4 ms·
> (or worse: using a shared-secret for signing tokens instead of asymmetric cryptography, ugh) What’s so terrible about that? Several security engineers I trus
by ramchip 2y ago
> (or worse: using a shared-secret for signing tokens instead of asymmetric cryptography, ugh)
What’s so terrible about that? Several security engineers I trust favor designs with symmetric crypto, e.g. Fly.io https://fly.io/blog/macaroons-escalated-quickly/ https://fly.io/blog/macaroons-escalated-quickly/ and Facebook https://eprint.iacr.org/2018/413.pdf https://eprint.iacr.org/2018/413.pdf
- ak217 2y agoIt limits your ability to compartmentalize your infrastructure, establish security perimeters, and provide defense-in-depth against vulnerabilities in your dependencies.