PasskeyBridge Blog
Engineering, security, and compliance notes from the PasskeyBridge team.
- A Verifier Can Hang Your Wallet with One Regular Expression (2026-09-14)
- Feeding a Hard Deny into Your Fraud Rules Engine: Integration Patterns (2026-09-11)
- The Pre-Filter Pattern: Paying for Heavy Fraud Signals Only on the Suspicious Tail (2026-09-07)
- Ground Truth for Space-Based Auth: Validating Doppler Challenges Against Public TLE Catalogs (2026-09-03)
- The PQC Inventory Your 2027 Audit Will Ask For (2026-08-31)
- Running CAEP in Production: Signing Outbound SETs and the Receivers That Take Them (2026-08-27)
- Benchmarking an Identity Verification API: Latency, Freshness, Failure Injection (2026-08-24)
- Anatomy of an A2A Handshake: How Two AI Agents Establish Trust Without a Shared Secret (2026-08-20)
- Six Contract Clauses That Test a “Zero PII” Claim (2026-08-17)
- Keying Every Identifier Hash Without Breaking Correlation (2026-08-13)
- Account Recovery Is the Front Door: Carrier-State Checks in Credit Union and Community Bank Recovery Flows (2026-08-10)
- Three 2026 Headlines About ML-DSA, Steelmanned and Corrected (2026-08-08)
- Roaming Steering and Identity: When the HPLMN You Trust Hands You to a VPLMN You Don't (2026-07-31)
- Inter-Satellite Links as a Trust Mesh: Optical Cross-Links in LEO Constellations and Identity Routing (2026-07-27)
- The Identity Stack Bifurcation: Consumer Wallets vs Enterprise Attestation Layers (2026-07-23)
- mDoc and mDL Interoperability with W3C VC 2.0: Bridging the ISO 18013-5 and JSON-LD Worlds (2026-07-20)
- Multi-Region Active-Active Identity: Conflict-Free Replicated Trust State Across Three Continents (2026-07-17)
- DORA Article 28 and Third-Party ICT Risk for Identity Providers: The Subcontracting Chain (2026-07-13)
- Cryptographic Agility as a Protocol Property: Designing Identity Wire Formats That Survive Algorithm Deprecation (2026-07-10)
- Trust Propagation When Your Agent Spawns Its Own Workers (2026-07-06)
- Network Slicing in 5G Standalone and the Birth of Per-Slice Identity Posture (2026-07-03)
- HAPS and Stratospheric Backhaul: Identity Implications of 20km-Altitude Cell Towers (2026-07-01)
- IDV Margin Compression: Per-Verification Pricing Toward Zero by 2027 (2026-06-29)
- OpenID4VP over the Digital Credentials API: Browser-Native Wallet Selection in Chrome and Safari (2026-06-26)
- Backpressure for Identity Pipelines: Designing Verifiers That Degrade Under DDoS, Not Collapse (2026-06-22)
- NYDFS Part 500 Amendments and Continuous Authentication: 23 NYCRR 500.12 (2026-06-19)
- ML-DSA-87 vs SLH-DSA-256: Choosing the Right Post-Quantum Signature for Long-Lived Identity Assertions (2026-06-16)
- Just-in-Time Capability Tokens for Agents: Persistent OAuth Scopes as Standing Privilege (2026-06-12)
- RCS Business Messaging as an Identity Channel: Verified Sender Telemetry Beyond A2P SMS (2026-06-08)
- The African Mobile Identity Leap: Carrier-First Identity in Markets Without Legacy IAM (2026-06-05)
- Credential Chaining: Deriving Trust from a Sequence of Issuer Attestations (2026-05-31)
- Cold Start Latency in Serverless Identity Functions: Benchmarks and Mitigations (2026-05-26)
- PCI DSS 4.0.1 and Identity Verification: Stronger Authentication Without Storing Cardholder Data (2026-05-22)
- Quantum Key Distribution and Identity Systems: Separating the Signal from the Hype (2026-05-18)
- Behavioral Fingerprinting for Agents: Detecting Model Substitution in Production Pipelines (2026-05-15)
- Carrier Signal Freshness: TTL Over Signal Strength (2026-05-12)
- Identity Federation for Cislunar Operations: Extending Trust Beyond Earth Orbit (2026-05-08)
- Insurance Underwriting Meets Identity Assurance: How Cyber Insurers Are Pricing Authentication Risk (2026-05-04)
- Credential Revocation at Scale: Bitstring Status List vs Accumulator Proofs (2026-05-02)
- Event Sourcing for Identity State: CRUD and Trust Decisions (2026-04-29)
- SSF and CAEP: Closing the Cross-IdP Revocation Latency Gap (2026-04-28)
- DPoP Token Binding: Beyond Bearer Tokens in 2026 (2026-04-28)
- FedRAMP Authorization for Identity APIs: The Moderate Baseline and Carrier Signal Processing (2026-04-26)
- Stateful Hash-Based Signatures for Audit Logs: When LMS/XMSS Outperforms Lattice Schemes (2026-04-24)
- The Liability Gap in Agentic Commerce: Responsibility When an Agent Commits Fraud (2026-04-22)
