
Sign up to save your podcasts
Or
This podcast on SpiceDB, an open-source authorization system, introduces the concept of authorization distinct from authentication. The speaker explains the difficulties and security risks of building application permissions internally, citing how broken authorization has become a top web security vulnerability. SpiceDB is presented as a solution inspired by Google's internal Zanzibar system, aiming to provide a hyperscale, centralized, and relationship-based access control (ReBAC) model. The presentation highlights how SpiceDB allows for modeling complex permissions and performing efficient checks and lookups
This podcast on SpiceDB, an open-source authorization system, introduces the concept of authorization distinct from authentication. The speaker explains the difficulties and security risks of building application permissions internally, citing how broken authorization has become a top web security vulnerability. SpiceDB is presented as a solution inspired by Google's internal Zanzibar system, aiming to provide a hyperscale, centralized, and relationship-based access control (ReBAC) model. The presentation highlights how SpiceDB allows for modeling complex permissions and performing efficient checks and lookups