Unique identifiers are the invisible backbone of modern software. Every database record, every API request, every distributed message, every file in cloud storage — they all need unique identifiers. But not all unique IDs are created equal. The choice between UUID versions, the method of generation, and where generation happens all have significant implications for security, performance, and privacy.
UUID Versions Explained
The UUID standard (RFC 4122) defines five versions, each with different properties:
- UUID v1: Time-based, incorporating the host machine's MAC address and a timestamp. Unique and sortable, but leaks hardware identity. Never use v1 for anything security-sensitive.
- UUID v3: Name-based, generated from a namespace UUID and a name using MD5 hashing. Deterministic — the same inputs always produce the same UUID. Useful for generating consistent IDs from known inputs.
- UUID v4: Random-based, the most commonly used version. Generated from random or pseudo-random bytes. Provides no guarantees of uniqueness beyond the statistical improbability of collision (approximately 1 in 2.71 × 10^18).
- UUID v5: Name-based, similar to v3 but using SHA-1 hashing instead of MD5. Preferred over v3 when deterministic generation is needed.
Security Implications
Predictable identifiers are a serious security vulnerability. If an attacker can guess the IDs of other users' resources, they can perform enumeration attacks — systematically accessing resources by iterating through likely IDs. This is why sequential integer IDs are dangerous in public-facing APIs.
UUID v4 addresses this by providing 122 bits of randomness, making enumeration computationally infeasible. However, if your random number generator is weak (as some older browsers' Math.random() implementations were), the entropy is reduced and predictability increases. Always use crypto.getRandomValues() for security-sensitive UUID generation.
Privacy Considerations
Generating UUIDs on an external server exposes information about your application: the volume of ID generation (usage patterns), the timing of requests, and potentially the context in which IDs are used. Client-side UUID generation using a tool like Formatho's UUID Generator eliminates this exposure entirely.
Generating UUIDs in JavaScript
Modern JavaScript makes secure UUID generation straightforward. The Web Crypto API provides crypto.randomUUID() in modern browsers, which generates v4 UUIDs using a cryptographically secure random number generator. For Node.js, the crypto module provides the same functionality.
For environments that do not support crypto.randomUUID(), you can implement v4 generation using crypto.getRandomValues() with proper bit manipulation to conform to the RFC 4122 specification.
ULIDs: The Modern Alternative
Universally Unique Lexicographically Sortable Identifiers (ULIDs) combine the uniqueness of UUIDs with time-based sortability. They are 26-character strings that encode a timestamp and random component, making them both unique and sortable by creation time. For many use cases, ULIDs are a better choice than UUIDs.