the title would not hurt. Otherwise I look at the title and feel compelled to joke "well, I mean, it's biscuit. It's in the name, it's biscuit." (Do you want to Accept Cookies? - Julie Nolke). https://www.youtube.com/watch?v=ZARmgNzP5L0 https://www.youtube.com/watch?v=ZARmgNzP5L0 Jokes aside, it looks really cool.
- geal 4y agoRight, we forgot to add the context on this release, thank you for the feedback!