noticed a pattern in signup data — users that registered and never came back. checked the emails: all throwaway domains. keycloak has no built-in setting for this, so I wrote an SPI extension.
Here's how it works:
https://mrbu.ch/articles/keycloak-block-disposable-email-extension/
#Keycloak #Java #opensource #seucrity #auth

Every Disposable Email Is A Hole In Your Funnel
Disposable emails flood your signups with accounts that never convert. A small Keycloak SPI extension that blocks them at registration — no polling, no database changes, no custom themes.
Mr. BuchAndroid and iOS devices impacted by new sensor calibration attack | ZDNet
SensorID technique can track users across apps and websites using sensor calibration data.