Перейти к содержимому

Authentication vs Authorization Explained: Who Are You? vs What Can You Do? | Bits To Billions

Bits To Billions

0:00 / 0:00

Authentication vs Authorization Explained: Who Are You? vs What Can You Do? | Bits To Billions

7 просмотров · 5 дней назад
Bits To Billions
16 подписчиков
7 просмотров · 5 дней назад
Authentication and authorization explained from absolute zero - with real-life analogies and real code. No prior knowledge assumed. You are logged in to your company billing site, on your own account. You open one of your invoices; the address ends in 1042. You change it to 1043 - and a different company's invoice opens. Nobody broke in. No password was stolen. The system knew exactly who you were the entire time. It just never asked the second question. Those are two different questions, answered by different code, in different places, at different times - and they fail in completely different ways. By the end of this video you will be able to explain both, and you will know why the second one is the one that goes wrong. Every idea lands twice: first a real-life picture so you understand what it is, then a practical example with real code and real numbers so you understand how it is actually built. And every analogy has its breaking point stated out loud, so you do not walk away with the wrong model. WHAT YOU'LL LEARN What authentication and authorization actually are, in plain words Why the web forgets you between requests - and what the standard says The three kinds of proof: something you know, have, and are Why a fingerprint is never a factor on its own in current NIST guidance What multi-factor really means, and why two passwords is not it Why a good server never stores your password, only a one-way blend A real bcrypt hash read field by field: method, cost, salt, hash What salt is for, and why cost is deliberate slowness Argon2 and why memory is the thing cracking hardware cannot buy The NIST rules that changed: no forced rotation, no character mixtures What your browser is actually carrying, and what it is worth if stolen OWASP's 64-bit rule, the 585-year figure, and why 292 is the honest one Why a token is encoded and not encrypted - anybody holding it can read it Why 401 is named Unauthorized but means unauthenticated Why the HTTP header called Authorization performs authentication The four permission models: lists, roles, attributes, relationships Role explosion, and the published case where 10 attributes need 1,024 roles The asymmetry: authentication once, authorization on every object forever Google's Zanzibar numbers, and why you authorise next to the data The one-line SQL bug behind the most common serious flaw in web software How PostgreSQL row level security makes the check impossible to forget Why turning that policy on and connecting as the table owner does nothing CHAPTERS 00:00 Intro 01:42 Two words, two questions 03:15 The server forgets you 04:46 Proving who you are 06:33 Nobody stores your password 08:40 The receipt you carry 10:54 The words are a mess 12:35 What are you allowed to do? 14:51 Once, versus forever 16:47 The bug that is one line 18:37 Make it impossible to forget 20:23 Common mistakes 21:42 Recap SOURCES RFC 9110 HTTP Semantics (IETF, June 2022) - statelessness, and the 401 definition RFC 7235 HTTP/1.1 Authentication (IETF) - the Authorization header authenticates RFC 6750 OAuth 2.0 Bearer Token Usage - the 401 vs 403 split RFC 6749 The OAuth 2.0 Authorization Framework (IETF, October 2012) NIST SP 800-63B-4 Digital Identity Guidelines (final, July 2025) OWASP Password Storage Cheat Sheet - Argon2id, bcrypt and PBKDF2 parameters OWASP Session Management Cheat Sheet - session entropy and the 585-year figure CWE-639 Authorization Bypass Through User-Controlled Key (MITRE) 2025 CWE Top 25 - CWE-862 Missing Authorization at #4 OWASP Top 10 - Broken Access Control at A01 in both the 2021 and 2025 editions Kuhn, Coyne & Weil, Adding Attributes to RBAC, IEEE Computer, June 2010 Pang et al., Zanzibar: Google's Consistent, Global Authorization System, USENIX ATC 2019 Cittadini et al., BeyondCorp Part III: The Access Proxy, USENIX ;login:, Winter 2016 Saltzer & Schroeder, The Protection of Information in Computer Systems, Proc. IEEE, 1975 US SEC administrative order 34-92176 (June 2021) and the NYDFS settlement (November 2023) PostgreSQL documentation - CREATE POLICY and Row Security Policies Every load-bearing number, date and claim in this video was checked against a primary source before recording. These are standalone explainers - one topic, one video, always from zero. Subscribe and you'll get the next one. #authentication #authorization #websecurity #softwareengineering #coding