- App redirects to identity broker
- Identity Broker redirects to social login
- Browser prompts to open password manager to access social login password.
- Password manager prompts for master password and redirects back to social login
- Social login prompts for security key.
- Social login redirects back to identity broker.
- Identity broker redirects back to app.
- “Cannot read properties of undefined (reading ‘length’)”
Is a system secure if no one can gain access?
Servers are much more secure when they are shut down.
Or never even purchased!
Why do we even bother with data at all? Let’s just not exist - humans greatly increase attack surface.
That’s the ultimate shift left. Secure your applications before people can get credentials.