#authentication

2025-12-15

Upcoming Changes to Let’s #Encrypt #Certificates - #API Announcements - #LetsEncrypt Community Support

Let’s Encrypt is introducing several updates to the certificates we issue, including new #rootCertificates , deprecation of #TLS client #authentication , & shortening certificate lifetimes. To help roll out changes gradually, we’re making use of ACME profiles to allow users to have control over when some of these changes take place. For most users, no action required

community.letsencrypt.org/t/up

Tommaso Gagliardonitomgag@infosec.exchange
2025-12-15

Hey #mastodon this is something to look at! @soatok just announced v0.1.0 of their key transparency specification for the Fediverse!

soatok.blog/2025/12/15/announc

This is an incredibly useful project, something really missing in a robust decentralized architecture.

#fedi #fediverse #crypto #cryptography #authentication #security #federation #digitalsovereignty #digitalselfsovereignty

2025-12-15

Start 2026 with one upgrade that pays off immediately: tighten identity verification across your organization. In this week’s Cyberside Chats: Live, Sherri Davidoff and Matt Durrin break down how AI-driven impersonation is changing the rules and the quick wins security teams should prioritize first.

Two more days to register: lmgsecurity.com/event/cybersid

#CybersideChats #IdentitySecurity #AIThreats #Deepfakes #Authentication #SecurityAwareness #CyberRisk #EnterpriseSecurity

mastodon.raddemo.hostadmin@mastodon.raddemo.host
2025-12-13

How to Setup SSH Login with Public Key #Authentication (4 Step Quick-Start Guide)

This article describes how to setup SSH login with public key authentication across your servers and clients for secure access.

If you're using SSH to connect to remote servers, public key authentication is a security best practice. Unlike password-based logins, key-based authentication is not vulnerable to brute-force attacks.

Using a key to ...
Continued 👉 blog.radwebhosting.com/how-to- #sshcommands #publickey

2025-12-12

Giới thiệu Toqen – luồng xác thực bảo vệ quyền riêng tư bằng mã QR và TOTP tạm thời, không cần tài khoản/mật khẩu. Giải pháp giảm thiểu thu thập dữ liệu, phù hợp cho SaaS, khóa học, sự kiện. TONs? #Authentication #Privacy #SaaS #XácThực #QuyềnRiêngTư #PhầnMềmSaaS

reddit.com/r/SaaS/comments/1pk

2025-12-11

Các loại token Git không thể thay thế nhau. PAT: Dùng cho truy cập cá nhân. Token Deploy: Cho CI/CD. Token CI: Tự động hóa. Hiểu đúng để tránh lỗi hệ thống. #Git #Authentication #GitTokens #DangNhap #GitToken

reddit.com/r/programming/comme

2025-12-09

MOSS là thư viện chữ ký cho hệ thống đa đại lý, giúp truy xuất nguồn gốc đầu ra bằng ID mã hóa. Mỗi hành động của đại lý đều được xác thực, chống giả mạo và phát hiện gửi lại. Sử dụng ML-DSA-44, SHA-256, tích hợp CrewAI/LangChain. #AI #BảoMật #MãNguồnMở #MultiAgent #Authentication

Tài trợ bởi: mosscomputing.com 🌐
Các tag khác: #CôngNghệAI #AnToànThiếtBị #PostQuantum #Audit

reddit.com/r/LocalLLaMA/commen

dmstorkdmstork
2025-12-09

NO NO NO, ! Every benchmark considers SMS & Email OTP as weak . But I would rank Email a bit higher (can have , no SIM swap)

To be clear, even weak MFA is better than none. But this is stupid. Give the user the option for their own OTP/passkey (not possible) 🤦‍♂️

Screenshot of Shell app on iOS. Text black on white background says:
"Turn on Two-Factor Authentication via SMS
When logging in you'll receive your verification code via SMS instead of email.
- Protect yourself in case your email inbox is breached.
- Verification code via SMS is more secure than via email.
- Optimise your account security."
Outpost24Outpost24
2025-12-09

📣 Outpost24 acquires Infinipoint to power its entry into the Zero Trust Workforce Access market.

“With the strategic addition of Infinipoint’s unique capabilities, we are setting a new benchmark for Zero Trust Workforce Access with a holistic security layer that validates both the person and their device.” — Ido Erlichman, CEO, Outpost24

Read more: outpost24.com/blog/outpost24-a

2025-12-09

Cal.com has patched a critical authentication bypass (CVE-2025-66489) that allowed attackers to submit any non-empty TOTP field and skip password checks. Versions ≤5.9.7 were impacted.

Update to 5.9.8 to ensure both password and TOTP verification are enforced.
How should MFA implementations be validated to prevent logic gaps like this?

Source: gbhackers.com/critical-cal-com

Share your insights and follow us for more security reporting.

