Skip to main content

Topic

Digital Identity and Credentials

Within the Topic facet, Digital Identity and Credentials topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

Editorial illustration showing a local browser permission aperture, a separate remote origin-validation structure, an unchanged blue client-data byte stream, and a copper four-stage evidence receipt ending at a relying-party server.

CASE FILE

WebAuthn’s Remote Client Can Validate the RP ID. The Local Permission Cannot Prove It Did

The first public draft of WebAuthn Level 4 proposes a careful handoff for remote-desktop sign-ins: a local browser may use client data supplied by a remote machine, but only after a per-origin grant. That grant opens the local capability. It does not preserve evidence of the…

Sep 23, 2026
One amber bearer credential splits toward three receiver modules while a looped path shows that one receiver can present it to another; separate blue paths represent isolated audiences.

IETF

One Bearer Token, One Audience: WIMSE Revision 07 Draws the Receiver Boundary

An external identity provider that accepts the same bearer token as a Kubernetes API server does not merely validate the workload. It acquires a credential it can present back to the API server as that workload. Revision 07 of the WIMSE practices draft turns the separation of…

Sep 22, 2026
An issuer's revoked certificate record passes through a timed distribution layer to three anonymous browser windows; one stops while two continue.

Story

One Revoked Certificate, Three Browser Outcomes at APNIC 62

The certificate was on the revocation list. That was not the end of the story. Geoff Huston's APNIC 62 demonstration put the same adverse record in front of three browser policies and obtained different results—a useful warning about the distance between publishing a security…

Sep 21, 2026
Two sequential governance thresholds connect a WebAuthn security key and grace-period hourglass to a separate patent-commitment covenant.

IETF

WebAuthn’s 2026 Rejoin Handoff: The Governance Receipt Behind a New Participation Cycle

The Web Authentication Working Group’s 11 September 2026 recharter begins a new institutional phase for WebAuthn. The central challenge is not simply continuing technical discussion; it is preserving a reliable record of how an approved charter becomes active participation and…

Sep 21, 2026
An author-only encrypted draft moves between a laptop and phone before crossing a distinct send boundary toward recipients, while the ordinary signing instrument remains separate.

IETF

RFC 9787 and the Moment a Draft Becomes a Message: Encryption, Commitment and Cross-Device Custody

A protected email draft is not merely an early copy of a sent message. RFC 9787 treats it as a different authority state: unfinished text may need confidentiality from the mailbox service while remaining unreadable to intended recipients and unendorsed by the user's ordinary…

Sep 20, 2026
An editorial network scene traces a self-generated IPv6 address registration from an endpoint through a relay to a DHCPv6 server, with separate layers for observation, identity and enforcement.

IETF

When “Lease” Stops Meaning “Address Assigned”

An operator upgrades a DHCPv6 inventory schema and discovers that one familiar dashboard label—“lease”—now conceals two different origins of authority. In one record, the server selected or delegated the resource. In another, the device selected a SLAAC or static address and…

Sep 20, 2026
Several anonymous IRT contact-state nodes pass through three policy clocks into a login gateway across an Asia-Pacific network map.

Story

APNIC Wants Login to Read the Current IRT Email State

An account should not inherit yesterday’s lock answer when today’s IRT contact state says something else. APNIC’s 2026 roadmap proposes replacing reliance on a static account lock flag with a login-time check of continuously tracked IRT email validity. That is a small sentence…

Sep 19, 2026
AI editorial portrait of Anita Borg beside an abstract governed message-routing boundary

History

Anita Borg and the Systers List: Admission to a Governed Room, Not Proof of Equality

A message could enter Systers because a member, an address and the list's routing rules admitted it to a private professional room. That delivery made scattered women in computing less isolated; it did not verify every identity claim, guarantee a career opportunity, erase…

Sep 19, 2026
AI editorial portrait of Andrew S. Tanenbaum beside an abstract segmented Amoeba capability

History

Andrew S. Tanenbaum and the Amoeba Capability That Authorized an Object, Not a Person

Amoeba compressed a service address, an entity name, an operations mask and an anti-forgery check into 128 bits. The resulting capability could travel with user code and carry authority without a central list of holders—but a valid token still said nothing by itself about the…

Sep 19, 2026
AI editorial portrait of Rob Pike beside separate translucent namespace frames and an open light-filled threshold.

