

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- https://xkcd.com/927
Nice work and all regardless
- excellent article, very thorough and nuanced explanation.by bijowo1676
- turns out naming is importantby tuberreact
- > can this subject perform this action on this object?
IMHO, the most elegant method to answer this question is capability based access control. If the subject can utter the action, then it can perform it. And then delegation is the transfer of nouns and verbs to perform the utterances.
by black_knight - Usually vendors fight over terminology because they want to "own" a portion of mindspace. Ultimately authorization is a programming problem, and people have devised very complicated declarative solutions like Google Zanzibar to avoid biting the bullet.by fmajid
- Unclosable cookie banner. Top notch website engineering.
- Are you fixing it at the IETF and RFC level, or is this just another way to say "BUY OUR SHIT AND IT TOTALLLY SOLVES EVERYTHING!!!!11"by nekusar
- I love how the OIDC standard is littered with “authentication identity token code id cookie identifier” and many subtle variations of homonyms in slightly different combinations and orders.
I’m sure someone thought it all made perfect sense.
Probably someone who never confuses “empathy” and “sympathy” while also carefully distinguishing between “should” and “ought”.
by jiggawatts