JusticeTech System
Open in Telegram
Learn to learn before you teach
Show moreThe country is not specifiedThe category is not specified
225
Subscribers
-124 hours
-27 days
-16630 days
Posts Archive
Ayo and Nameless actually did well with their verdict i commend their courage
Y'all are correct to some extent the only issue is that both of you didn't not thoroughly considered what the question is actually point at
The Answer to the question is SOCIAL ENGINEERING
If you don't know what that means kindly use /research function on chatra she will help you
It's a very simple and direct question if all those 3 layers are on point how then did the user get access to other user's data
Though it might be a little bit tricky but it's basic
Note that you don't have anything to prove to anyone be responsible for your actions
Now let me ask this question again base on what you learnt so far now attempt 👇
Attempt this question if you are really a developer
Your app has Authentication
Your app has Authorization
Your app has Encryption
A user still get access to other user's data
What did you miss?
Be genuine with your answer it makes you more solid even when you fail it
SUMMARY
Imagine a high-security corporate building:
1. Authentication: You show your ID card at the front desk. The guard checks the database and confirms you are an employee. (Identity verified).
2. Authorization: You take the elevator to the 5th floor and try to open the server room door. Your keycard flashes red. You are an employee, but you aren't an IT Admin. (Access denied).
3. Encryption: The IT Admin who is allowed in the server room sends a confidential file to the CEO. The file is locked in a secure, armored digital briefcase. Even if a thief intercepts the briefcase in the mail, they can't open it without the digital combination. (Data protected).
3. Encryption
While Authentication and Authorization control access, Encryption protects the data itself.
It is the process of converting readable information (plaintext) into an unreadable format (ciphertext) so that even if a hacker intercepts it, they cannot understand it.
Imagine a user in a Telegram group types the command /ban @spammer
1. Authentication: Telegram tells your bot who sent the message (User ID: 987654).
2. Authorization: Your bot checks the database: *Is User 987654 an administrator in this specific group?
If Yes: The bot executes the ban.
If No: The bot replies, "You do not have permission to use this command."
Even though the user is authenticated (Telegram knows they are a real Telegram user), they are not authorized to perform administrative actions.
Authorization
Authorization system what resources or actions you are permitted to access
You can be authenticated and still be denied access to some certain features
So Authorization always ask for "What you are allowed to do"
I believe y'all understand this clearly like this
I could continue to break this down bit by bit but then let just continue
Let's stop there on Authentication
3. Validation: in this case if the evidence dropped matches against it secure database, the system established a session or better still issue a proof of identity
2. Verification: in this case the system checks the provided evidence against its secure database
There's more to this verification but let's pass for now
Process of Authentication
1. Identification: Here the user claim an identity for instance providing a username or password or even presenting an API Token
There are 3 or 4 major process to take during Authentication since it ensures that the entity try to access the system is exactly who they claim to be
I can only remember but if i can cache it i will include the 4th one
Now let's continue
Authentication always ask a question and that is "Who are you" your ability to remember this will help you in this line of Authentication
Let me proceed
