If something is fast, it moves quickly or not at all. Cocktails can be garnished, but so can wages. Sales or trade of a product could be sanctioned by one country, but sanctioned by another.
I generally think it is a good thing to communicate clearly. Sometimes that means using words differently to explain something. Other times, that means using words the same way as others. I think this is a case of the latter.
Also, I think the idea of "native speaker" is a bit of a red flag. There are plenty of people that speak English from birth but are utterly unintelligible, and there are plenty of people that speak English as a second language who speak more clearly than those.
Garnishment of wages is garnisheeing, though here I'll agree "garnishing" seems to be acceptable too.
Oversight is a less ambiguous example of a single-word contranym.
Edited to add: Sticking with the context of food, "fasting from food" contradicts someone being a "fast eater."
When I'm at a restaurant and I like everyone I see, I order something "off the menu".
It is, unfortunately, possible for more than one thing to be bad at a time.
I assume you mean “red herring”. Red flag just means a sign that something is wrong.
It’s already universally used in IAM, where the other half of the puzzle is also clear and free from ambiguity: “Access”.
Iirc, Java or J2EE used “Principal”, which I found super confusing
Also, IAM has a cryptic assertion of ultimate authority: In Hebrew, . . . hayah carries the added weight of representing God himself: Yahweh, “I am.” [0]
https://hebraicthought.org/meaning-of-gods-name-i-am-exodus/
KYC (know your customer) are about removing the ambiguity between you user and their identity....
Identity is who you really are. Be that you as an individual or as a corporation.... In the case of your bank they have a copy of your ID, your SSN, for them identity is what established the account and auth lets you work with it.... AWS might know some members of your company (either by corporate or individual card) but might not know your identity (as an individual) and yet you can still authenticate, because you have been authorized by an identified customer. I can transact with crypto as an authenticated user and NOT be identified.
To “log in” is to convert the username/password pair (or API key, or whatever) into a smaller token with an expiration. Doesn’t matter of it’s put in a cookie in my browser, held in memory by some other API client, etc.
Aside: Why bother even doing that? Because every time you transmit the credential, there’s the possibility of leaking. We would rather leak the token that has an expiration.
As a dev you're either building or hooking up to either or both of them. And you know what each requires you to build / hook up to.
As a user, you just care "I put my login/password/api key here, and I get the capability to do several things in that webpage/service/etc". Both auth and the other auth are handed for you.
And if the other dev made an error and confused authorization and authentication you have a problem.
Stupider mistakes have been made and it is a sign of overconfidence if you think you are immune to them.
Yes, primarily I've heard that it is to be avoided in technical discussions...
Hence the confusion and ambiguous shorthand "auth". You auth and gets everything. You fail to auth and you don't have access. That covers ~80% of any authentication-authorization-accounting systems use cases, and that allows people to be care-free about differences.
What does the "auth" module ?
“Permission” and “persistence” have the same prefix but entirely different semantics. They also occur more commonly in everyday life.
AuthN and AuthZ are similar in in spelling, appear in similar contexts, and are less colloquial, making the distinction a lot less clear.
There’s a reason many junior devs use them interchangeably without knowing better.
I think the reason junior devs get them confused is that many junior devs are never taught anything about either in school. But then you just tell the junior dev that they mean different things and in my experience they only need to be told that once.
Ultimately I think it’s fine to use vocabulary.
__________
[1] Derived from the signing of a ship's logbook³ when coming aboard.
[2] A few decades ago.
[3] The logbook originally⁴ recorded navigational data and is named for instruments measuring speed through water⁵, of which the simplest is literally throwing roped wooden logs off the stern and counting the knots on the line paying out per interval⁶.
[4] Doubtless some bright-eyed young hornblower with a glittering future career as an admiralty archivist realised that log-structured records could be generalised usefully to all timestamped event and measurement capture, which is why your syslog is full of crap.
[5] Consequently any vessel, maritime or otherwise, measures its speed through the medium in knots. The Enterprise NCC-1701-D, for example, tops out ca.146 megaknots under impulse engine.
[6] It follows by transitive etymology that you may use the term "knots" to edify and delight your colleagues when referring to the rate of creation of user sessions.
> “Authorization” comes from “auctor” in Latin, meaning “leader” or “author”
This is a problem with only one solution: continue to improve one's skill with the language. You can't solve this by choosing different terms, because then something else will be the "this is confusing to non-native speakers" hangup. You can whack those moles until the day you die and you'll never get them all.
Why would we choose "login" - which is more of a special case than the norm to describe something we already have a precise term for?
Related words for related concepts is very normal, and if you are a professional in this space it's the least we can do to recognize the difference. We aren't astronauts, we have the time to figure it out.
Language learners already learned a second language, they have the skills to figure this out. At least it's not a homonym.
https://www.google.com/search?q=most+popular+language+in+the...
but the rest of your point is dead on.
https://www.visualcapitalist.com/top-languages-spoken-in-the...
English is not the most popular 1st spoken language, but it is the most spoken language overall.
What's the problem of telling apart the task of authenticating users from authorizing their access?
There's already identification and authorization (IAM) which is mostly a backronym.
This way, if someone says "Oh yeah we have an auth module on this site" you don't need to immediately disambiguate the statement.
But then "auth" itself is ambiguous. So it might make sense to get rid of the lot. "Identification" is a good word for the first. Perhaps "Permissions" for the second?
authz -> perm
So much clearer.
From an end user perspective, auth is the problem. Users can’t determine what is login vs permission. If non native speakers can’t handle the distinction, it’s a valuable lesson to learn.