I was having trouble using the One Login app to verify my identity for Companies House, as my initial attempt resulted me in inadvertently exceeding the maximum attempts. 😰 I tried calling customer support for them to reset my account, but they said that wasn’t possible. 😟 However, I was curious to see if deleting my account and creating it again would solve the issue, and it did! 😌 #OneLogin #CompaniesHouse
Whistleblowers raise ‘extreme’ concern about security of government’s Digital ID | ITV News https://alecmuffett.com/article/136503 #DigitalId #IdCards #OneLogin

Whistleblowers raise ‘extreme’...
Whistleblowers raise ‘extreme’ concern about security of government’s Digital ID | ITV News

My understanding from friends is One Login is a glorified bastion host that reliant services & parties are obligated to blindly trust, making it a giant SPOF; that alone would be terrifying at 


Dropsafe
Whistleblowers raise ‘extreme’ concern about security of government’s Digital ID | ITV News
https://alecmuffett.com/article/136503
#DigitalId #IdCards #OneLogin
Whistleblowers raise ‘extreme’ concern about security of government’s Digital ID | ITV News

My understanding from friends is One Login is a glorified bastion host that reliant services & parties are obligated to blindly trust, making it a giant SPOF; that alone would be terrifying at 


Dropsafe

Whistleblowers raise ‘extreme’ concern about security of government’s Digital ID | ITV News

My understanding from friends is One Login is a glorified bastion host that reliant services & parties are obligated to blindly trust, making it a giant SPOF; that alone would be terrifying at national scale, but then: this:

“Whistleblowers have told ITV News that One Login is failing to meet the mandatory, minimum government cybersecurity standards, ‘Secure by Design’ and the ‘Cyber Assessment Framework’”

https://www.itv.com/news/2025-12-18/whistleblowers-raise-extreme-concern-about-security-of-governments-digital-id

#digitalId #idCards #oneLogin

y'know, I have to wonder how the UK is gonna implement onelogin when it is not secure by most standards.
#onelogin is pretty funtimentally not #secure and this was actually proven by the IA (information assurance) team that supposedly help the UK secure the onelogin portal.

watch this video to see what I mean
https://www.youtube.com/watch?v=HWuNyiYftZw
(1/2)

David Davis MP speaks at a Westminster Hall debate against the Government's digital ID plans

YouTube

"The Lib Dem peer said he had been told by an official that #OneLogin would not pass the required security tests until March 2026. The whistleblower also highlighted an incident from March this year, when a so-called "red team" tasked with simulating a real life cyber attack was reportedly able to gain privileged access to One Login systems."

#UKPol #DigitalID #IDCards #No2ID

https://www.bbc.co.uk/news/articles/c5y930x81wpo

Security concerns over system at heart of digital ID

The government is facing questions over whether One Login can be trusted to keep people's personal data secure.

BBC News
“We do not guarantee that GOV.UK One Login will always be available, or that access to it will be error free. We will provide a way for you to report problems with GOV.UK One Login”
https://alecmuffett.com/article/117386
#DigitalId #IdCards #KierStarmer #OneLogin
“We do not guarantee that GOV.UK One Login will always be available, or that access to it will be error free. We will provide a way for you to report problems with GOV.UK One Login”

Wow. Reference to “Safari 12” suggests this is 2018-era technology, at best: Terms and conditions – GOV.UK One Login archived at

Dropsafe

“We do not guarantee that GOV.UK One Login will always be available, or that access to it will be error free. We will provide a way for you to report problems with GOV.UK One Login”

Wow. Reference to “Safari 12” suggests this is 2018-era technology, at best:

Terms and conditions – GOV.UK One Login

https://signin.account.gov.uk/terms-and-conditions archived at https://archive.ph/yTPbc

#digitalId #idCards #kierStarmer #oneLogin

Terms and conditions - GOV.UK One Login

🔒 CVE-2025-59363 (HIGH, CVSS 7.7) in OneLogin pre-2025.3.0 leaks OIDC client secrets via GET Apps API v2. Patch now or restrict API access, enforce RBAC, and monitor logs. Major risk for IAM environments! https://radar.offseq.com/threat/cve-2025-59363-cwe-669-incorrect-resource-transfer-1609a0a6 #OffSeq #OneLogin #Vuln #IAM
Hey #OneLogin, event type 93 is missing from your lists in docs and the API, but gets emitted. I think it might be "share note".