home.social

#passwordless — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #passwordless, aggregated by home.social.

fetched live
  1. 🤔 Ah, the #future where passwords are obsolete... yet here we are with a novel attack surface that screams, "Hello, hackers! 🎉 Please exploit me!" 🚨 Who knew going #passwordless meant losing your keys altogether? 🔑🔓
    unit42.paloaltonetworks.com/pa #security #cyberattack #tech #vulnerabilities #HackerNews #ngated

  2. 🤔 Ah, the #future where passwords are obsolete... yet here we are with a novel attack surface that screams, "Hello, hackers! 🎉 Please exploit me!" 🚨 Who knew going #passwordless meant losing your keys altogether? 🔑🔓
    unit42.paloaltonetworks.com/pa #security #cyberattack #tech #vulnerabilities #HackerNews #ngated

  3. The Silent Breach and the Persistence of Unauthorized Access

    938 words, 5 minutes read time.

    Once the session token is successfully exfiltrated, the nature of the intrusion shifts from external deception to internal subversion. The attacker does not need to crack passwords or trigger further security alerts, as they are now effectively operating with the digital identity of a trusted employee. Analyzing these incidents, I see that the primary goal is often the establishment of persistence within the target environment, which is achieved through the modification of inbox rules or the creation of clandestine mailbox delegates. By silently forwarding incoming emails to an external address or creating hidden folders for sensitive correspondence, the adversary can monitor ongoing business deals, intercept financial instructions, and identify high-value targets for subsequent business email compromise attacks. This stage of the operation is characterized by extreme patience, as the threat actor avoids loud, disruptive actions in favor of a low-and-slow approach that can remain undetected for months. The tragedy is that the victim often remains entirely unaware of the breach, believing they are still securely authenticated while their environment is being methodically picked apart from the inside.

    Challenging the Failure of Traditional Defensive Postures

    When considering why these attacks continue to succeed with such alarming frequency, it becomes evident that the industry’s reliance on legacy defensive postures is a failing strategy. Many organizations still treat email security as a static barrier, implementing blacklists and rudimentary heuristic scans that are easily circumvented by adversaries who control their own infrastructure and rotating IP addresses. Furthermore, the human-centric nature of these scams renders technical controls inherently insufficient unless they are paired with a cultural shift toward skeptical verification. It is not enough to deploy an automated solution if the culture within a firm encourages speed over accuracy and ignores the red flags of irregular communication patterns. Consequently, the defense against these campaigns must evolve into a proactive, threat-hunting discipline that monitors for anomalous login locations, unexpected session durations, and unauthorized changes to account configurations. Without this layer of vigilant oversight, the technical barriers essentially act as a screen door, providing the illusion of protection while failing to stop the actual threat.

    Implementing Rigorous Verification Protocols in a High-Stakes Environment

    The path forward requires a departure from the convenience-first mindset that dominates modern digital work environments. Organizations must adopt hardware-backed authentication methods, such as FIDO2-compliant security keys, which are resistant to the proxy-based interception tactics that currently plague mobile-based push notifications and SMS codes. Additionally, the adoption of strict device posture checks ensures that an attacker cannot simply use a stolen session token from an unauthorized machine or an unrecognized geographic region. Beyond the hardware, there must be a fundamental hardening of organizational processes, such as implementing mandatory out-of-band verification for any request involving financial transfers or the sharing of sensitive credentials. It is a harsh reality that trust is the primary vulnerability in any system, and the most secure posture is one that treats every incoming request as potentially malicious until proven otherwise through independent channels. While this might introduce friction into the workflow, that friction is the necessary price of security in an age where the cost of a single successful breach is often the survival of the entity itself.

    Call to Action

    The time for passive observation has passed, as the threats currently infiltrating our inboxes are not waiting for an invitation to compromise your organization. You must decide whether to continue relying on outdated defensive protocols that offer only the illusion of safety or to begin the hard work of hardening your infrastructure against the reality of modern adversarial tactics. I urge you to conduct an immediate audit of your current authentication stack and evaluate the necessity of migrating to hardware-backed security keys, as this is the single most effective step you can take to neutralize the threat of proxy-based session hijacking. Furthermore, initiate a comprehensive review of your internal communication policies to ensure that your team is empowered to question anomalies rather than blindly following the path of least resistance. Security is not a product you purchase, but a discipline you practice, and the responsibility to bridge the gap between your existing defenses and the current threat reality rests entirely with you. Do not wait for a compromised session to force your hand, because by the time the impact of a breach is visible, the damage is already absolute.

