GitHub will require 2FA for all developers who commit by September 2, 2026.
End of a transition started in 2022 - the real passive remains the automation workflows still relying on non-2FA tokens.
Jul 20, 2026 at 16:39 17 12
End of a transition started in 2022 - the real passive remains the automation workflows still relying on non-2FA tokens.
Jul 20, 2026 at 16:39 17 12
A vulnerability researcher documents six years of unauthenticated UDP replies from TP-Link Kasa EC71 cameras that returned the device's GPS coordinates on request - a textbook IoT trust-boundary failure.
Jul 18, 2026 at 11:11 34 8
The EU wallet age verification spec de facto requires an official mobile OS. Cryptographic security versus interoperability - but the European identity rail is being set in concrete with a foreign OS duopoly as a dependency.
Jul 14, 2026 at 15:44 31 8
A popular HN thread reignites the question: how should we authenticate an app in 2026? The answer is no longer "JWT + refresh token". A clear overview.
Jul 11, 2026 at 17:19 29 6