authentication
Safeguard articles tagged "authentication" — guides, analysis, and best practices for software supply chain and application security.
75 articles
Account Linking by Email Match Trusts a Claim, Not a Verification
Continue with Google links to the matching existing account by email address. That is correct when the identity provider genuinely verified the email. Some providers make verification optional, and not every system checks which claim it is reading.
Which Timing Differences Actually Matter
Extracting a secret from microsecond differences across the internet is genuinely hard. A response that takes 120ms when an account exists and 3ms when it does not needs no statistics at all.
Account Recovery Is the Weakest Authentication You Have
You require strong passwords and enforce MFA, then built a flow that lets someone with inbox access bypass all of it. Recovery exists to let in someone who cannot satisfy the normal requirements, so every control above it is capped by how well it is built.
Your App Issues Two Kinds of Token and One Verifier Only Knows One
An SSO user carries your auth service's token, not your identity provider's. A verifier that accepts only the provider's tokens rejects exactly the users it was built for, and the symptom is a button that does nothing.
Apple Patched a Network-Exploitable Auth Bug Across Five Concurrent macOS Releases
CVE-2026-65400, an authentication issue Apple fixed with 'improved state management,' was backported across Golden Gate, Sequoia, Sonoma and two Tahoe releases at once.
Authenticated DAST: Getting Past the Login Without Wrecking the App
Most of an application is behind a session, so an unauthenticated scan tests the login page and the marketing footer. Getting in is the easy half — staying in, and not clicking Delete Account, is the rest.
react-native-confirmation-code-field: Building Secure OTP Input
This tiny React Native library gives you a clean OTP entry UI, but a secure one-time-code flow is mostly about what happens around the field, not in it.
Designing a secure Node.js API gateway: auth, rate limits, validation, and signing
CVE-2020-15084 let attackers forge JWTs against express-jwt because one algorithm check was missing — a case study in why gateways need four defense layers, not one.
Web API Security: A Practical Guide to Protecting Your APIs
Web API security is about controlling who can call your endpoints, what they can do, and what data they can reach. Here are the risks that matter and the defenses that work.
API gateway security: enforcing authN/authZ and rate limits at the edge
A single unauthenticated API endpoint exposed 37 million T-Mobile accounts in 2023. Edge-enforced authZ and identity-aware rate limits are how you prevent the repeat.
Building an authenticated, TLS-secured WebSocket server in Python
WebSockets skip same-origin checks by default — CWE-1385 exists because of it. Here's how to build one in Python with origin checks, TLS, and rate limits.
JWT security vulnerabilities and best practices
The jsonwebtoken library shipped three separate signature-bypass CVEs between 2015 and 2022 — algorithm confusion is still the most common way JWTs fail.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.