4 ms·
I don’t really consider making an API call as “logging in”. The term sounds really out of place other than in a few specific contexts.
by 4death4 2y ago
I don’t really consider making an API call as “logging in”. The term sounds really out of place other than in a few specific contexts.
- rwoerz 2y agoIndeed. "Logging in" implies some kind of long lasting session. And logging in conceptually only requires "identification" (e.g. via a username) but not necessarily "authentication" (e.g. via a password)
- nmz 2y agoIdentification is not necessarily via a username, people can identify you via just knowing how you look or your voice, the method doesn't matter.
- Too 2y agoThe term “Identify” is a lot better in this regard. It’s already universally used in IAM, where the other half of the puzzle is also clear and free from ambiguity: “Access”.
- jbverschoor 2y agoAccess doesn’t cover everything though. But identify seems good
- jonplackett 2y agoI think they mean use both - identity in place of login/authenticate and access in place of auth
- jbverschoor 2y agoYeah, but access to me feels like access to records. Not necessarily permissions to do certain actions (in general or to certain records) Iirc, Java or J2EE used “Principal”, which I found super confusing
- lupire 2y agoPrincipal is Identity not access.
- adolph 2y agoAnd the third half, “management” verbalizes the action therein. Also, IAM has a cryptic assertion of ultimate authority: In Hebrew, . . . hayah carries the added weight of representing God himself: Yahweh, “I am.” [0] https://hebraicthought.org/meaning-of-gods-name-i-am-exodus/ https://hebraicthought.org/meaning-of-gods-name-i-am-exodus/
- zer00eyz 2y agoIdentity/identify may or may not have anything to do with Login, or Authentication... KYC (know your customer) are about removing the ambiguity between you user and their identity....
- recursive 2y agoWhat could be a difference between identification and authentication? In my understanding they are completely synonymous. I frequently use an IdP (identity provider) to authenticate for web applications.
- duncan-donuts 2y agoI think authentication is about proof of identity. Identity can mean a lot of things imo. Applications identify me all the time without me giving them any proof of who I am. This happens in meatspace all the time too. People project identity and we make assumptions about what we observe. We don’t necessarily ask them to verify this identify through mutually agreed upon terms.
- zer00eyz 2y agoKnow your customer is something that started in banking and is leaking everywhere. Identity is who you really are. Be that you as an individual or as a corporation.... In the case of your bank they have a copy of your ID, your SSN, for them identity is what established the account and auth lets you work with it.... AWS might know some members of your company (either by corporate or individual card) but might not know your identity (as an individual) and yet you can still authenticate, because you have been authorized by an identified customer. I can transact with crypto as an authenticated user and NOT be identified.
- recursive 2y agoIn some circles "identity" is a term of art. For instance an identity provider maps credentials to user accounts. Those may or may not map to a government-numbered human.
- 2y ago
- asalahli 2y agoIdentification and authentication are different, though. You identify yourself to a website as a specific user (e.g. using a username) and the website in turn authenticates your claim, i.e. verifies that you are in fact the user you claim to be (e.g. using that user's password).
- jagged-chisel 2y agoIMO… To “log in” is to convert the username/password pair (or API key, or whatever) into a smaller token with an expiration. Doesn’t matter of it’s put in a cookie in my browser, held in memory by some other API client, etc. Aside: Why bother even doing that? Because every time you transmit the credential, there’s the possibility of leaking. We would rather leak the token that has an expiration.