Biscuit 3.0
biscuitsec.org
biscuitsec.org
Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforcement based on a logic language.
Seems like an elegant replacement for use cases where people commonly reach for JWTs.
But also PASETO is an unopinionated token format with strong security guarantees from using modern cryptographic algorithms.
Edit: Looks like the ParagonIE website is returning 502s right now. Here's the archive: https://web.archive.org/web/20230123041631/https://paragonie...
Attenuation does seem cool though.
https://www.youtube.com/watch?v=ZARmgNzP5L0
Jokes aside, it looks really cool.
https://www.clever-cloud.com/blog/engineering/2021/04/12/int...
> That was one of the motivating goals for Biscuit: what if we could attenuate the token, but still be able to verify it with public key cryptography?
Avoid having to share a critical secret across many services.
> With Biscuit, there's another way. Authorization policies can be provided by the verification service, but they can also be carried by the token. The service can specify its policies, and the user can attenuate tokens with their own policies. And they will all be evaluated in the same way, while guaranteeing that the token cannot get more rights with user policies. So from an initial token, an entire parallel authorization design can be developed that will still be compatible with the original one.
> The reference implementation of rust has been released, will full support for the latest spec additions
I thought this was the reference implementation of Rust. That confused me and so I left.
French Macaroons.... they're on another level compared to what the English and Americans do (fresh, in France - in the UK and NL they've been disappointing).
I think the lack of real-life examples Biscuit's power and usefulness is the missing piece in the docs. Because they are a building block often used in proprietary systems, people can't even imagine what they could be used for.
Edit: Seems my guess was right:
> But it does a lot more! It supports offline attenuation (like Macaroons): from a Biscuit token, you can create a new one with more restrictions, without communicating with the service that created the token.
Here’s their example of implementing role-based access control: https://www.biscuitsec.org/docs/guides/rbac/