Article may be outdated

This article is 62 days old. Some details may have changed since publication.

Hacker News·4 min read·hard

Authorize, don't authenticate

M
marcua
Authorize, don't authenticate
✦AI Summary

The author argues that users should maintain ownership of their data by hosting it in personal databases rather than relying on traditional application-controlled authentication. The piece introduces a new authorization flow that allows applications to access user-controlled databases without requiring a standard login screen.

Why it matters

This approach challenges the current centralized model of data management, potentially increasing user privacy and data sovereignty in the digital ecosystem.

✦Dive DeeperCreate a free account to unlock

Hold on to your data by keeping it in your own database

The login screen of any web application is the equivalent of that application telling you “In order to access YOUR data in MY database, prove you are who you say you are.” You’re authenticating with the application so that you can have the privilege of giving it your data.

In a previous blog post , I covered the downside to applications controlling your data. An application’s owner can restrict your access to your own data. They can delete the data. They can sell the data to a third party. They might introduce a bug that allows other people to access the data. They might get compromised. Or they can avoid all of this just to modify their policies down the road or see changes in ownership or management.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in