DPoP Support Comes to the Identity Protocol Debugger
OAuth2 has always had a fundamental problem: a bearer token is a bearer token. After all, it’s a bearer token.
Read article: DPoP Support Comes to the Identity Protocol DebuggerNotes on application security, API security, identity, and API management from the field. Articles are also published on Medium. Browse the archive by topic instead — 124 subjects.
OAuth2 has always had a fundamental problem: a bearer token is a bearer token. After all, it’s a bearer token.
Read article: DPoP Support Comes to the Identity Protocol DebuggerIf you’ve spent any time reading about modern cryptography — especially BBS Signatures, attribute-based credentials, or identity-based encryption — you’ve probably encountered the phrase bilinear pairing.
Read article: Bilinear Pairings: Modern Privacy-Preserving CryptographyIf you’ve spent any time reading about modern cryptography, you’ve probably encountered the phrase Elliptic Curve Cryptography (ECC). It sounds less like a security technology and more like an elective mathematics course that everyone regrets taking — I’ve been in several of those.
Read article: Elliptic Curve Cryptography: The Tiny Keys That Protect the InternetSelective Disclosure is fundamentally a mathematical concept. The protocols (SD-JWT VC, BBS-2023, AnonCreds, Idemix, U-Prove, etc.) are really just engineering built on top of several branches of mathematics.
Read article: Selective Disclosure: The MathThis post seemed like a missing link in my Post-Quantum Cryptography series. Note, this is for non-technical people, non-physicist, or maybe IT community.
Read article: Quantum Mechanics Explained: The Universe’s Passive-Aggressive User ManualFor decades, digital identity has operated on a remarkably inefficient principle, “If someone asks for one piece of information, give them everything.”
Read article: Selective Disclosure: Finally, an Identity System That Knows When to Stop TalkingIdentity & Access Management (IAM) has spent decades answering fairly simple questions: “Who are you?” and “What are you allowed to do?”
Read article: Verifiable Credentials: The Next Evolution of Identity & Access ManagementWebAuthn is actually the tip of a much larger iceberg. Like the SD-JWT VC spec, it is built upon several W3C, FIDO Alliance, and IETF specifications. Together, these define a complete passwordless authentication ecosystem.
Read article: WebAuthN: Passwordless LoginsImagine if every time you bought groceries, boarded a plane, logged into a website, rented a car, or proved you were old enough to appreciate terrible coffee, someone quietly scribbled another note into your permanent file.
Read article: Unlinkability: Randomness Is Your FriendLooking for something specific? Browse all 124 topics.