Category: Authentication

  • Auth In The World Of Customer Identity

    Auth In The World Of Customer Identity

    In the world of Customer Identity and Access Management, Authentication and Authorization are essentially the two sides of the “Auth” coin. Whilst at first glance they seem similar, the distinction between each is fundamental to achieving a successful outcome from both an integration and a security perspective — yet is often misunderstood.

  • Taking the Risk out of Customer Identity Migration

    Taking the Risk out of Customer Identity Migration

    When it comes to Customer Identity integration, Migration is an almost inevitable part of the journey, and one that can be a challenging and risky prospect if not approached in the right way. In this article, I’ll be discussing what you’ll need to consider in order to make your transition as smooth as possible.

  • Single Page Survival When Integrating With OAuth 2

    Single Page Survival When Integrating With OAuth 2

    Whilst the SPA paradigm has grown in prominence over the years, little has changed in the guidance provided for integrating Customer Identity. With the necessity to provide a compelling UX, whilst protecting from attacks like XSS, this article introduces the ACME pattern and how it has been designed to tackle the challenge.

  • Spotlight on the CIAM Token Storage Conundrum

    Spotlight on the CIAM Token Storage Conundrum

    Tokens lie at the heart of modern CIAM integrations, enabling scalable and secure authentication and authorization. However, their power makes them a target for attackers. Mismanaged tokens and token storage can undermine the security of even the most advanced identity systems, leaving applications and security-sensitive data vulnerable to attack.

  • Anatomy of a Password

    Anatomy of a Password

    Password authentication remains a cornerstone of Customer Identity and Access Management (CIAM) systems, but to be effective, it must be secure. Passwords must never be stored in plain text, proper encryption, hashing and salting techniques must be employed, and regular monitoring with periodic auditing is essential to keeping password data secure.

  • B2C and B2B SaaS Authentication Architectures

    B2C and B2B SaaS Authentication Architectures

    The CIAM requirements for B2C and B2B SaaS differ significantly due to the varying needs for security, complexity, and user experience. B2C platforms emphasize ease of use and scalability, where B2B SaaS platforms focus on the addition of enterprise-level integrations and adaptive processes that provide greater flexibility, granular access control, and robust security.

  • Passwordless OTP and Magic Link Scenarios

    Passwordless OTP and Magic Link Scenarios

    Passwordless authentication methods like Magic Links and OTPs provide substantial benefits in terms of user experience, security, and scalability in numerous workflow scenarios. By eliminating passwords, these methods reduce the risk of phishing and credential theft while providing seamless access to users.

  • Passkeys and Their Role in Customer Identity & Access Management

    Passkeys and Their Role in Customer Identity & Access Management

    Passkeys represent the future of authentication, offering businesses and users a more secure, user-friendly, and privacy-respecting method of logging in. By replacing traditional passwords with cryptographic keys, passkeys address many of the vulnerabilities that have plagued password-based systems for years.

  • Social Authentication for Customer Identity and Access Management

    Social Authentication for Customer Identity and Access Management

    Social authentication is an invaluable tool for improving user experience, enhancing security, and streamlining account management as part of a broader Customer Identity and Access Management (CIAM) solution. By offering users the ability to log in via trusted third-party platforms like Facebook, Google, and LinkedIn, businesses can reduce friction during the onboarding process, increase customer retention, and lower operational costs.