3 ms·
Indeed, but one could easily argue that 128 bits of entropy aren't sufficient for a good invite token in the first place.
by javawizard 1y ago
Indeed, but one could easily argue that 128 bits of entropy aren't sufficient for a good invite token in the first place.
- pinkgolem 1y agoI am just puzzled why delifue calls something that, as far as I know is pretty standard across the industrie, bad practice
- nesarkvechnep 1y agoBecause it is?
- skrebbel 1y agoNo?
- treve 1y agoThere's 2 cases being discussed. A UUIDv7 is a bad secret, but it's fine for many other ids. If I can guess your user id, it shouldn't really matter because your business logic should prevent me from doing anything with that information. If I can guess your password reset token it's a different story because I don't need anything else beyond that token to do damage.
- tracker1 1y agoBut the random part of a UUIDv7 is 74 bits... larger than a 64-bit integer of random values. Larger than many systems use in total when generating random keys for such things. Likely a larger number of values than the total number of comments here on HN over a couple decades. It's emphatically NOT guessable.
- treve 1y agoI don't think you'll find many recommendations for key lengths under 128 bits / 16 bytes these days.