DPoP: The Missing Security Layer in OAuth2 and OID4VCI
OAuth2 has long suffered from a fundamental weakness: bearer tokens.
Read article: DPoP: The Missing Security Layer in OAuth2 and OID4VCINotes on application security, API security, identity, and API management from the field. Articles are also published on Medium. Browse the archive by topic instead — 124 subjects.
OAuth2 has long suffered from a fundamental weakness: bearer tokens.
Read article: DPoP: The Missing Security Layer in OAuth2 and OID4VCIIf you’ve ever read a specification like WebAuthn, DID Core, SD-JWT VC, BBS Signatures, OID4VCI, or OID4VP, you’ve probably encountered references to P-256, secp256k1, Ed25519, or BLS12–381.
Read article: Elliptic Curve Groups: The Mathematical Engine Behind Modern Digital IdentityWhen we think about algorithms, we often imagine a computer executing a series of instructions:
Read article: Discrete Algorithms: The Mathematics of Decisions, Networks, and Digital IntelligenceModern technology runs on mathematics that most people never see.
Read article: Finite Fields: The Mathematics Behind Cryptography, Error Correction, and Digital TrustOr, how AI Is Changing Mathematics
Read article: The Future of Mathematics: AI’s Impact on the FieldThe first thing people do after deploying a Large Language Model (LLM) is ask it to write a poem.
Read article: Model Governance: Congratulations, You’ve Hired the Smartest Intern in HistoryThere is a recurring problem in the Verifiable Credentials world.
Read article: SD-JWT VC vs. BBS-2023: Why These Aren’t Really the Things You’re ComparingModern identity systems have a bit of a hoarding problem.
Read article: Data Minimization: Why Does the Coffee Shop Need to Know My Blood Type?For most of the history of digital identity, we’ve had a remarkably simple solution to the question, “Who are you?”
Read article: Decentralized Identifiers: Because Apparently We Needed to Rethink the Name FieldLooking for something specific? Browse all 124 topics.