|
|
|
|
|
by headmelted
2476 days ago
|
|
I would have phrased it differently, but I see the parent's point. You don't roll your own security. You just don't do it. There are far too many variables that you can screw up, and anything you come up with isn't realistically going to go through nearly as much battle-testing as a ready-made solution (either upfront or on an ongoing basis). > Custom built auth isn't as scary as you make it to be Custom-built auth should be scary. Anyone who's worked on the security story for a popular framework will tell you that. If you're not scared by it I'd have to assume you're either not seeing large swathes of the problem space or you're a genius. |
|
Don't write your own crypto. That's great advice. The idea that everyone's auth needs are so standard they fit for every app just hasn't been realistic in my experience.