Skip to content

Tracks

Identity & CIAM

How people prove who they are online, and how products get that right at scale. Passkeys, MFA, account recovery, CIAM architecture and the standards underneath them.

187 posts, newest first. Page 1 of 7.

Tags in this track:CIAMAuthenticationpasskeysPasswordlessMFADigital IdentityidentityIAMCustomer Identitydecentralized identityFIDOWebAuthnoAuthauthorization

Latest in Identity & CIAM

Hijacking

Device Bound Session Credentials: The Answer to Session Theft

Chrome shipped DBSC to stable. It binds the session cookie to a key in the TPM, which makes a stolen cookie inert off the originating device. Here is the protocol, the honest limits, and the buyer checklist.

Read the article
CIAM

CIAM Observability: The Metrics Nobody Tracks

Vendor log retention ends months before the average breach is discovered. The funnel, security, and silent-failure metrics every CIAM deployment should have, and the seven-panel dashboard to start with.

identity

Meta's $17B Settlement Is Really an Age Assurance Mandate

Meta's settlement with 51 attorneys general commits at least $12.1 billion, but the money is the survivable part. Every teen safety term in the deal depends on knowing who is under 18, and nobody has solved that yet.

WebAuthn

WebAuthn Level 3: What's New in the Passkey Standard

WebAuthn Level 3 was proposed for W3C Recommendation in July 2026. Encryption key derivation, cross-domain credentials, and automatic list syncing are now first-class. Here is what changed.

Authentication

Authentication and Authorization in Microservices: What Works

In a monolith you check who someone is once. In microservices, every hop has to ask again. Here is how I design authentication and authorization across services: edge auth, per-service verification, workload identity with SPIFFE, and centralized policy.

authentication

AI Authentication: Verifying People, Agents, and Content

AI made it cheap to fake a face, a voice, and a video. Here is my working map of the three problems authentication now has to solve, and the tools that actually hold up in 2026: verifying people, verifying agents, and verifying content.

Authentication

Build vs Buy Auth Is the Wrong Question. Here's the Right One.

Every CTO re-litigates build vs buy for authentication every 18 months, and the framing is broken. The real question isn't build or buy. It's which parts of identity are commodity and which parts are your actual product.

CIAM

Auth0 Isn't Overpriced. You're Just the Wrong Buyer.

Whether Auth0 is too expensive depends entirely on who's asking. A framework for telling the regulated enterprise buyer (pay and negotiate) apart from the high-volume, cost-sensitive platform (migrate), with 2026 pricing and breach-cost data.

Mobile Security

eSIM vs iSIM vs SIM: Which Is Actually More Secure?

"Is eSIM safer than a physical SIM?" has a more interesting answer than most articles give. Each SIM type, physical, eSIM, and iSIM, has a different architecture and a different attack surface. Here is how they actually work and which is genuinely more secure.

Get new Identity & CIAM writing

New writing on identity, AI security, and building software, delivered when it ships. No tracking pixels, no funnels, unsubscribe with one click.

Tell us what you read most (optional)