Rrathsarainrr-cyber.hashnode.dev·2h ago · 19 min readOpenID Connect: The Identity Layer OAuth Was MissingBy the time I actually heard the word OIDC, I'd already been through OAuth and PKCE conversations I hadn't fully understood, years apart from each other, and this one arrived even later than those. It00
MSManu Shuklainecorpit.hashnode.dev·6d ago · 15 min readEKS raised the OIDC provider cap to 10 on 24 August 2026, but only above Kubernetes 1.32EKS raised the OIDC provider cap to 10 on 24 August 2026, but only above Kubernetes 1.32 Summary. On 24 August 2026 AWS announced that Amazon EKS supports up to 10 external OpenID Connect identity pro00
MSManu Shuklainecorpit.hashnode.dev·Aug 23 · 11 min readCloudflare saved login profiles: 5 per device, and 3 docs that never mention themCloudflare saved login profiles: 5 per device, and 3 docs that never mention them Summary. On 21 August 2026 Cloudflare added saved login profiles to the dashboard sign-in page. A profile stores an em00
MSManu Shuklainecorpit.hashnode.dev·Aug 21 · 13 min readAWS IAM doubled managed policies per role to 20 in August 2026 — three caps did not moveAWS IAM doubled managed policies per role to 20 in August 2026 — three caps did not move Summary. On 19 August 2026 AWS Identity and Access Management raised the default quota for managed policies per00
KMKartik Mehtainwriter.mrmehta.in·Aug 19 · 8 min readAgents should be Self-ishWhy the next trust primitive on the agentic web isn't a smarter model. It's a passport scan! At 2:00 AM UTC on March 18, 2025, an AI agent with 460,000 followers sent 55.5 ETH, roughly $104,000, to a 20
Rrathsarainrr-cyber.hashnode.dev·Aug 14 · 31 min readUnderstanding OAuth 2.0: Delegation, Grant Types, and the Attacks That Actually HappenThe first time I heard the term OAuth, I didn't know what it meant. I was in a conversation with a DBA lead about something adjacent to authentication and authorization, and he mentioned, almost in pa00
Rrathsarainrr-cyber.hashnode.dev·Aug 6 · 15 min readIdentity Foundations: Everything Before OAuthBefore any protocol makes sense on its own terms, a few things underneath it need to be settled first: what authentication and authorization actually are as distinct concepts, how identity gets carrie13N
Rrathsarainrr-cyber.hashnode.dev·Aug 5 · 9 min readIdentity Was the Gap I Did Not Know I HadI had worked across cloud security engineering, vulnerability assessment, penetration testing, and application security. I had reviewed IAM configurations across multiple cloud platforms, flagged over11N
SSapotaCorpinsapotacorpvn.hashnode.dev·Jul 12 · 7 min readMCP Cross-Device Identity: Merge Mechanics and the Edge CasesA real visitor uses three devices in a typical week. Phone in the morning, laptop at work, tablet in the evening. Marketing Cloud Personalization is built to recognize that all three are the same pers00
PKPrashant Koiralainblog.prashantkoirala.info.np·Jul 11 · 26 min readPasskeys are finally becoming mainstreamPasswords have been declared dead so many times that the phrase barely means anything anymore. For years, the replacement story was always just around the corner. Biometrics would replace passwords. S00