3 ms·
For me as a non-native English speaker, "authorize" and "authenticate" are always pretty unclear as to what exactly they mean in a security context. I don't use
by OvbiousError 2y ago
For me as a non-native English speaker, "authorize" and "authenticate" are always pretty unclear as to what exactly they mean in a security context. I don't use it enough for it to stick. I'll actually try to remember "login" and "permissions" as shorthand for getting a feel of what they are. And yes, I've never dug deep in security code/systems, but doesn't that make this even more of a problem instead of less. I should be able to understand what these concepts by themselves want to achieve without having a deep understanding of the technical details or coming into contact with it on a regular basis.
- oreilles 2y agoThink of it in a real life context instead of a software context. Let's say you want to go inside a building and there's a bouncer at the entry. By presenting him your ID, he'll be able to authenticate you (determine who you are). Only then, will he decide to authorize you in, or not - depending of your right to do so.
- deanishe 2y agoThe problem here, I think, is the words, not the concepts. Like remembering when it's spelled "stationary" and when "stationery". "Still" and "paper" are easier to remember.
- kaashif 2y agoStationery means more than just paper. I don't think there are any good synonyms for stationery, it's the only word with that exact meaning. Same problem when someone wants to substitute "login" for "authenticate" - not synonyms.
- barrkel 2y agoThe problem is the similarity of the words, not understanding the concepts.
- Control8894 2y agoIs it? Or is the problem the similarity of the concepts?
- numpad0 2y agoimo it's stupid notion that authentication and authorizations are completely different concepts that were infuriatingly given similar spellings. We give oranges and apples those distinct sounds, while giving blueberries and strawberries very similar names. It's just makes no sense that we should change the latter two so no one mixes them up trying to sprinkle some on yogurt.
- barrkel 2y agoThey're so unclear that HTTP error codes got them confused. 401 Unauthorized usually actually means Unauthenticated, while 403 Forbidden means Unauthorized. I'm a native speaker and I need to pause for a few hundred milliseconds just to be sure I'm using the right one in a sentence.
- Jensson 2y ago> Unauthorized usually actually means Unauthenticated What does "unauthenticated" even mean here? You aren't logged in, not logged in isn't a state of "unauthenticated", you haven't given any credentials meaning currently you don't have any authority, so unauthorized makes sense. You can have several sets of credentials and switch between them, not giving them any isn't being in an unauthenticated state its a different thing, and using "unauthorized" in that case makes sense.
- Control8894 2y ago> What does "unauthenticated" even mean here? That you're not logged in. > You aren't logged in, not logged in isn't a state of "unauthenticated" What? Yes it is. > you haven't given any credentials meaning currently you don't have any authority, so unauthorized makes sense Ok? Yes, if you are unauthenticated (and authentication is required), then you are also unauthorized. However, the error code is not communicating that you are unauthorized; it is communicating that you need to authenticate, thus unauthenticated is more appropriate. > You can have several sets of credentials and switch between them Ok? > not giving them any isn't being in an unauthenticated state its a different thing That is exactly what being in an unauthenticated state means. What would you define to be an unauthenticated state otherwise?
- RiverCrochet 2y agoWhile we're at it, let's change 404 from "file not found" to "nothing here." The stream thrown back at you in response to an HTTP request is often not really a file.
- dbsmith83 2y ago
- clwg 2y agoI think of them like this: Authentication is the act of verifying that you are who you say you are, generally with something you know (password) and ideally with something you have (token, authenticator app, etc.). This lets you log in. Once you log in, you are granted authorization for certain tasks. This could be rights to an individual record or column, or it could be administrative privileges within an app. It's not involved in determining who you say you are; it authorizes you to access things based on who you are (from the act of authenticating). That's the way I understand those two terms and their practical applications.