Safeguard
Tag

authentication

Safeguard articles tagged "authentication" — guides, analysis, and best practices for software supply chain and application security.

75 articles

Application Security

Account Linking by Email Match Trusts a Claim, Not a Verification

Continue with Google links to the matching existing account by email address. That is correct when the identity provider genuinely verified the email. Some providers make verification optional, and not every system checks which claim it is reading.

Sep 18, 20266 min read
Application Security

Which Timing Differences Actually Matter

Extracting a secret from microsecond differences across the internet is genuinely hard. A response that takes 120ms when an account exists and 3ms when it does not needs no statistics at all.

Sep 18, 20265 min read
Application Security

Account Recovery Is the Weakest Authentication You Have

You require strong passwords and enforce MFA, then built a flow that lets someone with inbox access bypass all of it. Recovery exists to let in someone who cannot satisfy the normal requirements, so every control above it is capped by how well it is built.

Sep 18, 20266 min read
Application Security

Your App Issues Two Kinds of Token and One Verifier Only Knows One

An SSO user carries your auth service's token, not your identity provider's. A verifier that accepts only the provider's tokens rejects exactly the users it was built for, and the symptom is a button that does nothing.

Sep 17, 20266 min read
Vulnerability Analysis

Apple Patched a Network-Exploitable Auth Bug Across Five Concurrent macOS Releases

CVE-2026-65400, an authentication issue Apple fixed with 'improved state management,' was backported across Golden Gate, Sequoia, Sonoma and two Tahoe releases at once.

Sep 16, 20264 min read
Application Security

Authenticated DAST: Getting Past the Login Without Wrecking the App

Most of an application is behind a session, so an unauthenticated scan tests the login page and the marketing footer. Getting in is the easy half — staying in, and not clicking Delete Account, is the rest.

Aug 16, 20265 min read
Open Source

react-native-confirmation-code-field: Building Secure OTP Input

This tiny React Native library gives you a clean OTP entry UI, but a secure one-time-code flow is mostly about what happens around the field, not in it.

Jul 17, 20266 min read
Application Security

Designing a secure Node.js API gateway: auth, rate limits, validation, and signing

CVE-2020-15084 let attackers forge JWTs against express-jwt because one algorithm check was missing — a case study in why gateways need four defense layers, not one.

Jul 15, 20266 min read
Security

Web API Security: A Practical Guide to Protecting Your APIs

Web API security is about controlling who can call your endpoints, what they can do, and what data they can reach. Here are the risks that matter and the defenses that work.

Jul 13, 20266 min read
Application Security

API gateway security: enforcing authN/authZ and rate limits at the edge

A single unauthenticated API endpoint exposed 37 million T-Mobile accounts in 2023. Edge-enforced authZ and identity-aware rate limits are how you prevent the repeat.

Jul 13, 20266 min read
Application Security

Building an authenticated, TLS-secured WebSocket server in Python

WebSockets skip same-origin checks by default — CWE-1385 exists because of it. Here's how to build one in Python with origin checks, TLS, and rate limits.

Jul 11, 20266 min read
Application Security

JWT security vulnerabilities and best practices

The jsonwebtoken library shipped three separate signature-bypass CVEs between 2015 and 2022 — algorithm confusion is still the most common way JWTs fail.

Jul 10, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.