Tech & AI News
Hacker News

Authentication Is Largely Solved. Authorization Isn't

The book *Authorization in Action* argues that while authentication—proved by passkeys and FIDO—has reached maturity, authorization remains ad-hoc, scattered across application code, and poorly standardized. It explains why fine-grained, externalized policies such as Amazon Verified Permissions and the Cedar language are essential for secure, usable systems, especially as AI agents increase demand for robust access control.