Authentication vs Authorization Explained: Who Are You? vs What Can You Do? | Bits To Billions
Bits To Billions
0:00 / 0:00
Authentication vs Authorization Explained: Who Are You? vs What Can You Do? | Bits To Billions
7 просмотров · 5 дней назад
Bits To Billions
16 подписчиков
7 просмотров · 5 дней назад
Authentication and authorization explained from absolute zero - with real-life
analogies and real code. No prior knowledge assumed.
You are logged in to your company billing site, on your own account. You open one of
your invoices; the address ends in 1042. You change it to 1043 - and a different
company's invoice opens. Nobody broke in. No password was stolen. The system knew
exactly who you were the entire time. It just never asked the second question.
Those are two different questions, answered by different code, in different places,
at different times - and they fail in completely different ways. By the end of this
video you will be able to explain both, and you will know why the second one is the
one that goes wrong.
Every idea lands twice: first a real-life picture so you understand what it is, then
a practical example with real code and real numbers so you understand how it is
actually built. And every analogy has its breaking point stated out loud, so you do
not walk away with the wrong model.
WHAT YOU'LL LEARN
What authentication and authorization actually are, in plain words
Why the web forgets you between requests - and what the standard says
The three kinds of proof: something you know, have, and are
Why a fingerprint is never a factor on its own in current NIST guidance
What multi-factor really means, and why two passwords is not it
Why a good server never stores your password, only a one-way blend
A real bcrypt hash read field by field: method, cost, salt, hash
What salt is for, and why cost is deliberate slowness
Argon2 and why memory is the thing cracking hardware cannot buy
The NIST rules that changed: no forced rotation, no character mixtures
What your browser is actually carrying, and what it is worth if stolen
OWASP's 64-bit rule, the 585-year figure, and why 292 is the honest one
Why a token is encoded and not encrypted - anybody holding it can read it
Why 401 is named Unauthorized but means unauthenticated
Why the HTTP header called Authorization performs authentication
The four permission models: lists, roles, attributes, relationships
Role explosion, and the published case where 10 attributes need 1,024 roles
The asymmetry: authentication once, authorization on every object forever
Google's Zanzibar numbers, and why you authorise next to the data
The one-line SQL bug behind the most common serious flaw in web software
How PostgreSQL row level security makes the check impossible to forget
Why turning that policy on and connecting as the table owner does nothing
CHAPTERS
00:00 Intro
01:42 Two words, two questions
03:15 The server forgets you
04:46 Proving who you are
06:33 Nobody stores your password
08:40 The receipt you carry
10:54 The words are a mess
12:35 What are you allowed to do?
14:51 Once, versus forever
16:47 The bug that is one line
18:37 Make it impossible to forget
20:23 Common mistakes
21:42 Recap
SOURCES
RFC 9110 HTTP Semantics (IETF, June 2022) - statelessness, and the 401 definition
RFC 7235 HTTP/1.1 Authentication (IETF) - the Authorization header authenticates
RFC 6750 OAuth 2.0 Bearer Token Usage - the 401 vs 403 split
RFC 6749 The OAuth 2.0 Authorization Framework (IETF, October 2012)
NIST SP 800-63B-4 Digital Identity Guidelines (final, July 2025)
OWASP Password Storage Cheat Sheet - Argon2id, bcrypt and PBKDF2 parameters
OWASP Session Management Cheat Sheet - session entropy and the 585-year figure
CWE-639 Authorization Bypass Through User-Controlled Key (MITRE)
2025 CWE Top 25 - CWE-862 Missing Authorization at #4
OWASP Top 10 - Broken Access Control at A01 in both the 2021 and 2025 editions
Kuhn, Coyne & Weil, Adding Attributes to RBAC, IEEE Computer, June 2010
Pang et al., Zanzibar: Google's Consistent, Global Authorization System, USENIX ATC 2019
Cittadini et al., BeyondCorp Part III: The Access Proxy, USENIX ;login:, Winter 2016
Saltzer & Schroeder, The Protection of Information in Computer Systems, Proc. IEEE, 1975
US SEC administrative order 34-92176 (June 2021) and the NYDFS settlement (November 2023)
PostgreSQL documentation - CREATE POLICY and Row Security Policies
Every load-bearing number, date and claim in this video was checked against a primary source before recording.
These are standalone explainers - one topic, one video, always from zero. Subscribe and you'll get the next one.
#authentication #authorization #websecurity #softwareengineering #coding