-
Notifications
You must be signed in to change notification settings - Fork 19
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
flesh out faq #101
flesh out faq #101
Conversation
divarvel
commented
May 25, 2023
•
edited
Loading
edited
- what is biscuit?
- why is offline attenuation great?
- the crypto is not broken
- can i be fired for choosing biscuit?
- how can i bake delicious biscuits?
Co-authored-by: juliabenisty <80972586+juliabenisty@users.noreply.github.com>
Co-authored-by: juliabenisty <80972586+juliabenisty@users.noreply.github.com>
|
||
Neither the biscuit specification nor the various implementations have been formally audited. The specification itself (more specifically the cryptographic scheme) has been informally audited by experienced cryptographers and the current specification raised no alarms. | ||
|
||
Of course biscuit is a recent piece of tech, which makes it harder to justify than more standard choices like JWT. That being said, biscuit and the patterns it allows have been instrumental in the success of several projects, so it is worth trying it out. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
maybe mention that biscuit builds on experience earned when using systems like JWT, and try to avoid their pitfalls
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
i'll try it out in another PR, i need to think it over a bit first.
Co-authored-by: Geoffroy Couprie <contact@geoffroycouprie.com>