Software Engineering Radio - the podcast for professional software developers cover image

Software Engineering Radio - the podcast for professional software developers

SE Radio 664: Emre Baran and Alex Olivier on Stateless Decoupled Authorization Frameworks

Apr 15, 2025
Emre Baran, CEO of Cerbos and veteran in B2B and B2C products, teams up with Alex Olivier, CPO of Cerbos with a diverse tech background, to explore stateless decoupled authorization frameworks. They clarify key terms and address the challenges and benefits of these systems. A deep dive into Cerbos showcases its advantages over Open Policy Agent. The duo discusses the intricacies of applying YAML for policy management and the critical role of audit logs in compliance. They wrap up with insights into emerging trends in authorization.
51:54

Podcast summary created with Snipd AI

Quick takeaways

  • Understanding the distinction between authentication and authorization is crucial for implementing effective security measures within software systems.
  • Decoupled authorization allows centralized management of access controls, enhancing scalability and simplifying updates while reducing code complexity.

Deep dives

Understanding Authorization vs. Authentication

Authorization is often misunderstood as being synonymous with authentication, but it plays a crucially different role in software systems. Authentication is the process of verifying a user's identity, confirming who they are, while authorization determines what actions a user can perform based on their identity. For example, gaining entry to a secure location requires authentication to prove one's identity, but authorization decides if the authenticated person is allowed access based on their credentials—much like needing the correct visa to enter a country. It's essential to grasp this distinction for implementing effective security measures within applications.

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner