#Authentication

2025-07-09

As I try to find a job, I got email from apparent recruiter and I feel something is odd. So I want to authenticate the email.

The address is like no-reply@example.com

Headers show it was received from
smtp.email.us-phoenix.ocs.oraclecloud.com

With IP address: 192.184.11.189

From what I read in RFC, I think the A, MX, and SPF records are a no match, but I'm no pro nor expert. I value input. Got records on PNG below

example.com. 300 IN A 96.7.281.284
example.com. 300 IN A 23.219.106.176
example.com. 300 IN A 96.7.281.223
example.com. 300 IN A 23.219.106.156

example.com. 900 IN MX 10 examplemscloud.mail.protection.outlook.com.

v=spf1 exists:%{i}._i.%{d}._d.espf.agari-dns.net include:%{d}.ff.spf-protect.agari-dns.net include:_spf.salesforce.com include:spf.example.com include:spf-d.example.com include:spf-c.example.com include:spf.protection.outlook.com -all
2025-07-08

@link2xt

I'M TROUBLED BY THE FOLLOWING:

The email was sent using oraclecloud servers, and when I checked the SPF records using the MXTOOLBOX.COM

I see what I think would be other authorized domains

v=spf1 exists:%{i}._i.%{d}._d.espf.agari-dns.net include:%{d}.ff.spf-protect.agari-dns.net include:_spf.salesforce.com include:spf.somedomain.com include:spf-d.somedomain.com include:spf-c.somedomain.com include:spf.protection.outlook.com -all

Spike in credential theft. Probably comes as no surprise to anyone. Use MFA!

infosecurity-magazine.com/news

#authentication #mfa

2025-07-04

Pivot-Lite by Fors is a #free two-operator #virtual #FM #synth that uses similar approach as Elektron Digitone groovebox. It requires #registration for the #download but no #online #authentication, which is great.

I'm getting tired of audio #software developers requiring additional authentication software to run the software I buy with my own money. Companies like Steinberg require 5 different apps to run one of their instruments. Here is a developer for once that says no authorisation needed.

W3C Developersw3cdevs@w3c.social
2025-07-03

The @w3c Linked Web Storage specification aims to create #WebApps with loosely coupled components like data #storage and #authentication, unlike today's tightly integrated systems.
The "Linked Web Storage Use Cases" document is published as a Draft Note. It presents user stories, use cases, and necessary requirements.
▶️ w3.org/TR/lws-ucs/

You’re welcome to contribute! github.com/w3c/lws-ucs/

Rad Web Hostingradwebhosting
2025-07-02

How to Setup SSH Login with Public Key (4 Step Quick-Start Guide)

This article describes how to setup SSH login with public key authentication across your servers and clients for secure access.

If you're using SSH to connect to remote servers, public key authentication is a security best practice. Unlike password-based logins, key-based authentication is not vulnerable to brute-force attacks.

Using a key to ...
Continued 👉 blog.radwebhosting.com/how-to-

Mad A. Argon :qurio:madargon@is-a.cat
2025-07-01

Thought it is high time to finally set #2FA on my #DeviantArt account... Turned out it's premium feature for paid accounts :neocatBlushHide:

#security #authentication

2025-07-01

Successful #evaluation for ESS: From May 26 to 18, 2025, a group of international scientists visited Karlsruhe to evaluate, among other things, the Topic Engineering Secure Systems (ESS). The guests came from ETH Zurich, the University of Wisconsin-Madison, and the University of Leuven, among others. ESS is one of three (sub)topics in the Program Engineering #Digital Futures (EDF) in the @helmholtz Research Field “Information.” We at SECUSO are involved in ESS as part of the Human and Societal Factors (HSF) research group. HSF presented the work of the research group in four demonstrators from the areas of #security #awareness, user #authentication, legal design patterns, and securing democracies. Further information can be found in the special issue on Topic Engineering Secure Systems: kastel-labs.de/wp-content/uplo

Yvo Verschooryv
2025-06-28

-> That warning e-mail itself asks whether you find it suspicious, or whether you yourself attempted to log in. It is the latter. But that button leads to nothing. It doesn't throw the e-mail away either. Only an extra screen with explanation and a 'cancel' button (which also does nothing, because it links to the previous screen).
Well. Clearly a bug. 2/2

Google dialogue box with a not usefull expanation and a missing "confirm" button. Only a cancel button that leads back to a previous screen.
Joseph Lim :mastodon:joseph11lim
2025-06-28


Make process for more user-friendly
"After multiple failed attempts.. As a w , I hv yet to complete an online nomination successfully. shld be more adaptable to conditions. Basic form data shld be saved as draft to avoid te need to re-enter everything in case of errors. ’s push twds is commendable but experiences like tis risk leaving some behind"
straitstimes.com/opinion/forum

mastodon.raddemo.hostadmin@mastodon.raddemo.host
2025-06-28

How to Setup SSH Login with Public Key #Authentication (4 Step Quick-Start Guide)

This article describes how to setup SSH login with public key authentication across your servers and clients for secure access.

