Skip to content
Topic

#Authentication

17 articles on Authentication — news, releases, guides and analysis from the SourceFeed engine.

Synced Passkeys Have a Malware Problem
Article 5d ago 2

Synced Passkeys Have a Malware Problem

Unit 42's Pass-ta-key attacks steal Google passkeys from a compromised endpoint without breaking any crypto.

Ji-ho Choi
Passkeys Still Kill Phishing. Malware Is Another Story.

Passkeys Still Kill Phishing. Malware Is Another Story.

Article · 1w ago0
DNS Poisoning on Hotel Wi-Fi Is a Phishing Problem

DNS Poisoning on Hotel Wi-Fi Is a Phishing Problem

Article · 2w ago0
676,000 Trucks Behind an API With No Auth

676,000 Trucks Behind an API With No Auth

Article · 2w ago5
Add Passkeys to Your Web App with Node.js and WebAuthn

Add Passkeys to Your Web App with Node.js and WebAuthn

Tutorial · 2w ago0
Issue HMAC-Signed, Scoped API Keys for a Public REST API

Issue HMAC-Signed, Scoped API Keys for a Public REST API

Tutorial · 3w ago0
Add Google Sign-In to a Node.js App with OpenID Connect

Add Google Sign-In to a Node.js App with OpenID Connect

Tutorial · 3w ago0
GitHub Locks 2FA On for Good This September

GitHub Locks 2FA On for Good This September

Article · 3w ago4
n8n Cross-Issuer Bug Turns JWT sub Into Account Takeover

n8n Cross-Issuer Bug Turns JWT sub Into Account Takeover

Article · 4w ago1
Voice Auth Is Dead. Your IVR Just Doesn't Know It Yet

Voice Auth Is Dead. Your IVR Just Doesn't Know It Yet

Article · 4w ago2
Add TOTP-Based Two-Factor Authentication to Your Web App

Add TOTP-Based Two-Factor Authentication to Your Web App

Tutorial · 4w ago1
Hardware Passkeys Gate OpenAI’s Frontier Cyber Models

Hardware Passkeys Gate OpenAI’s Frontier Cyber Models

Article · 4w ago1
Hand-Rolling OAuth 2.0 Authorization Code + PKCE in a React SPA

Hand-Rolling OAuth 2.0 Authorization Code + PKCE in a React SPA

Tutorial · 1mo ago0
Why Logto Is Challenging the B2B Auth Status Quo

Why Logto Is Challenging the B2B Auth Status Quo

Article · 1mo ago6
The Client-Side Illusion: Lessons from the J&J Web App Vulnerabilities

The Client-Side Illusion: Lessons from the J&J Web App Vulnerabilities

Article · 1mo ago0
Why JWTs Are a Security Anti-Pattern for Sessions

Why JWTs Are a Security Anti-Pattern for Sessions

Article · 1mo ago0