2 ms·
With the external id I get a single layer of obfuscation. If the external id is leaked they still don’t have any data that allows me to make a CC purchase. And
by 2muchcoffeeman 1y ago
With the external id I get a single layer of obfuscation. If the external id is leaked they still don’t have any data that allows me to make a CC purchase. And if you designed it correctly, you could invalidate the id. ie a token that expires.
- 1718627440 1y agoIf the external id represents a single costumer uniquely, it still counts as personal information. That you hand out money by giving one id, but not to another is really arbitrary and doesn't make any sense. Knowing an identifier of another person should not allow you to withdraw money either way.
- 2muchcoffeeman 1y agoBut you can’t hand out money with either value. The external ID is only valid in the system it was generated in. And as I said, you can design it so that the ID expires periodically.
- 1718627440 1y ago> But you can’t hand out money with either value. Then there is no problem using the natural key?