5 ms·
Auth means authentication or authorization? that's the dilemma
by hackernewds 2y ago
Auth means authentication or authorization? that's the dilemma
- alex_lav 2y agoSure, so why would we replace the two words that have correct meaning when the real problem is laziness?
- theptip 2y agoThe industry has used “authz” and “authn” to disambiguate for decades.
- cdelsolar 2y agoI’ve been working in this industry for decades and this is the first time I made that connection…
- mgkimsal 2y agoyou're not alone.
- bostik 2y agoThe distinction was already present in Apache2 configs in early 2000's, although there authentication was "auth", and "authorisation" was authz. Real travesty came from OAuth. A system designed to handle authorisation was named after the term for authentication.
- recursive 2y agoBut then it mostly ended up getting used for authentication anyway, so maybe it was ok.
- foobazgt 2y agoI can second GP. I have always heard and used authz and authn (pronounced auth-z and auth-n). Bare "auth" typically was used to mean both, but IAM was more clear for that in specific contexts. E.G. you might say someone "authed" to indicate both authentication and authorization, and you might have an IAM team that handles both authentication and authorization. FWIW, I lead an IAM team.
- croes 2y agoOne type and you have a problem. Maybe it's better to use less similar words if it's security related.
- mgkimsal 2y agoHow are those pronounced?
- giaour 2y agoYou pronounce the last letter as a second syllable: authn is "auth-in" and authz is "auth-zee" (probably "auth-zed" in non-American English).
- erik_seaberg 2y agoI've seen https://en.wikipedia.org/wiki/AAA_(computer_security) https://en.wikipedia.org/wiki/AAA_(computer_security) because authentication, authorization, and accounting (audit trails) need to go together so often. You need to know who they really are and whether they're abusing the system.
- croes 2y agoAnd then you someone who uses "auth" for AUTHentication and and authn for AUTHorizatioN. authn and authz are only clear if used as pair.
- selecsosi 2y agoAuthN and AuthZ are appropriate and succinct ways to express the concerns when brevity is required
- croes 2y agoSo one wrong letter or wrong auto complete and we have the wrong meaning. In security, anything that is less prone to error is good, so words that are hard to confuse or misspell are good.
- selecsosi 2y agoWhy would you type the wrong letter when you mean the other one? Authentication means proving what something says it is, authorization is allowing someone to do something. The concepts are different so it's not like a dial you are turning to make a measurement, the terms are for different domains
- deathanatos 2y agoWhile I also agree that authn or authz are perfectly clear, > Why would you type the wrong letter when you mean the other one? Really? Ignorance, laziness, rushing, fatigue, simple mistakes, etc. What I think is worse is more letters doesn't save you. I've had some conversations where it has gone like 2–3 round trips before the other end realizes that "not" means not, and they mean … the other way.
- dathinab 2y agoyes but it's also even more important to be precise and correct which login/permission fail to be login is at best defined as authorization + authentication but things which are in general referred to as login but only provide authorization are not that rare (e.g. you pass a token to a client) and logins which to provide authentication but not authorization exist to (but are rare and you probably could always nitpick them out of existence) Similar the term permission is hugely overloaded due to it's wide usage in more causal most times end user facing documentation. Most times permissions are used in a more generic context, like a user having the permission to do something vs. a request made by a user being authorized to do something. I mean in the end there is no reason not to use login/permission for end-user facing documentations, causal conversations etc. This terms are "good enough" most times. But if you provide a login library or technical documentation for APIs with complex interactions between authentication and authorization then using login/permission just won't cut it. Also for AuthN,AuthZ there is no point to use auto completion and there is very very little chance to mistype them as long as you don't confused them. Luckily this kind of mistakes do not fall under the patterns dyslexia causes (especially if you do the capitalization).
- bradjohnson 2y agoIdentity and permission are often closely related, and usually auth means both. If we replaced auth with permissions and login, I suspect we would still encapsulate the same overarching concept with one of those two words anyway. E.g. use the login module to add permissions to a user or use the permissions module to authenticate.