account-security
Safeguard articles tagged "account-security" — guides, analysis, and best practices for software supply chain and application security.
3 articles
One Mailbox, Six Spellings: The Signup Bug in Almost Every Product
name+tag@, dotted Gmail, googlemail.com, a zero-width space. All reach one inbox, all pass a uniqueness check, and one common fix locks real users out of accounts they are entitled to.
The Security Chores Agents Should Handle Themselves
Enabling 2FA, rotating a password, revoking a stale session, minting a scoped key — the account-hygiene tasks everyone postpones. When an agent can do them through MCP, 'later' becomes 'now.'
PyPI 2FA Lessons Two Years In
PyPI mandated 2FA for all maintainers in 2024. Two years in, account takeovers dropped — but attackers shifted to OIDC tokens, abandoned packages, and maintainer devices.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.