The Self-Signed Permission Slip

JWTs feel like magic until you realize nobody's checking the signature.

appsecidentityauthentication

The Flimsy Wristband

Why the thing that keeps you logged in is the thing attackers want most

appsecidentitysession security

Turns Out I've Been Taking Notes

How a pile of scratch notes became whatever this is