P.01Pass-TA-Key: Malware That Steals Synced Passkeys
Unit 42 found three ways Windows malware hijacks Google Password Manager's synced passkeys with no biometric prompt. What that changes for passkey plans.
Tag
7 articles tagged #Authentication.
P.01Unit 42 found three ways Windows malware hijacks Google Password Manager's synced passkeys with no biometric prompt. What that changes for passkey plans.
P.025 billion passkeys are active and 75% of people have enabled one, yet 57% of organisations still use phishable logins. What the FIDO data actually means.
P.03OAuth 2.1 is still an IETF draft, but most providers enforce it already. What changed from 2.0, plus a checklist for auditing your own implementation.
P.04OAuth handles authorization, OIDC adds identity on top, and SAML is the older enterprise SSO standard still running much of the corporate world. How to pick.
Three real authentication options for Next.js apps, with different trade-offs on control, cost, and setup time. Here's what each one actually involves.
The implicit flow is dead and tutorials still teach it. How authorization code flow with PKCE works, where tokens belong, and where SPA auth goes wrong.
Passkeys are no longer an experimental feature. Apple, Google, and Microsoft all support them natively. Here's what WebAuthn actually looks like in code and when passkeys make sense for your app.