Engineering
The Composability Test: Five Questions Before Adding a Feature
Arguments about scope are hard to win because both sides are reasonable.
Engineering
Arguments about scope are hard to win because both sides are reasonable.
Engineering
Most teams load test a week before launch.
Engineering
Every identity platform is the sum of about ten decisions, most of which get made in the first six months and none of which get revisited cheaply. They're not implementation details. They're the load-bearing choices that determine what the system can do five years later — and more importantly, what
Engineering
A bank I worked with had a rule: transfers over £10,000 required a second factor.
Engineering
Somewhere in your SAML integration documentation there is probably a sentence like "assertions must be signed and encrypted." Somewhere in a customer's security questionnaire there is a question asking whether you support assertion encryption, and the only commercially viable answer is yes.
Engineering
Identity bugs have a distinctive personality, and it's an unpleasant one.
Engineering
A support ticket, verbatim, from a team I worked with: "User logs out of the admin app, gets redirected to the login page, and is immediately logged back in without entering anything. Only happens on admin.example.com, not app.example.com. Only in Chrome."
Engineering
These three get compared constantly, usually in a table that lists which one uses XML and which one uses JSON. That comparison is technically accurate and almost useless, because it implies the three are alternatives competing for the same job.
Engineering
At 08:47 on a Monday, 4,000 people at one of your customers cannot log in. Every SSO attempt fails with a signature validation error.
Engineering
These two terms get used interchangeably constantly, including by people who work with them daily, and the conflation causes real confusion when it actually matters — like debugging a TLS handshake failure or reviewing a SAML integration. Here's the distinction, and why it exists at all.
Engineering
Every year, another billion credentials leak.
Engineering
Here is a claim you will find on nearly every passkey landing page, including some very good ones: passkeys are phishing-resistant, unphishable, unreusable, and not vulnerable to credential stuffing. All of that is true.