logoalt Hacker News

mcpherrinmyesterday at 8:04 PM2 repliesview on HN

There is no username in ACME besides the account URI, so the UUID you’re suggesting isn’t needed. The account uri themselves just have a number (db primary key).

If you’re worried about correlating between domains, then yes just make multiple accounts.

There is an email field in ACME account registration but we don’t persist that since we dropped sending expiry emails.


Replies

9devyesterday at 10:25 PM

It’s still a valid point IMHO - why not just use the public key directly? It seems like the account URI just adds problems instead of resolving any.

show 1 reply
glzone1yesterday at 10:27 PM

Interesting.

I didn't realize the email field wasn't persisted. I assumed it could be used in some type of account recovery scenario.