Tag: MFA
-

Hardware Tokens: The Quiet Comeback
The hardware token in 2026 has made a quiet comeback, with the YubiKey, the Titan, the Feitian all seeing the adoption that the push notification lost, with the hardware token sitting as the authentication that cannot be phished, that cannot be bypassed, that cannot be social engineered. The 2026 guide covers why the hardware token…
-

2026 Passkey Adoption: The Mid Year
Passkey adoption in 2026 has crossed 25% of the consumer facing applications, 15% of the enterprise applications, and 8% of the legacy applications, with the adoption rate accelerating as the implementation friction drops. The mid year 2026 state of passkey adoption amounts to the state of a technology that has stopped being the next big…
-

The Passkey Rollout That Actually Worked
The passkey rollouts that actually worked in 2026 share the same pattern: the platform support sits in place, the user experience runs as smooth, the help desk runs ready, the metrics run visible. The rollouts that failed share the opposite pattern. The 2026 field guide covers what the working rollout looks like, what the failed…
-

Phishing Resistant MFA Deep Dive
Passwords died somewhere around 2022. The funeral for SMS codes happened in 2024. The survivors in 2026 sit at three: hardware keys, passkeys, certificate based auth. The choice between them runs as the choice the enterprise has been postponing for three years, and the postponement has cost enough breaches to retire the debate.
-

SSH Key Management: The Honest Guide
A field guide to SSH key management in 2026, with the inventory problem, the rotation problem, the trust problem, and the right way to actually manage the SSH keys in a production environment.
-

The Quiet Death of Passwords
The password is dying. Not in a flashy way. In a slow, decade-long, regulatory-driven way that most users will not notice until one day they realize they have not typed a password in a year.
-

Non-Human Identity Attestation in 2026
Non-human identity attestation is the work of knowing what every service account, every API key, every bot identity, and every machine credential can do, who owns it, when it was last used, and whether it is still needed. Most enterprises in 2026 have not done this work. The attackers know. The auditors are catching up.
-

The Service Account Attestation Problem
The service account attestation problem is the largest unknown risk in the typical enterprise. The defender who solves the attestation problem has solved a category of breach the defender did not know existed. Here is the approach.
-

The Machine Identity Attestation Problem
Machine identity attestation in 2026 amounts to the work of knowing what every workload, every container, every service mesh identity, every machine credential, every certificate, every API token can do, who owns it, when it was last rotated, whether it sits still needed. Most enterprises in 2026 have not done this work. The 2026 guide…
-

Session Token Theft Has Replaced Password Theft (And You Are Not Ready)
Infostealer logs have made session token theft the dominant credential attack. The password is no longer the thing the attacker wants. The session is. Here is what to do about it.