A Post-Quantum Future for Let's Encrypt

Let’s Encrypt is committed to a post-quantum-safe Web PKI. The path we’re planning to take is Merkle Tree Certificates (β€œMTCs”), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal.
β€” by @letsencrypt

πŸ” https://letsencrypt.org/2026/06/03/pq-certs

#letsencrypt #PQCryptography #pqc #web #it #authentication #postquantum #login #pwords #postquantumcryptography #websecurity #future #webpki

A Post-Quantum Future for Let's Encrypt

Let’s Encrypt is committed to a post-quantum-safe Web PKI. The path we’re planning to take is Merkle Tree Certificates (β€œMTCs”), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal. This post is about these plans and why we believe MTCs are worth pursuing as a key to a post-quantum future. An increasingly urgent problem For much of the last several years, the conversation about post-quantum cryptography has been a conversation about encryption. The reasoning was straightforward: an attacker who records encrypted traffic today might be able to decrypt it years from now once quantum computers can break the underlying math. Authentication, the part of TLS that indicates a server is who it says it is, has been a less urgent problem. A quantum computer needs to forge a signature in real time, not retroactively, so threats to authentication hinge on the existence of a cryptographically relevant quantum computer (CRQC).

Passkeys Are Better Than Passwords, but Not a Silver Bullet

Passkeys are a major improvement over passwords, but weak recovery flows, SMS fallbacks, legacy credentials, and help desk shortcuts can still give attackers a way around them.

CybersecKyle
1-Click GitHub Token Stealing via a VSCode Bug

My blog, mostly about programming

Ammar's Blog

FIDO vs FIDO2: Understanding the Evolution of Passwordless Authentication

FIDO2 is the latest evolution in the realm of passwordless authentication, building upon the foundations laid by FIDO (Fast IDentity Online). […], understanding the differences and advancements between FIDO and FIDO2 is crucial for implementing robust, secure authentication systems.

πŸ”‘ https://www.iamdevbox.com/posts/fido-vs-fido2-understanding-the-evolution-of-passwordless-authentication/

#fido #login #online #fido2 #passkeys #passwordless #password #login #iam #account #authentication #security #it

FIDO vs FIDO2: Understanding the Evolution of Passwordless Authentication

Explore the evolution from FIDO to FIDO2 and learn how modern passwordless authentication enhances security and user experience in DevOps environments.

IAMDevBox

https://winbuzzer.com/2026/06/01/microsoft-to-tighten-entra-id-password-reset-rules-xcxwbn/

Microsoft will require registered authentication methods for Entra ID password resets from September 7, pushing admins to close enrollment gaps early.

#MicrosoftEntraID #MicrosoftEntra #Authentication #Security #Cybersecurity #Microsoft #Microsoft365

In my #SSO / #IdM adventures, looks like if I wanted to allow people to use my hackerspace's #OIDC SSO to access my services, I can configure this in #Authentik, but not in #KaniDM πŸ€”

#privacy #SelfHosting #authentication

Create a Centralized Login For Your Vibe Coded Apps

A Step by Step Guide for Using LogTo for a Vibe Coder

Medium

Ory IAM handles auth for OpenAI's 900M weekly users. Here's what Kratos, Hydra, Keto, Oathkeeper, and Polis each do, and who it's for.

Full story here: https://ostechnix.com/what-is-ory/

#Ory #IAM #Authentication #Openai #Chatgpt #Kratos #Hydra #Keto #Oathkeeper #Polis #IdentityAccessManagement #Opensource

Ory: The Open Source IAM Stack That Powers ChatGPT's Login - OSTechNix

Ory IAM handles auth for OpenAI's 900M weekly users. Here's what Kratos, Hydra, Keto, Oathkeeper, and Polis each do, and who it's for.

OSTechNix

API Security 101: Understanding the Foundation and Why Attacks are Rising
This article discusses the growing importance of API security and the rising number of attacks against APIs. The author explains that APIs have become critical components in modern applications, handling a wide range of tasks including authentication, data transfer, and business logic. However, their increasing usage has exposed numerous vulnerabilities. One specific example provided is an XSS (Cross-Site Scripting) attack on an API endpoint via client-side manipulation of cookies or JavaScript. The researcher was able to exploit insufficient input validation by injecting malicious scripts within the user's session cookie, which executed upon subsequent API requests due to the lack of Content Security Policy headers. The impact includes unauthorized access, data theft, and account hijacking. The author recommends implementing proper access controls, token-based authentication, rate limiting, and input validation to secure APIs. Key lesson: Secure APIs are crucial for maintaining application security in the modern digital landscape. #API #Cybersecurity #WebSecurity #XSS #Authentication #InputValidation

https://medium.com/@dakshdhamija2006/api-security-101-understanding-the-foundation-and-why-attacks-are-rising-9ee82d764627?source=rss------bug_bounty-5

API Security 101: Understanding the Foundation and Why Attacks are Rising

APIs are the hidden plumbing of the internet, but they are also a hacker’s favorite target. If you are new to cybersecurity or just want to…

Medium

I'm considering #smime certificates instead of PGP keys for my #email #encryption and #authentication. Unfortunately I have no clue which certificate authorities are good. Any suggestions from the fediverse?

Also #boost|s for more reach would be highly appreciated :) , thanks!