If you're using SSH to connect to remote servers, public key authentication is a security best practice. Unlike password-based logins, key-based authentication is not vulnerable to brute-force attacks.

Using a key to ...
Continued 👉 blog.radwebhosting.com/how-to- #sshcommands #publickey

2025-06-27

Путеводитель по Ktor JWT auth на стороне сервера

Документация Ktor по server-jwt неполна. Если необходимо сделать что-то за рамками «Hello world», придется лезть в исходники и городить костыли. Какой-то консистентности и предсказуемости ждать не стоит, возможно, не обошлось без заговорщиков . Статья покроет необходимую базу для работы с JWT и убережет от множества подводных камней.

habr.com/ru/articles/921076/

#ktor #backend #kotlin #jwt_auth #говнокод #авторизация #аутентификация #костыли #authorization #authentication

|7eter l-|. l3oling 🧰galtzo@ruby.social
2025-06-27

Rename `oauth-xx` org to `ruby-oauth`?

Intent of current name was to be a home for oauth tools across many languages, but it never materialized that way. The vestigial -xx is awkward for many reasons, and I think discoverability would improve with a ruby-* org name, and perhaps it could even bring in other oauth-related tools. I have a few thoughts about this, so 🧵

I'm very interested in others thoughts #Ruby #RubyFriends #OAuth #Authentication

N-gated Hacker Newsngate
2025-06-26

🎉 .15 is out! Now with 15% more and room summaries because who needs meaningful when you can have version numbers? 😂 Enjoy the thrill of yet another where you can pitch your groundbreaking ideas on how to send text messages. 💡📱
matrix.org/blog/2025/06/26/mat

mastodon.raddemo.hostadmin@mastodon.raddemo.host
2025-06-24

How to Setup SSH Login with Public Key #Authentication (4 Step Quick-Start Guide)

This article describes how to setup SSH login with public key authentication across your servers and clients for secure access.

If you're using SSH to connect to remote servers, public key authentication is a security best practice. Unlike password-based logins, key-based authentication is not vulnerable to brute-force attacks.

Using a key to ...
Continued 👉 blog.radwebhosting.com/how-to- #sshcommands #publickey

Felix Palmen :freebsd: :c64:zirias@bsd.cafe
2025-06-24

Just released: #swad 0.12 🥂

swad is the "Simple Web Authentication Daemon". It basically offers adding form + #cookie #authentication to your reverse proxy (designed for and tested with #nginx "auth_request"). I created it mainly to defend against #malicious_bots, so among other credential checker modules for "real" logins, it offers a proof-of-work mechanism for guest logins doing the same #crypto #challenge known from #Anubis.

swad is written in pure #C with minimal dependencies (#zlib, #OpenSSL or compatible, and optionally #PAM), and designed to work on any #POSIX system. It compiles to a small binary (200 - 300 kiB depending on compiler and target platform).

This release brings (among a few bugfixes) improvements to make swad fit for "heavy load" scenarios: There's a new option to balance the load across multiple service worker threads, so all cores can be fully utilized if necessary, and it now keeps lots of transient objects in pools for reuse, which helps to avoid memory fragmentation and ultimately results in lower overall memory consumption.

Read more about it, download the .tar.xz, build and install it .... here:

github.com/Zirias/swad

Shubham Tiwarimysterio909
2025-06-21

🚀 Mastering API Handling in React & Vanilla JS – One Step at a Time!

This week, I deep-dived into handling APIs in React and Vanilla JavaScript – not just fetching data, but doing it efficiently and securely which includes: Fetch, CRUD, Query Params, Auth, and AbortController Explained

dev.to/shubhamtiwari909/handli

eicker.news ᳇ tech newstechnews@eicker.news
2025-06-19

#Facebook is adding #passkey support to its #mobileapp, allowing users to log in using their device’s #authentication method: aims to enhance security and protect against phishing attacks. theverge.com/news/689410/faceb #tech #media #news

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst