Category: Identity
-

The Machine Identity Attestation Problem
Machine identity attestation in 2026 amounts to the work of knowing what every workload, every container, every service mesh identity, every machine credential, every certificate, every API token can do, who owns it, when it was last rotated, whether it sits still needed. Most enterprises in 2026 have not done this work. The 2026 guide…
-

Session Token Theft Has Replaced Password Theft (And You Are Not Ready)
Infostealer logs have made session token theft the dominant credential attack. The password is no longer the thing the attacker wants. The session is. Here is what to do about it.
-

The Non-Human Identity Problem You Have Not Mapped Yet
Service accounts, API keys, OAuth tokens, machine certificates. The non-human identity surface in 2026 is larger than the human one, and almost nobody has mapped it.
-

Why SSO Isn’t Magic and Your Service Account Problem Is Worse
Single sign on solved the human password problem. It did not solve the service account problem. The service account problem is now larger than the human password problem was in 2015.
-

The Passkey Migration Is a Mess (And How to Fix It)
Passkeys are the right answer to the password problem. The migration is full of edge cases the FIDO Alliance did not think through. Here is what is broken, and what the realistic path forward looks like.
-

Passwordless Is a Five Year Project, Not a Five Month Project
The companies that are treating passwordless like a five month project are the ones whose roadmaps have slipped twice and will slip a third time. The reason it is a five year project is that passwordless is a migration you manage.