History

Rob Pike and the 9P Walk That Opened Nothing

A client walks a name in 9P and receives every qid it expected. The path has resolved, yet no file has been opened and no byte has moved. The distinction at the heart of Rob Pike’s naming work is useful far beyond Plan 9: a protocol receipt is strongest when it is allowed to…

Sep 15, 2026
Two algorithm-identity crystals, one with an altered parameter facet, pass through the same derivation chamber and produce different keys; only the intact path reaches contained clear content.

CASE FILE

The Algorithm Label Changed. The Key Refused to Follow: RFC 9709

An attacker can rewrite a cryptographic label without breaking the advertised cipher. RFC 9709 answers that awkward fact by making the complete encoded algorithm identity part of the key itself—and by forcing operators to separate successful processing from evidence they can…

Sep 15, 2026
AI editorial portrait of Marshall T. Rose in an early network-management setting with three discrete state fields.

IETF

Marshall T. Rose and the SNMP SetRequest That Changed Every Variable or None

A maintenance console sends one SNMP SetRequest containing several variable bindings. The agent answers `noError`. That is a useful receipt—but only for a deliberately narrow claim. The early SNMP design associated with Marshall T. Rose’s working-group leadership helps show why a…

Sep 15, 2026
An identity-control network routes active access paths across contract rings and an amber renewal bridge.

Global Cloud Services Trends

SailPoint’s AI ARR needs a renewal-status column

SailPoint has put a number on its new AI business: more than US$70 million of annual recurring revenue. The number is useful precisely because it is not yet a revenue line. Its definition can keep a contract in the count after expiry while a renewal or replacement deal is still…

Sep 14, 2026
AI editorial portrait of Jerry Saltzer beside a directory link that stops at a separate access-control gate around a protected file.

History

Jerry Saltzer and the Link That Carried a Name but No Permission

A path can tell a computer where a file is without answering whether the person following it may read the file. Jerry Saltzer’s account of protection in Multics turned that separation into an operating rule—and exposed how much revocation, audit and institutional power can be…

Sep 14, 2026
AI editorial portrait of Eve Schooler beside separate paths for a SIP invitation, a session description and the resulting media stream.

History

Eve Schooler and the Invitation That Did Not Carry the Conversation

The most consequential line in an Internet call is not the one carrying a voice. It is the one that finds the other person, proposes a session and then gets out of the way. Eve Schooler’s path from experimental conference control to the early Session Initiation Protocol helps…

Sep 14, 2026
AI editorial portrait of Lixia Zhang beside multiple routes carrying matching named data copies through a separate trust-verification aperture.

History

Lixia Zhang and the Data Packet That Did Not Need Its Original Server

The revealing moment in Named Data Networking is not when a packet reaches a machine. It is when an Interest is answered by a copy found somewhere else—and the receiver can still ask who signed the data, whether that key was entitled to sign this name, and whether a fresher…

Sep 14, 2026
An identical row of dark service apertures feeds one luminous TLS boundary, where a trusted signal separates into distinct private diagnostic paths.

CASE FILE

The Resource Disappeared. So Did the Diagnosis: RFC 9729’s Concealed Authentication Boundary

Concealed authentication removes a useful signal from an intruder: the server no longer has to advertise a challenge before an authorized client can prove itself. The same silence can also erase the evidence an operator needs when a key is revoked late, a gateway exports the…

Sep 14, 2026
AI editorial portrait of Kenneth J. Klingenstein between two distinct institutional domains connected by a signed metadata and attribute trust layer.

History

Kenneth J. Klingenstein and the Registry Between Two Login Domains

A login crossing from a university to an outside service looks like a short trip through a browser. Kenneth J. Klingenstein’s work helped expose the institution hidden in the middle: a trust fabric that must make one domain’s assertion usable in another without pretending that…

Sep 13, 2026
AI editorial portrait of Klaas Wierenga between two academic network domains linked by a federated authentication path

History

Klaas Wierenga and the Credential That Stayed Home

A student from Delft opens a laptop in Cape Town. The local university can offer a network, but it cannot vouch for the visitor’s account. Delft can vouch for the account, but it does not control the Cape Town network. Klaas Wierenga’s decisive contribution to eduroam was to make…

Sep 13, 2026
A blank glass case card passes through separate cyan context, visibility, notification and brass authority stages while a branch enters an organization archive.

Story

ARIN Can Attach a Ticket to an Org ID. That Does Not Make It the Organization’s Decision.

ARIN fixed a mundane but costly support problem: staff no longer need to begin every ambiguous question by asking which organization it concerns. The resulting Org ID selector gives a ticket context and a durable home. That is good service design. It also makes one distinction…

Sep 12, 2026