identity verification
11 posts
LLMs turned fluency into a forged credential
Perceived intelligence is a sender-controlled signal, not identity. Treating fluency as authorization is the exposure social engineers now produce on demand.
The session that never expired
How attackers held a year-long live feed inside an ID verification vendor via exposed credentials and session persistence, and why telemetry missed it.
Verification became the leak
An unauthorized live feed of every ID verification let attackers bypass MFA for over a year. Why readable verification output stops being proof.
FBI probes sale of 153 million license records
An FBI probe into a service selling 153 million driver's license records shows why static identity data cannot be rotated, recalled, or trusted as proof.
Possession is the credential
Verified badges, JWTs and X.509 certificates resolve trust once and keep honoring the reference long after the reality behind it has moved.
Saying you built it proves nothing
A contested 'vibe code' claim shows why self-reported origin accepted without verification is an unenforced control, not a trust boundary.
2023 mistakes an IP address for a passport
Forcing real ID on all internet traffic relocates an unsolved identity problem to a layer that cannot verify the subject and creates a higher value target.
demand is not a control
Stop Killing Games gathered 13 million signatures and produced no EU law. The proposed approach lacked granular data access control and identity verification.
FaceTec stores non-rotatable identity material
A senior operator's position on the storage of non-rotatable biometric templates by ID verification vendors, and the exposure that condition creates.
The helpdesk chat window is the breach
Microsoft Teams helpdesk impersonation succeeds because identity verification is placed at the channel boundary, not at the credential action.
How Identity Presentation Without Verification Enabled a Credential Compromise
A breakdown of how the Axios npm credential breach occurred due to identity presentation without technical validation, highlighting systemic risks in open-source infrastructure.