🦞🌯 Lobster Roll

Thread

The “email is authentication” pattern (rubenerd.com)

Stories related to "The “email is authentication” pattern" across the full archive.

Email authentication: SPF, DKIM and DMARC out in the wild (blog.jonlu.ca)
The “email is authentication” pattern (rubenerd.com)
Improved Authentication for Email Encryption and Security (2016) (protonmail.com)
Revisiting Email Spoofing (alex.kaskaso.li)
Critical OpenSMTPd bug opens email servers to hackers (thehackernews.com)
Stop Using Encrypted Email (latacora.micro.blog)
Email service provider recommendations (drewdevault.com)
DIME, Formerly DarkMail, Promises Secure Email (2014) (tomsguide.com)
Google Meddling With URLs In Emails, Causing Security Concerns (hackaday.com)
Protect domains that don’t send email (gov.uk)
Yes, We Want Cryptographic Protection for Email (sequoia-pgp.org)
Treating Email More Like a Password Manager (dmitryfrank.com)
The "email is authentication" pattern (rubenerd.com)
How do you manage Personal Email, Registar and Host Accounts to Prevent Lock Out?
I once lost access to a 15 year old google account and have also been geolocked out while traveling. Although the recovery emails didn't help then, I still broadened my footprint and especially maintained emails on hosted domains. I see holes in this too, however. Is there anything foolproof? I (...
How to fix email encryption (weddige.eu)
Fun with Gzip Bombs and Email Clients (grepular.com)
Everything You Need to Know About Email Encryption in 2026 (soatok.blog)
Two-factor authentication with ssh (blog.authy.com)
Two Factor SSH Authentication (sethvargo.com)
Bypassing Google’s Two-Factor Authentication (blog.duosecurity.com)
Sudo authentication bypass when clock is reset (sudo.ws)
Ask Lobsters: What is the general consensus on the best API authentication these days?
I liked Flickr's now-deprecated [hash-the-params](http://www.flickr.com/services/api/auth.howto.web.html) authentication because it was simple (though [flawed](http://vnhacker.blogspot.com/2009/09/flickrs-api-signature-forgery.html), it is fixable). Now it seems like most sites are using OAuth 1....
Use Google Authenticator For Two-Factor SSH Authentication in Linux (scottlinux.com)
Using Yubikey For SSH Multi-Factor Authentication (undeadly.org)
Web Security Relies on SSL Which Relies on Email Which is Broken (blog.whitehatsec.com)
Tesla Model S REST API Authentication Flaws (programming.oreilly.com)
Signing email with an NFC smart card on Android (nelenkov.blogspot.com)
Scramble: secure email for everyone (dcposch.github.io)
A portscan by email – HTTP over X.509 revisited (blog.nruns.com)
Beyond SSL client cert authentication: authorization (spootnik.org)