» Tag
authentication
5 posts«August 2026
IETF Publishes Best Current Practice for Cross-Device Flow Security
New IETF BCP (RFC 10027) details cross-device flow security threats, real-world exploits, and mitigation strategies for engineers and architects.
Why Most Security Keys Ship Without a PIN
Most FIDO2 security keys ship without a PIN. How does this impact user security?
Presigned URLs: A Security Vulnerability?
Presigned URLs are viewed as a security vulnerability. Systems like Tigris face risks with this feature.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comWebAuthn Level 3: New Features for Passkeys
WebAuthn Level 3 introduces passkey support and improved usability for developers.
Three New Attack Techniques Targeting Google Passkey System Revealed
Three new attack techniques targeting passkey credentials in Google Password Manager have been revealed, highlighting significant security risks.