• Home
  • About
  • Blog
  • Contact

← All posts

Authentication Series

November 19, 2024by Robert Broeckelmann
  • Authentication
  • Series

Barcode / Christiaan Colen

This is a collection of blog posts I’ve written on the topic of authentication.

Check out:

  • Authentication vs. Federation vs. SSO
  • Design Principals For Seamless User Authentication
  • Static Credentials Must Not Be Used In The Browser
  • Identity Protocols, Hosted Login UIs, and Custom Login UIs
  • OpenID Connect (OIDC) and OAuth2 Authentication Libraries
  • Identity Broker: An SSO Protocol Transition From OpenID Connect To WS-Federation
  • Understanding OpenID Connect Series
  • Don’t Use Source IP Addresses As The Primary Authentication Mechanism
  • Multi-Factor Authentication (MFA): Don’t Let Your CyberSecurity Insurance Claim Get Denied On Preventable Details and Fine Print
  • Understanding Unauthenticated Traffic: How Applications and APIs Represent The Unauthenticated User

Originally published on Medium.

More articles

Bearer, Proof of Possession, and Sender Vouches: Three Ways to Trust an Identity

August 20, 2026
  • Access Tokens
  • Authorization
  • Identity & Access Management

One of the most fundamental questions in any identity or authorization system is how does the system know that the party presenting a credential is actually entitled to use it?

Read article →: Bearer, Proof of Possession, and Sender Vouches: Three Ways to Trust an Identity

Holder of Key vs. Proof of Possession: Two Sides of Cryptographic Identity

August 19, 2026
  • Access Tokens
  • Authentication
  • Identity & Access Management

For years, identity protocols have used phrases such as Holder of Key, Proof of Possession, Key Binding, and Bearer almost interchangeably.

Read article →: Holder of Key vs. Proof of Possession: Two Sides of Cryptographic Identity

Content Security Policy: Putting the Browser on a Security Diet

August 19, 2026
  • Application Security
  • Web Application Security
  • Security

Web applications have become remarkably powerful.

Read article →: Content Security Policy: Putting the Browser on a Security Diet
Site design by Yvette Richter Design
Contact Us|Privacy Policy

Proud sponsor of the Open Source IDPTools Project. Github project

© 2026 IYA Cyber Security. All rights reserved.

This site uses cookies for analytics and to remember this choice. See the Privacy Policy for what is collected and how to opt out.