Using Third-Party ID Providers Without Losing Zero Trust
ID: 38eef40d-10d1-5065-9a00-ca3e6440748c
STIX ID: report--38eef40d-10d1-5065-9a00-ca3e6440748c
Feed Name: Dark Reading
The article proposes an “extra-factor authentication” approach that appends an organization-controlled passkey verification step after a third-party IdP completes authentication. By self-hosting a final verification and authorization stage (using OpenFGA, Ory Hydra, Ory Kratos, and Juju charms) the design aims to preserve IdP heuristics and protections while eliminating the risk that an IdP or a compelled/backdoored account can unilaterally grant access, giving organizations the final source of truth for access decisions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
