Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The industry has used “authz” and “authn” to disambiguate for decades.


I’ve been working in this industry for decades and this is the first time I made that connection…


I can second GP.

I have always heard and used authz and authn (pronounced auth-z and auth-n). Bare "auth" typically was used to mean both, but IAM was more clear for that in specific contexts. E.G. you might say someone "authed" to indicate both authentication and authorization, and you might have an IAM team that handles both authentication and authorization.

FWIW, I lead an IAM team.


The distinction was already present in Apache2 configs in early 2000's, although there authentication was "auth", and "authorisation" was authz.

Real travesty came from OAuth. A system designed to handle authorisation was named after the term for authentication.


But then it mostly ended up getting used for authentication anyway, so maybe it was ok.


you're not alone.


I've seen https://en.wikipedia.org/wiki/AAA_(computer_security) because authentication, authorization, and accounting (audit trails) need to go together so often. You need to know who they really are and whether they're abusing the system.


One type and you have a problem.

Maybe it's better to use less similar words if it's security related.


And then you someone who uses "auth" for AUTHentication and and authn for AUTHorizatioN.

authn and authz are only clear if used as pair.


How are those pronounced?


You pronounce the last letter as a second syllable: authn is "auth-in" and authz is "auth-zee" (probably "auth-zed" in non-American English).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: