Cryptographic Commitments: I Promise I’m Not Changing My Answer
There are a few cryptographic primitives that sound considerably more complicated than they actually are.
Read article: Cryptographic Commitments: I Promise I’m Not Changing My Answer17 articles tagged Identity & Access Management.
There are a few cryptographic primitives that sound considerably more complicated than they actually are.
Read article: Cryptographic Commitments: I Promise I’m Not Changing My AnswerIn modern identity systems, a compromise at one service can become a compromise at another service.
Read article: OpenID RISC: Sharing the Bad News Before the Attacker Gets ThereThere is a basic assumption hiding inside many identity architectures in that if someone authenticated successfully, they should continue to have access.
Read article: Continuous Access Evaluation: Maybe We Should Stop Trusting Yesterday’s AuthenticationThere is a fundamental problem with modern identity systems that is easy to overlook.
Read article: OpenID Shared Signals Framework: Giving Identity Systems a Way to Talk to Each OtherThere is a special kind of fun involved in looking at an X.509 certificate with OpenSSL.
Read article: X.509v3 Extensions: Taking Apart a Certificate ChainIdentity systems have a bad habit of starting with a simple question: Who are you?
Read article: IAM GovernanceOAuth2 was designed around the assumption that the client can open a browser.
Read article: OAuth2 Device Authorization Grant: OAuth2 for Devices That Can’t Really Do OAuth2Disclaimer: This article was written in Q3,2026. It is current as of that date. The OAuth 2.1 draft proposals have not yet been published as an RFC. So, some changes could still occur. Given the late stage of the process, it is unlikely it will change that much, but be aware that some changes could…
Read article: OAuth 2.1: How OAuth 2.0 Evolved into a More Secure Authorization FrameworkWe have spent decades building systems that ask people to prove who they are.
Read article: OID4VP: OAuth2 for the “Prove It” ProblemThere is a recurring problem in digital identity: I want to prove something about myself, but, I don’t necessarily want to tell you everything about myself in the process.
Read article: Anonymous Credentials: Prove Something Without Telling Everyone Who You Are