Firebase API Keys: Got a Callback From A Potential Client
I originally wrote this post about six months ago. Variations of this story have been published many times this year.
Read article: Firebase API Keys: Got a Callback From A Potential ClientNotes on application security, API security, identity, and API management from the field. Articles are also published on Medium. Browse the archive by topic instead — 124 subjects.
I originally wrote this post about six months ago. Variations of this story have been published many times this year.
Read article: Firebase API Keys: Got a Callback From A Potential ClientThis is the second part of a series on the topic of MCP Governance. Check out MCP Governance: Part 1 to start at the beginning.
Read article: MCP Governance: Part2There are a few cryptographic primitives that sound considerably more complicated than they actually are.
Read article: Cryptographic Commitments: I Promise I’m Not Changing My AnswerThere are technologies that get all the attention.
Read article: PKI: The Infrastructure That Everyone Needs and Nobody Wants to Think AboutOAuth2 has been around long enough that it is easy to forget just how much machinery has accumulated around it.
Read article: GNAP: An Alternative Authorization Model for MCPIn modern identity systems, a compromise at one service can become a compromise at another service.
Read article: OpenID RISC: Sharing the Bad News Before the Attacker Gets ThereThere is a basic assumption hiding inside many identity architectures in that if someone authenticated successfully, they should continue to have access.
Read article: Continuous Access Evaluation: Maybe We Should Stop Trusting Yesterday’s AuthenticationThere is a fundamental problem with modern identity systems that is easy to overlook.
Read article: OpenID Shared Signals Framework: Giving Identity Systems a Way to Talk to Each OtherThere is a category of enterprise terminology that exists primarily to make consultants argue with each other.
Read article: Asset Management vs. Configuration Management: Yes, They Are Different ThingsThere is a special kind of fun involved in looking at an X.509 certificate with OpenSSL.
Read article: X.509v3 Extensions: Taking Apart a Certificate ChainLooking for something specific? Browse all 124 topics.