Hacker News new | ask | show | jobs
by morshu9001 245 days ago
uuid7 is still guessable though, as the article says. The assumption is that these are internal only PKs.
3 comments

There is a big difference though. Serial keys allow attackers to guess the rate at which data is being added.

UUID7 allows anyone to know the time of creation, but not how many records have been created (approximately) in a particular time frame. It leaks data about the record itself, but not about other records.

Far, far less than sequential Ids, and the random part is some pretty big values numerically... I mean there's billions of possible values for every MS on the generating server... you aren't going to practically "guess" at them.
Guessable with 80 bits of entropy?