#infosec #appsec #CVE2025 #authentication #MFA #ThreatIntel #SecureCoding #SoftwareSecurity #VulnerabilityManagement #SecurityUpdate

Critical Cal.com Flaw Allows Attackers to Bypass Authentication Using Fake TOTP Codes
2025-12-08

Công cụ khởi đầu SaaS (FastAPI) với tính năng: xác thực, thanh toán, Celery + Stripe. Kiến trúc sạch, sẵn sàng sản phẩm. Mời góp ý! #SaaS #FastAPI #Authentication #XácThực #Billing #Stripe #PhátTriểnWeb

reddit.com/r/SideProject/comme

2025-12-08

🌟 Nhà sáng lập SaaS an ninh mạng đang tìm kiếm giải pháp xác thực (Authentication) hiệu quả! Hiện tại đang xem xét các lựa chọn như Auth0, Descope (với đội ngũ backer ấn tượng), và các dịch vụ nhỏ hơn khác. Với sản phẩm B2B nhắm đến CISO & Kỹ sư An ninh, việc tự xây xác thực là không khả thi. Cầu hỏi: Bạn sử dụng giải pháp nào và vì sao?

#SaaS #Authentication #Cybersecurity #KinhNghiemLapTrinh #MastodonTechnology #ViễnThôngViệtNam #StartupVietNam #TechNewsVN

reddit.com/r/SaaS/co

Negative PID Inc.negativepid
2025-12-07

You use SSH for remote authentication. But do you know how it works in the background? For SSH authentication to work, you need a server at the backend. Here is how to execute a complete SSH server installation, start to end.

negativepid.blog/how-to-instal
negativepid.blog/how-to-instal

2025-12-07

Why my sudoers file doesn't let me access? #sudo #authentication #postgresql

askubuntu.com/q/1560579/612

2025-12-04

For the absence of doubt, we've published an Internet Draft calling for a conclusion to the ARC (RFC8617) experiment we developed over 10 years ago, moving what we learned from it into work on the proposed DKIM2 specification.

ietf.org/archive/id/draft-adam

#ietf #email #security #authentication #standards #dmarc #arc #dkim

Erik van StratenErikvanStraten@todon.nl
2025-12-04

@pake_preacher : I forgot the details of PAKE and SRP, but in the end the most secure client authentication requires:

1️⃣ Strong, long term, human comprehensible, *serving endpoint* authentication;
*AND*
2️⃣ TLS channel binding (enforcing known endpoints).

(Apart from those, both serving endpoint AND client MUST be trustworthy).

🚨 The -corrupt- CA/B forum breaks 1️⃣ by:
a) Advocating anonymous Domain Validated certificates, which render secure account creation IMPOSSIBLE;
b) Continuously decreasing certificate lifetime.

🚨 Furthermore, "legitimate" MitM's * break 2️⃣.

* Man in the Middle, like on-device virusscanners and firewalls that "open" TLS tunnels (both requiring installation of a dedicated root certificate) and proxies such as (definitely not limited to) Cloudflare and Fastly.

😱 Passkeys enforce NEITHER 1️⃣ NOR 2️⃣.

😱😱 Worse, because passkeys (or FIDO2 hardware keys) can be easily irretrievably "lost", servers typically provide WAY EASIER phishable authentication methods (such as "rescue codes").

@cendyne @soatok @chazh

#AitM #MitM #SecureOnlineAuthIsHARD #SecureAuthentication #OnlineAuthentication #Authentication #Impersonation #ChannelBinding #TLSchannelBinding #UTM #TLS #TLSinterception #TLSscanning #Proxy #Proxies #GoogleIsEvil #CloudflareIsEvil

Renewable Sexcellencediffrentcolours@tech.lgbt
2025-12-04

Has anyone done some kind of SSO / SAML auth thing which supports "N of M" type authentication?

Like, I want to log into a shared Fedi account to post something; I log into my SSO provider as usual, and another member of the same group needs to "approve" before I get a login ticket for the target account.

The intended market for this would be organisations who don't want to share a password for an account, or who want some oversight on how it's used.

#SSO #SAML #Authentication

𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕kubikpixel@chaos.social
2025-12-04

Time to update your React implementation… Now!

»Admins and defenders gird themselves against maximum-severity server vuln:
Open source React executes malicious code with malformed HTML — no authentication needed.«

🪲 arstechnica.com/security/2025/

#javascript #react #coding #html #code #js #authentication #webdev #admin #web #dev #vuln #noauth

𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕kubikpixel@chaos.social
2025-12-03

Cookies vs. Local Storage: What’s the Difference? When and Where to Use Each?

Cookies are suitable for authentication and session management, while local storage is ideal for storing non-sensitive data on the client side. This detailed guide explains why and when to use each.

🍪 permit.io/blog/cookies-vs-loca

#webdev #cookies #localstorage #guide #web #authentication #blog #guide

Negative PID Inc.negativepid
2025-12-02

Europe has invested heavily in digital citizenship. During the last year, we experienced Quebec's withdrawal from emails and other digital services due to security concerns, and later, we got to experience a full-blown, certificate-based digital identity experience in Spain.

negativepid.blog/online-citize
negativepid.blog/online-citize

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst