Engineering
Seven Identity Bugs Every Team Eventually Ships
Identity bugs have a distinctive personality, and it's an unpleasant one.
Engineering
Identity bugs have a distinctive personality, and it's an unpleasant one.
Engineering
A support ticket, verbatim, from a team I worked with: "User logs out of the admin app, gets redirected to the login page, and is immediately logged back in without entering anything. Only happens on admin.example.com, not app.example.com. Only in Chrome."
Engineering
These three get compared constantly, usually in a table that lists which one uses XML and which one uses JSON. That comparison is technically accurate and almost useless, because it implies the three are alternatives competing for the same job.
Engineering
At 08:47 on a Monday, 4,000 people at one of your customers cannot log in. Every SSO attempt fails with a signature validation error.
Engineering
These two terms get used interchangeably constantly, including by people who work with them daily, and the conflation causes real confusion when it actually matters — like debugging a TLS handshake failure or reviewing a SAML integration. Here's the distinction, and why it exists at all.
Engineering
Every year, another billion credentials leak.
Engineering
Here is a claim you will find on nearly every passkey landing page, including some very good ones: passkeys are phishing-resistant, unphishable, unreusable, and not vulnerable to credential stuffing. All of that is true.
Engineering
There's a code pattern that appears in production systems everywhere, written by competent engineers, that reliably produces a complete authentication bypass:
Engineering
OAuth isn't one flow, it's a small family of them, and picking the wrong one for your application type is one of the most common ways teams end up with a security gap they didn't know they'd introduced. The right flow depends almost entirely on one question: what kind of application is asking for ac
Engineering
Ask a developer who's spent a frustrating afternoon debugging a redirect URI mismatch what they think of OAuth, and you'll usually get some version of the same complaint: too many parameters, too many steps, too many ways to get it subtly wrong. State, nonce, PKCE, scopes, grant types, token types,
Engineering
Most explanations of OAuth start with a sequence diagram full of boxes labeled "Resource Owner" and "Authorization Server," which is accurate and almost useless if you're trying to build an intuition for what's actually happening. Here's a version that starts with something everyone already understa
Engineering
Every OAuth deployment makes a decision about how clients prove who they are, and in most deployments the decision was made by whichever tutorial the first integrating engineer found. That's how you end up with client_secret_post everywhere, a spreadsheet of secrets, and a compliance finding four ye