Tomas Ekeli · @tomasekeli
764 followers · 3164 posts · Server snabelen.no

maybe i'm getting old, but i feel the recent trend towards with / might be a bad idea.

passwords (with all their problems) are a low-tech thing. depending on the people having access to a high-end device with their keys seems highly rich-tech-bro-in-the-western-world

#passwordless #passkeys #authn

Last updated 1 year ago

Jan <3 :gopher: 🛹 · @rollbrettklauen
4 followers · 137 posts · Server fosstodon.org

that you don’t need an library like ’s fortify. Just host an AuthN provider and implement or .

If you ship a desktop app, you don’t need because the user is authenticated through their login into their computer.

If you ship to a business, they will have an LDAP or OIDC server or will host one when needed.

If you ship an app with online account, you can just host or or pay .

More below:

reddit.com/r/golang/comments/y

#TIL #auth #laravel #oidc #ldap #authn #keycloak #authentic #auth0

Last updated 1 year ago

As we recap our fantastic talks, next up is William Brown @firstyear from @SUSE who walks us through for , showing us their ambiguities, how they work, what their limitations are, and what we need to be thinking about when we implement them.

Another fabulous talk from William.

youtube.com/watch?v=V-7zMIgGO1

#everythingopen #passkeys #web #authn

Last updated 1 year ago

J. Trent Adams · @jtrentadams
124 followers · 123 posts · Server infosec.exchange

Working on a project with non-InfoSec folks I was reminded that not everyone's gotten the message. All the contributors were accessing the collaboration platform with the admin's credentials ('cause it was easier than creating separate accounts).

#sigh #infosec #authn #authz #fail #meme

Last updated 1 year ago

Next in our Speaker Spotlight series, because we know you're all - is @firstyear William Brown, who's presenting:

"Web , and you - the future of "

2023.everythingopen.au/schedul

#everythingopen #nightowls #authn #passkeys #authentication

Last updated 1 year ago

Florian Maury · @x_cli
398 followers · 1610 posts · Server infosec.exchange

Qqn sait où on peut trouver plus d'info sur le protocole en "double anonymat" que le gouv veut déployer en mars pour restreindre l'accès à certains sites, dont les sites porno ?
J'ai vu un schéma et moralement, ça ressemble a du "sous-privacy pass", mais je voudrais bien étudier la spec ou le code.

#cryptography #france #pornography #privacypass #securite #security #authz #authn

Last updated 1 year ago

damienbod · @damienbod
250 followers · 52 posts · Server mastodon.social
Dela 🏳️‍🌈 · @dela
38 followers · 175 posts · Server hachyderm.io

: done
: done
: Time to investigate and

#authn #authz #logging #jaeger #opentelemetry #webdev

Last updated 2 years ago

Joey deVilla 🪗 · @AccordionGuy
742 followers · 477 posts · Server mastodon.cloud

Here’s my first video chat with ChatGPT about authentication, authorization, and building Android and iOS apps that use Auth0/Okta for login. Does ChatGPT gets the answers right? Yes for some, categorically NO for others.

ChatGPT did me a solid, though — it wrote the YouTube description of the video for me. Thanks, ChatGPT! 🤖

youtube.com/watch?v=rfkgdorO-8

#ai #oauth #authentication #authorization #security #chatgpt #cyber #cybersecurity #oidc #authn #login

Last updated 2 years ago

“Remember me” he asks as he checks that little box below the login.

Oh the lies we tell ourselves.

#identity #infosec #authn

Last updated 2 years ago

ath0 · @scottlink
145 followers · 154 posts · Server infosec.exchange

@VidmoOreda @nf3xn The scraper would just be grabbing and parsing the html off the page. API interaction isn't scraping and can require authN/authZ or be wide open. If the API doesn't require authN/authZ, then I don't see how any AUP is enforceable. (I still have a way to go on API security. I'm familiar with the use of OAuth tokens for authZ. I think OIDC can be used instead, which I think uses an OAuth token with a "wrapper" to add authN. Reckon JWT is in play for authN/authZ, as well.)

#api #authn #authz

Last updated 2 years ago

Arthur Lutz (Zenika) · @arthurzenika
295 followers · 291 posts · Server pouet.chapril.org
Solinvictus :verified: · @dminca
36 followers · 922 posts · Server mastodontech.de

Introducing Public Key Cryptography and Web Authentication (WebAuthn)

webauthn.guide

#security #webauthn #authn

Last updated 2 years ago