Authorize, don't authenticate

The author argues that users should maintain ownership of their data by hosting it in personal databases rather than relying on traditional application-controlled authentication. The piece introduces a new authorization flow that allows applications to access user-controlled databases without requiring a standard login screen.
Why it matters
This approach challenges the current centralized model of data management, potentially increasing user privacy and data sovereignty in the digital ecosystem.
Hold on to your data by keeping it in your own database
The login screen of any web application is the equivalent of that application telling you “In order to access YOUR data in MY database, prove you are who you say you are.” You’re authenticating with the application so that you can have the privilege of giving it your data.
In a previous blog post , I covered the downside to applications controlling your data. An application’s owner can restrict your access to your own data. They can delete the data. They can sell the data to a third party. They might introduce a bug that allows other people to access the data. They might get compromised. Or they can avoid all of this just to modify their policies down the road or see changes in ownership or management.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in