    SUPPORTSUBSCRIBECONTACT ME

    D. Bryan King

    Sources

    Disclaimer:

    The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

    Related Posts

    Rate this:

    #accountTakeover #adversaryInTheMiddle #AiTM #ATO #authenticationProtocols #BEC #businessEmailCompromise #corporatePhishing #corporateSecurity #credentialHarvesting #cyberResilience #cyberThreatIntelligence #cyberWarfare #cybersecurity #cybersecurityBestPractices #dataBreachPrevention #digitalFraud #digitalIdentity #emailScams #emailSecurity #emailThreats #enterpriseSecurity #FIDO2 #hardwareSecurity #identityTheftProtection #incidentResponse #informationSecurity #infosec #maliciousInfrastructure #MFABypass #multiFactorAuthentication #networkDefense #onlineSafety #passwordless #phishingAttacks #phishingAwareness #phishingKits #phishingResistantAuthentication #riskManagement #secureAuthentication #securityAudit #securityCulture #securityHardening #securityKeys #sessionTokenTheft #socialEngineering #threatDetection #threatLandscape #zeroTrust
  4. Passwordless adoption isn’t failing because of tech 🚨

    Pax8’s Robb Reck says SMBs struggle with:
    • Legacy apps
    • Identity sprawl
    • MFA rollout friction
    • Limited IT resources
    Operational drag remains the real blocker.

    technadu.com/the-real-reason-p

    #Infosec #Passwordless #Cybersecurity

  5. Passwords are no longer enough 🚨
    BeyondTrust’s Morey Haber says organizations must move toward:
    • Passwordless auth
    • Least privilege
    • JIT access
    • Continuous monitoring
    Identity is the new perimeter

    technadu.com/world-password-da

    #Infosec #Passwordless #Cybersecurity

  6. This World Passkey Day, take a moment to thank your passwords for their years of service. Then, escort them gently to retirement before they reset themselves for the 14th time this quarter.

    To every company still making users create complex passwords with inscrutable complexity rules, consider this your friendly intervention. The passwordless future is already here. Passkeys are making sign-ins faster, phishing-resistant, and dramatically less painful for users everywhere. That means fewer “Forgot Password?” clicks and fewer support tickets fueled by existential despair.

    The time is now. Stop treating passkeys like a “coming soon” feature and start treating passwords like fax machines with better PR.

    Happy #WorldPasskeyDay from all of us here at the FIDO Alliance.

    #Passkeys #Passwordless #Authentication #Cybersecurity

  7. This World Passkey Day, take a moment to thank your passwords for their years of service. Then, escort them gently to retirement before they reset themselves for the 14th time this quarter.

    To every company still making users create complex passwords with inscrutable complexity rules, consider this your friendly intervention. The passwordless future is already here. Passkeys are making sign-ins faster, phishing-resistant, and dramatically less painful for users everywhere. That means fewer “Forgot Password?” clicks and fewer support tickets fueled by existential despair.

    The time is now. Stop treating passkeys like a “coming soon” feature and start treating passwords like fax machines with better PR.

    Happy #WorldPasskeyDay from all of us here at the FIDO Alliance.

    #Passkeys #Passwordless #Authentication #Cybersecurity

  8. Почему мы до сих пор используем пароли, хотя все их ненавидят

    Все ругают пароли, но продолжают их вводить. Даже там, где уже есть токены, OAuth и биометрия, Привычная строка «Введите пароль» никуда не делась. Кажется, мы привыкли к боли, но у этой устойчивости есть вполне рациональные причины… Заходите, расскажу вам правдивую историю про эпоху мейнфреймов, технический долг Unix и иллюзию беспарольного доступа, а также разберу замены и поделюсь классными парольными утилитами. Читать

    habr.com/ru/companies/ruvds/ar

    #ruvds_статьи #пароли #аутентификация #unix #linux #pam #devops #системное_администрирование #passwordless #администрирование

  9. Passwordless login is one of the simplest ways to improve security and UX.

    In this tutorial I show how to build magic link authentication with Quarkus and Keycloak.
    Email token → validation → secure session.

    No passwords. No complexity. Just clean Java.

    the-main-thread.com/p/password

    #Java #Quarkus #Keycloak #AppSec #JavaDev #Passwordless

  10. Passwordless login is one of the simplest ways to improve security and UX.

    In this tutorial I show how to build magic link authentication with Quarkus and Keycloak.
    Email token → validation → secure session.

    No passwords. No complexity. Just clean Java.

    the-main-thread.com/p/password

    #Java #Quarkus #Keycloak #AppSec #JavaDev #Passwordless

  11. Passwordless is finally becoming normal. This carousel shows what passkeys change for MSP identity services in 2026.

    #Passkeys #IdentitySecurity #Passwordless #CyberTrends

  12. Bearbeitet:

    What to do when passwordless SSH is not working after ssh-copy-id?
    #passwordless #ssh #ssh-copy-id #ubuntu #ubuntu-22-04

    fortschrittsanzeige.de/what-to

    Are you trying to make your SSH-connection to a Ubuntu 22.04. (or higher) server passwordl

  13. I’m seeing more and more companies going #passwordless by removing the option for a password and just sending a #totp one time password via #email.

