Tag: MFA
-

The Non-Human Identity Problem You Have Not Mapped Yet
Service accounts, API keys, OAuth tokens, machine certificates. The non-human identity surface in 2026 is larger than the human one, and almost nobody has mapped it.
-

Why SSO Isn’t Magic and Your Service Account Problem Is Worse
Single sign on solved the human password problem. It did not solve the service account problem. The service account problem is now larger than the human password problem was in 2015.
-

The Passkey Migration Is a Mess (And How to Fix It)
Passkeys are the right answer to the password problem. The migration is full of edge cases the FIDO Alliance did not think through. Here is what is broken, and what the realistic path forward looks like.
-

Why Your MFA Push Notifications Are a Security Hole
The MFA push notification in 2026 sits as the security control the typical enterprise has deployed to replace the password, with the push notification promising the security the password cannot provide. The 2026 reality amounts to the reality where the push notification has become the attack vector the attacker uses, with the MFA fatigue attack,…
-

Passwordless Is a Five Year Project, Not a Five Month Project
The companies that are treating passwordless like a five month project are the ones whose roadmaps have slipped twice and will slip a third time. The reason it is a five year project is that passwordless is a migration you manage.