Engineering
Configuration Beats Customization: An Entropy Argument
The first if (customer == "ACME") is free.
Engineering
The first if (customer == "ACME") is free.
Engineering
You won the argument. It took two quarters, a written proposal, and a meeting where you walked the security team through the research: rotation trains users to increment a digit, it drives helpdesk volume, it conditions people to comply with unexpected "change your password now" prompts. NIST agrees
Engineering
The requirement arrives from your security team looking entirely reasonable. Users shouldn't be allowed to set a password that's already appeared in a breach.
Engineering
Look at the feature list of any major identity platform from ten years ago and compare it to today. Authentication, federation, tokens, sessions — all still there. But now there's also bot detection. IP reputation scoring. Rate limiting. Geo-blocking. Threat intelligence feeds. Fraud signals. CAPTCH
Engineering
The first time I explained our identity architecture to a platform engineer, I was three diagrams in and losing them. Then I said "it's basically Kubernetes," and they got the entire thing in about fifteen seconds.
Engineering
Here's a bug report that should feel familiar:
Engineering
Every developer can build a login page. Give a junior engineer a weekend and a copy of bcrypt and they'll produce something that works: a form, a database check, a session cookie. It'll even be secure enough for a side project. The gap between that and a login system that survives enterprise custome
Engineering
Every engineer can recite the distinction. Authentication is who you are; authorization is what you're allowed to do. It takes about four seconds to explain and everyone nods.
Engineering
Authentication is one of the few parts of a software system that becomes more expensive the longer you own it. Unlike business features, it never reaches a point where it's "done." New attack vectors emerge. New standards appear. Enterprise customers demand federation. Compliance teams ask for stron
Engineering
The incident review started well. Someone had pulled 4,200 customer records out of the analytics API in eleven minutes on a Tuesday afternoon, and we had beautiful logs — every read, timestamped to the millisecond, with the record ID, the fields returned, the source IP, and the actor.
Engineering
There is a moment in most WebAuthn implementations when someone reads the spec, discovers attestation, and gets excited. It sounds like exactly what a security-conscious team wants: cryptographic proof of what kind of authenticator the user registered. Not a claim, not a user-agent string — a signat
Engineering
You buy a television. You open the YouTube app. It shows you a URL and eight characters — BQDJ-MXWP — and asks you to type them into your phone.