    I’m not a #security researcher (just a lowly software engineer), but this feels like they are making my account less secure and my email inbox an even greater target.

  14. I’m seeing more and more companies going #passwordless by removing the option for a password and just sending a #totp one time password via #email.

    I’m not a #security researcher (just a lowly software engineer), but this feels like they are making my account less secure and my email inbox an even greater target.

  15. Экосистема SeedKey. Или как улучшить беспарольную аутентификацию

    Почему беспарольная аутентификация с помощью девайс ключей не так распространена? И почему сайты неохотно внедряют её у себя? В статье мы попытаемся разобраться с ответами на эти вопросы, и я расскажу о моем эксперименте исправить это.

    habr.com/ru/articles/984456/

    #webauthn #passkeys #беспарольная_аутентификация #passwordless #browser_extensions #fido #helm_chart #seedkey #ctap #sdk

  16. Windows 11 recently improved its passkey experience, part of a broader pattern worth paying attention to. We've been working hard within the FIDO Alliance to remove friction around passkeys, since improving usability is one of the most important drivers to boosting passwordless adoption in both the consumer and enterprise worlds. Moves like these help passkeys become just as operationally viable as they are technically sound.

    There’s also a benefit to this architectural pattern that people miss at first glance that enables passkeys to really scale in real-world environments. Check out my blog to learn more.
    blog.talkingidentity.com/2025/
    #Passkeys #Passwordless #IAM #UsableSecurity #UsePasskeys #CredentialManagers

  17. Windows 11 recently improved its passkey experience, part of a broader pattern worth paying attention to. We've been working hard within the FIDO Alliance to remove friction around passkeys, since improving usability is one of the most important drivers to boosting passwordless adoption in both the consumer and enterprise worlds. Moves like these help passkeys become just as operationally viable as they are technically sound.

    There’s also a benefit to this architectural pattern that people miss at first glance that enables passkeys to really scale in real-world environments. Check out my blog to learn more.
    blog.talkingidentity.com/2025/
    #Passkeys #Passwordless #IAM #UsableSecurity #UsePasskeys #CredentialManagers

  18. Can't phish my password when it doesn't exist ;)

    Passwordless auth on firewall via CTAP2 platform authenticators + FIDO2 FTW.

    Has your org gone passwordless yet?

    #passwordless #FIDO2

  19. Can't phish my password when it doesn't exist ;)

    Passwordless auth on firewall via CTAP2 platform authenticators + FIDO2 FTW.

    Has your org gone passwordless yet?

    #passwordless #FIDO2

  20. Bert Kashyap, CEO & Co-Founder of SecureW2, says:
    “True Zero Trust goes beyond MFA - it requires dynamic, contextual machine identity.”
    His Q&A with TechNadu explores how PKI, automation, and open standards are driving passwordless trust.
    technadu.com/building-password

    #ZeroTrust #PKI #Cybersecurity #Passwordless #IdentitySecurity #SecureW2

  21. Passwords cost time, money, and trust. #Passkeys solve the problem with public-key cryptography. Stronger security and a better experience—no shared secrets. Learn how to use them in #Java apps with @deepu105.

    Discover the future: javapro.io/2025/05/30/a-passwo

    #WebAuthn #Passwordless

  22. Passwords cost time, money, and trust. #Passkeys solve the problem with public-key cryptography. Stronger security and a better experience—no shared secrets. Learn how to use them in #Java apps with @deepu105.

    Discover the future: javapro.io/2025/05/30/a-passwo

    #WebAuthn #Passwordless

  23. Passwörter werden wohl zu unseren Lebzeiten nicht verschwinden, aber ich zweifel gerade, wann (und ob überhaupt jemals) Passkeys einfach genug sind, dass auch Nicht-Techies sie bequem benutzen können. Google, Microsoft und Apple haben jedenfalls einiges dazu beigetragen, dass alles wieder furchtbar kompliziert ist, weil jeder sein eigenes Süppchen kocht und es doch besser weiß, wie es geht.

    (3/3)

    #Apple #Microsoft #Google #Passkeys #Passwordless #Passkey #Passwords #Password #Security #FIDO2 #WebAuthn

  24. Passwörter werden wohl zu unseren Lebzeiten nicht verschwinden, aber ich zweifel gerade, wann (und ob überhaupt jemals) Passkeys einfach genug sind, dass auch Nicht-Techies sie bequem benutzen können. Google, Microsoft und Apple haben jedenfalls einiges dazu beigetragen, dass alles wieder furchtbar kompliziert ist, weil jeder sein eigenes Süppchen kocht und es doch besser weiß, wie es geht.

