
Account recovery without account takeover
Recovery is the weakest door into most accounts. Design rules for a recovery email that helps a locked-out person without handing an attacker a second way in.
20 articles, newest first.

Recovery is the weakest door into most accounts. Design rules for a recovery email that helps a locked-out person without handing an attacker a second way in.

Employees and customers both sign in, but the users, scale, lifecycle and sign-in methods differ. Here is how the two compare and when one platform fits both.

Signing keys, SSH authorities, SAML certificates and sealed secrets belong behind one key service. How envelope encryption and rotation with a grace window work.

SSH keys copied to servers outlive the people who made them. Certificates signed by a CA expire in minutes, name who may log in and leave a record. How they work.

Step-up authentication asks for a stronger or fresher factor only before sensitive actions. Which actions to cover, how fresh a session must be, and how to avoid MFA fatigue.

This blog is a Next.js app on Cloudflare Workers with a Strapi CMS. Pages are pre-rendered, cached at the edge and regenerated only when a webhook says content changed.

Identity data is personal data. What counts as identity data, how regional planes and a global control plane divide the work, and what may reasonably cross a border.

An audit record should answer who did what, on whose behalf, from where and with what outcome. How to design the fields, make it tamper-evident and keep it searchable.

Role-based access control decays unless it is maintained. How permissions, roles and bindings fit together, and how to find roles nobody holds or that grant nothing.