» Tag
identity
10 postsSAML Replay Flaw: Signed Assertion, Unsigned Response Envelope
SAML's InResponseTo field is unsigned and strippable, letting attackers bypass replay protection; the fix is binding checks to the signed assertion ID.
OIDC MFA Bypass: How One URL Parameter Skipped the Second Factor
An OIDC login flow let attackers skip MFA by editing a return URL; the fix moves enforcement from the login page to the token-issuing endpoint.
PassControl: Secure Your API Keys from AI Agents
PassControl offers a credential gateway to secure API keys from AI agents.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comThe Agent Security Stack: Transport, Identity, Policy, Runtime
The agent security stack addresses transport, identity, and policy layers, providing crucial insights for engineers.
Leaving Auth0: What Really Migrates and What You Won't Get
Learn about the challenges of leaving Auth0 and how Authagonal simplifies migration.
An AI Agent at the Border: Implications for the Future
Insights on AI agents' document verification and the impact of regulations.
Proof of Human: A New Way to Verify Real Humans Online
CAPTCHA and phone verification no longer stop bots. The team behind World ID explains how to verify unique humans online without ever revealing who they are.
Securing API Connections in Azure Logic Apps Standard
Learn how to secure API connections in Azure Logic Apps Standard using access policies and managed identities.
Building on ATProto: Opportunities and Challenges
Bluesky's Atmosphere Protocol offers opportunities for developers, yet limitations exist in privacy and data control.
Building a Confidential Cross-Chain Identity Protocol with Oasis Sapphire
Create a confidential cross-chain identity protocol with Oasis Sapphire. Manage user data securely.