- eSIM Profile Switching as an Identity Signal, and as an Attack Surface (2026-04-20)
- Orbital Slot as Entropy Source: Harvesting Positional Uncertainty from Satellite Constellations (2026-04-18)
- Carrier Monetization of Identity Signals: The $4B Opportunity Reshaping Telecom Revenue (2026-04-16)
- DID Method Proliferation: did:web and Enterprise Adoption (2026-04-15)
- Circuit Breakers for Identity Pipelines: Graceful Degradation When a Carrier API Goes Dark (2026-04-13)
- Data Residency for Identity Signals: Navigating Schrems III and Cross-Border Carrier Lookups (2026-04-12)
- Key Encapsulation for Identity Tokens: KEM in a Post-Quantum Auth Stack (2026-04-11)
- Agent Attestation Fatigue: When Too Many Trust Checks Become the Vulnerability (2026-04-10)
- Silent Number Recycling and the Carrier Signal Most Identity Stacks Ignore (2026-04-09)
- Delay-Tolerant Identity: Authentication Protocols for 600ms+ Round-Trip Latency (2026-04-08)
- The Consolidation of Identity Verification: Point Solutions and Platforms (2026-04-07)
- Selective Disclosure with SD-JWT: Revealing Only the Claims That Matter (2026-04-06)
- Edge-First Identity Verification: Moving Carrier Signal Processing to the CDN Layer (2026-04-05)
- The EU Digital Identity Wallet and Carrier Signals: How eIDAS 2.0 Creates a New Compliance Surface (2026-04-04)
- Hybrid Signatures in Practice: Dual-Signing Identity Assertions with ES256 and ML-DSA (2026-04-03)
- Scope Poisoning: How Compromised Agents Escalate Privileges Through Delegation Chains (2026-04-02)
- Carrier Signal Chaining: Correlating Multi-IMSI Events Across Roaming Boundaries (2026-04-01)
- Starlink Direct-to-Cell and Identity: Satellite-Terrestrial Handoff and SIM Attestation (2026-03-31)
- The Missing Link in Identity Assurance: Cross-Referencing SIM Signals with Verifiable Credentials (2026-03-30)
- SOC 2 Type II for Identity APIs: The Audit Controls Few Will Tell You About (2026-03-29)
- Carrier Signal Fusion: Single-Provider Lookups as a Single Point of Failure (2026-03-28)
- QRNG vs. CSPRNG: The Entropy Identity Systems Need (2026-03-27)
- Verifiable Credentials Without the Blockchain: A Pragmatic Approach to Digital Identity (2026-03-26)
- Trust Decay Functions: The Mathematics of Agent Behavioral Drift (2026-03-25)
- The 200-Millisecond Blind Spot Between SIM Swap and Detection (2026-03-24)
- Designing an Identity Playbook Engine: From Signal to Action in One API Call (2026-03-23)
- Non-Terrestrial Trust Anchors: The Next Identity Layer Won't Touch the Ground (2026-03-22)
- Encrypted Tunnels in Identity: Beyond TLS (2026-03-21)
- A2A Trust Negotiation: How Two AI Agents Prove Identity to Each Other Without a Human (2026-03-20)
- The Identity Stack for Autonomous Commerce: When Your AI Agent Needs a Credit Line (2026-03-19)
- The CISO's Guide to Zero-PII Identity Verification in a Post-GDPR World (2026-03-18)
- Harvest Now, Decrypt Later: Your 2026 Identity Data Is Already at Risk (2026-03-17)
- Physics-Anchored Identity Settlement Tokens: Proof of Presence, Not Stake (2026-03-16)
- The Identity Threat Response Market in 2026: Detection Without Response Is Logging (2026-03-15)
- Passkeys Need a Carrier Signal Layer (2026-03-14)
- Identity From Orbit: How LEO Satellite Signals Could Replace Ground-Based Entropy (2026-03-14)
- The Zero-Knowledge Audit Trail: Proving Provenance Without PII (2026-03-13)
- A Governor for Autonomous AI Agents, Not Just a Password (2026-03-11)
- The Invisible SIM-Swap: Carrier-Signal Variance as a Detector (2026-03-11)
- Post-Quantum Identity: NIST FIPS 204 and Your Auth Stack (2026-03-08)
- Identity is a Physics Problem, Not a Math Problem (2026-03-08)
- Building an Identity Threat Playbook in Under 10 Minutes (2026-03-07)
- Delegating Identity to AI Agents Without Delegating Trust (2026-03-06)
- Reg S-ID Compliance Without Storing a Single Phone Number (2026-03-05)
- After SIM-Swap Detection: The Next 50 Milliseconds (2026-03-04)
- Agentic Identity: Scoped Digital Delegates for AI Agents (2026-03-02)
- SIM-Swap Detection on Its Own (2026-03-01)
- Introducing PasskeyBridge: Identity Security as a Service (2026-03-01)
- Building a Zero-PII Audit Trail (2026-02-28)
- SOC 2 Readiness for Identity Startups in 2026 (2026-02-25)
- The Carrier Signal Landscape in 2026 (2026-02-20)