    (3/3)

    #Apple #Microsoft #Google #Passkeys #Passwordless #Passkey #Passwords #Password #Security #FIDO2 #WebAuthn

  25. Die Liste der praktischen Probleme ist lang:

    • #Apple, #Microsoft, und #Google bieten alle Passkeys an, machen aber alle ihr eigenes Ding mit unterschiedlichen Workflows und Speicheroptionen. Aber Hauptsache die Nutzer nutzen ihre Dienste und man hat es möglichst schwer zu wechseln.
    • Einen sicheren Export und Import von Passkeys gibt es in der Praxis derzeit nicht. Offizielle Spezifikationen der FIDO-Allianz gibt es seit letztem Jahr, aber wirklich umgesetzt hat das niemand. Apple hat das für iOS und macOS 26 mal angekündigt, aber ich finde für die Umsetzung keine Anhaltspunkte. Edit: Apple hat das wohl tatsächlich schon umgesetzt.
    • Passkeys werden fast nirgends als echter Passwortersatz unterstützt. Dazu müsste man die Nutzung von Passwörtern unterbinden können. Geht bei Microsoft Entra ID, sonst fällt mir nix ein. Dann kann das Hacken und Phishing ja fröhlich weiter gehen! :awesome:

    (2/3)

    #Passkeys #Passwordless #Passkey #Passwords #Password #Security #FIDO2 #WebAuthn

  26. Die Liste der praktischen Probleme ist lang:

    • #Apple, #Microsoft, und #Google bieten alle Passkeys an, machen aber alle ihr eigenes Ding mit unterschiedlichen Workflows und Speicheroptionen. Aber Hauptsache die Nutzer nutzen ihre Dienste und man hat es möglichst schwer zu wechseln.
    • Einen sicheren Export und Import von Passkeys gibt es in der Praxis derzeit nicht. Offizielle Spezifikationen der FIDO-Allianz gibt es seit letztem Jahr, aber wirklich umgesetzt hat das niemand. Apple hat das für iOS und macOS 26 mal angekündigt, aber ich finde für die Umsetzung keine Anhaltspunkte. Edit: Apple hat das wohl tatsächlich schon umgesetzt.
    • Passkeys werden fast nirgends als echter Passwortersatz unterstützt. Dazu müsste man die Nutzung von Passwörtern unterbinden können. Geht bei Microsoft Entra ID, sonst fällt mir nix ein. Dann kann das Hacken und Phishing ja fröhlich weiter gehen! :awesome:

    (2/3)

    #Passkeys #Passwordless #Passkey #Passwords #Password #Security #FIDO2 #WebAuthn

  27. 🔑 Ich habe mich nach längerer Zeit anlässlich eines Vortrags wieder etwas intensiver mit #Passkeys befasst, nachdem ich schon selbst eine Hand voll davon im Einsatz hatte. Eigentlich sollen uns Passkeys ja das bequeme und vor allem sichere Authentifizieren gegenüber Diensten ermöglichen.

    Boah, ist der aktuelle Zustand nach wie vor ernüchternd. 🫠

    Ein Thread. (1/3)

    #Passwordless #Passkey #Passwords #Password #Security #FIDO2 #WebAuthn #Security

  28. 🔑 Ich habe mich nach längerer Zeit anlässlich eines Vortrags wieder etwas intensiver mit #Passkeys befasst, nachdem ich schon selbst eine Hand voll davon im Einsatz hatte. Eigentlich sollen uns Passkeys ja das bequeme und vor allem sichere Authentifizieren gegenüber Diensten ermöglichen.

    Boah, ist der aktuelle Zustand nach wie vor ernüchternd. 🫠

    Ein Thread. (1/3)

    #Passwordless #Passkey #Passwords #Password #Security #FIDO2 #WebAuthn #Security

  29. Ever wished your chats could be secure without the headache of remembering passwords? WhatsApp’s new passkey-encrypted backups use your fingerprint or face to keep your conversations safe—talk about a smarter, safer future.

    thedefendopsdiaries.com/passke

    #whatsappsecurity
    #passwordless
    #biometricauthentication
    #dataprivacy
    #passkeyencryption

  30. Ever wished your chats could be secure without the headache of remembering passwords? WhatsApp’s new passkey-encrypted backups use your fingerprint or face to keep your conversations safe—talk about a smarter, safer future.

    thedefendopsdiaries.com/passke

    #whatsappsecurity
    #passwordless
    #biometricauthentication
    #dataprivacy
    #passkeyencryption