Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Taggart boosted
Bill
Bill
@Sempf@infosec.exchange  ·  activity timestamp 2 weeks ago

This follows what I am seeing in tests. Far fewer injection vulnerabilities, far more aurh issues. The apps didn't change, the attackers got better.

https://stateofsecurity.com/identity-security-is-now-the-1-attack-vector-and-most-organizations-are-not-architected-for-it/

#auth #vector

  • Copy link
  • Flag this post
  • Block
Bill
Bill
@Sempf@infosec.exchange  ·  activity timestamp 2 weeks ago

This follows what I am seeing in tests. Far fewer injection vulnerabilities, far more aurh issues. The apps didn't change, the attackers got better.

https://stateofsecurity.com/identity-security-is-now-the-1-attack-vector-and-most-organizations-are-not-architected-for-it/

#auth #vector

  • Copy link
  • Flag this post
  • Block
Stefano Marinelli boosted
Peter N. M. Hansteen
Peter N. M. Hansteen
@pitrh@mastodon.social  ·  activity timestamp 4 months ago

Yubikey OTP support disabled in -current https://www.undeadly.org/cgi?action=article;sid=20250822064253 #openbsd #yubikey #otp #auth #security #buggysoftware #freesoftware #libresoftware

  • Copy link
  • Flag this post
  • Block
Peter N. M. Hansteen
Peter N. M. Hansteen
@pitrh@mastodon.social  ·  activity timestamp 4 months ago

Yubikey OTP support disabled in -current https://www.undeadly.org/cgi?action=article;sid=20250822064253 #openbsd #yubikey #otp #auth #security #buggysoftware #freesoftware #libresoftware

  • Copy link
  • Flag this post
  • Block
jbz
jbz
@jbz@indieweb.social  ·  activity timestamp 6 months ago

🦀 actix-passport: A comprehensive, flexible authentication framework for actix-web applications in Rust.

https://github.com/densumesh/actix-passport

#actix #rust #webdev #auth

  • Copy link
  • Flag this post
  • Block
洪 民憙 (Hong Minhee) :nonbinary:
洪 民憙 (Hong Minhee) :nonbinary:
@hongminhee@hollo.social  ·  activity timestamp 8 months ago

I'm exploring a new idea called FediOTP (codename): an authentication system that uses #ActivityPub DMs to deliver one-time passwords, allowing any #fediverse account to authenticate with web services. Unlike current solutions that rely on specific APIs ( #Mastodon, #Misskey), this would work with any ActivityPub-compatible server, increasing interoperability across the fediverse. Would love to hear your thoughts on potential challenges or use cases for this approach.

#OTP #fedidev #auth

  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.41 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct